Skip to content

Changing A Swissbit iShield Key 2 Pro Mifare PIV Pin

The Security Key is a very powerful cybersecurity device and represents the state-of-the-art in multi-factor authentication (MFA) technology that does not use any passwords. The MFA is supported by the:

  • Possession factor – where the physical possession of the Security Key is essential to the authentication process;
  • Knowledge factor – where know the PIN to the Security Key is also essential to the authentication process.

Since the Security Keys provided with the SB2 use two different NIST-approved, passwordless authentication protocols, there are two containers for the cryptographic keys used with the protocols. Each container is managed by a separate PIN.

However, StrongKey recommends using the SAME PIN to both containers of the Security Key to reduce the burden on users. As long as the Security Key is safely in the possession of the legitimate user, and the legitimate user is NOT sharing the PIN to the Security Key with anyone, the user will be complying with one of the strictest security policies recommended for access control.

This document outlines the process for changing the two required PINs – one for the PIV certificate and the other for the FIDO credential.

AP1 Prerequisites

  • MacOS 13 and above
  • Swissbit iShield Key 2 Pro
  • USB-C port or USB-C-to-USB-A adapter
  • iShield Key Manager

AP2 Open the iShield Key Manager Application

To begin, open the iShield Key Manager application by searching for it with Spotlight (⌘ + Space) or locating it in Finder's Applications folder.

Change Pin

AP3 Select iShield Key Manager

When you open the application, it displays the messages 'No iShield Key found' and 'Please connect your iShield Key via USB or NFC'.

Change Pin

AP4 Insert the iShield Key 2

Plug the Security Key into the USB-C port.

AP5 Identifying the USB-C Port

Locate the USB-C port—typically found along the edge of the computer, it features a compact design with smooth, rounded corners that set it apart from traditional USB-A ports. The image below shows both a USB-C port and its matching male connector.

Change Pin

AP6 No USB-C Port? No Problem.

With the provided USB-A to USB-C adapter, simply plug the USB-A end into the computer and insert the Security Key into the USB-C port.

The provided USB adapter is pictured below.

Change Pin

AP7 Changing the Personal Identity Verification (PIV) PIN

From the home screen, navigate to the lower right-hand side of the screen and open the PIV’s Details & Settings.

Change Pin

AP8 Change PIN Option

Select the Change PIN option.

Note

Unless otherwise specified, each PIN on iShield Key 2 Pro MIFARE, must comply with the following rules:
PIN must be at least 6 characters long

4 identical characters are not permitted (e.g. 2222as), but PIN with 3 identical characters is permitted (e.g. 222asd).

Sequences of numbers are not permitted (e.g. 123456, abcdef).

Change Pin

AP9 Enter PIN Information

  1. Enter the default PIN (112233).
  2. Enter the new PIN. The PIN must contain 6 to 8 characters.
  3. Re-enter the new PIN to confirm then click Change PIN.

Change Pin

AP10 Success!

If the PIN was changed succesfully, a confirmation message will appear near the bottom of the application. StrongKey recommends using the same PIN for setting or changing the FIDO PIN.

AP11 Changing the FIDO PIN

Changing the PIN for the FIDO2 container uses the same procedure as outlined in steps AP8 – AP10. If the Details & Settings button is not accessible, close the iShield Key Manager and reopen but select Run as administrator (see Step AP3).

Note

StrongKey recommends using the same PIN for the FIDO credential.

Change Pin

AP12 Change PIN

Click Change PIN.

Change Pin

AP13 Enter New PIN

  1. Enter the default PIN (112233).
  2. Enter the new PIN. The PIN must contain 6 to 8 characters.
  3. Re-enter the new PIN to confirm then click Change PIN.

Note

Unless otherwise specified, each PIN on iShield Key 2 Pro MIFARE, must comply with the following rules:
PIN must be at least 6 characters long

4 identical characters are not permitted (e.g. 2222as), but PIN with 3 identical characters is permitted (e.g. 222asd).

Sequences of numbers are not permitted (e.g. 123456, abcdef).

Change Pin

AP14 Success!

If the PIN was changed succesfully, a confirmation message will appear near the bottom of the application. StrongKey recommends using the same PIN for setting or changing the FIDO PIN.