Factory Reset Heads v2.0+

Reasons for resetting to factory settings

  • Your Nitrokey is locked (e.g. due to multiple incorrect PIN entries)

  • You have lost your Nitrokey (in which case you will first need a new one)

  • You have installed an operating system yourself (e.g. after changing the hard disk)

  • Your operating system does not start

Warning

All GPG keys of your Nitrokey will be deleted during this procedure.

Procedure

  1. Connect your Nitrokey to the NitroPad.

  2. Turn on the NitroPad and interupt the automatic boot by pressing any key.

  3. Select “Options”.

    heads options menu
  4. Select “OEM-Factory Reset /Re-Ownership”.

    reset
  5. Confirm reset with “Continue”.

    confirm
  6. The integrity of your setup will be tested, deppending on your reason to perform the reset this can fail continue with ok anyways

    confirm integrity
  7. You will be prompted with:

    Would you like to use default configuration option?
    If N, you will be prompted for each option [Y/n]:
    

    You can hit enter for the default option (Y).

    A second prompt will show:

    Would you like to export your public key to an USB drive? [y/N]:
    

    Also choose the default option (N) by hitting enter.

    You will need to touch your Nitrokey during this process when asked.

  8. Now it shows all PINs used by Heads:

    defaults

    You will need them for certain procedure so make sure to remember them.

  9. Confirm the subsequent restart.

    reboot
  10. After the restart the OTP secret must be created. Confirm the process with Enter.

    otp secrets generate confirm 1
    otp secrets generate confirm 2
  11. Enter TPM Owner Password (Default: 12345678)

    tpm password enter
  12. Scan QR code with Phone to inport TOTP Seceret (Optional) and hit Enter

    qr code totp

    When asked touch your Nitrokey.

  13. When prompted, enter the Secret App PIN of your Nitrokey (Default: 12345678) and hit Enter

    admin pin nitrokey input
  14. Hit enter and the automatic boot will start.

  15. You will now need to select your default boot, pick the first option and make it default.

    admin pin nitrokey input
  16. This prompt will appear:

Do you wish to add a disk encryption key to the TPM [y/N]:

Hit enter to choose the default option (N).

Please confirm that your GPG card is inserted [Y/n]:

Here also hit enter for the default option (Y).

It will ask for the Admin PIN which is by default (123456).

The reset is done and you are booting in your installed operating system.