I login maybe once a year on my domain registrar's website (Gandi). Something has changed in both Firefox/Chromium since last time, because neither of them accepted any of my Yubikeys anymore: it prompted for a PIN, and I don't remember setting one! (I set one on the OpenPGP application, but that PIN is not accepted for FIDO2).
Temporarily disabling FIDO2 allowed the login to succeed as documented here: https://support.yubico.com/s/article/Understanding-YubiKey-PINs https://support.yubico.com/s/article/Enabling-or-disabling-applications
Note that this does *not* reset FIDO2 (Which IIUC would delete the FIDO U2F key too).
In that case IIUC it uses FIDO U2F instead of FIDO2 with a PIN. Although this seems like a bug, why doesn't the browser offer me the option of using U2F when I reject providing a FIDO2 PIN? Clearly all this worked fine several years ago when I initially registered the Yubikeys.
#FIDO2 #Yubikey #U2F
![Gandi is evolving, and so is its security!
Security keys now use a new protocol. Keys registered before September 10, 2019, are no longer compatible and have been deactivated.
Therefore, we have removed your security keys: [redacted] from your account.
To maintain a satisfactory level of security, we have enabled MFA via email for your account.
However, you can re-register them in your administration console, in the ACCOUNT application](https://files.mastodon.social/cache/media_attachments/files/115/690/254/104/311/592/small/7b88d93c702f8b28.png)

