Customer Release Notes
Product Description
SafeNet FIDO Key Manager for macOS is a standalone offline application that allows customers and end users to manage and setup Thales’ FIDO USB tokens and Smartcards. Users can use these FIDO Key for a secure and phishing-resistant authentication method for logging in to various websites or applications. It allows administrators or users to be in full control of their physical FIDO Keys and not be dependent on the limited functionality offered natively by browsers or desktops. With SafeNet FIDO Key Manager you can configure the basic FIDO specifications and the unique set of additional features that Thales’s FIDO Keys offer for better security and control.
Release Description
12/12/2024
SafeNet FIDO Key Manager for macOS 1.0 introduces the following features:
-
Suppport for biometrics: Allows users to add or remove a fingerprint when using a compatible SafeNet Bio Smart card. This allows users to replace their PIN with a fingerprint during authentication.
-
Support for managing FIDO credentials: Allows users to view and delete the credentials that are registered on a FIDO Key.
-
Pin Management: Users can set a PIN for a new FIDO key as well as change their existing PIN.
-
Device Reset: Users can reset their FIDO keys if they no longer remember their PIN or if they want to clear the credentials on their FIDO keys.
-
Additional features unique to SafeNet FIDO tokens and smartcards:
Available on FIDO 2.1 FIDO Key onwards.
SafeNet FIDO tokens and smartcards can be managed by an administrator to have more control on the FIDO Keys before they are handed over to the users. Some of those administrator features are:
-
Admin PIN Setup: An administrator can set or change admin PIN on a FIDO device that will put the device in the managed mode. When the device is in managed mode, the admin can restrict or control certain capabilities (listed below) that are available on the FIDO device.
-
Unlock PIN: An administrator has the capability to unlock a FIDO device that has been locked due to multiple PIN retries. Utilizing the admin PIN, the device is unlocked, and a new PIN must be set on the device.
-
Application Whitelist: When the administrator manages the FIDO device, they have the authority to limit its usage to specific web applications. This restriction includes limiting storage on the device to add more credentials, ensuring that the device can only be utilized for the approved websites.
-
Minimum PIN Length: Administrators can restrict the device PIN to be set with a specified minimum PIN length.
-
Manage Device Reset: Administrators can limit the capability of users to directly reset the device, mandating the use of an admin PIN before the device can be reset.
-
Limitations
- You cannot reduce the minimum PIN length below the current value, as this may be restricted by the FIDO device you are using.
Known Issues
Issue | Workaround |
---|---|
If user enrolls multiple failed fingerprints before successful one, the application retains and displays the previously assigned friendly names. Furthermore, deleting any of the failed fingerprints will also delete the successfully enrolled fingerprint. | None. |
In the reset flow, when the application prompts the user with the instruction Remove and re-insert your Thales FIDO Key within 20 seconds, if the user inserts another FIDO Key with the same AAGUID as the previously selected FIDO Key, the new device will undergo the reset process. | Ensure that you re-insert the same FIDO key to perform the reset operation on that specific FIDO key only. |
Compatibility Information
Operating System
- macOS devices running macOS Ventura (13.0) or higher
Beta releases of the operating system are not supported.