Factory Reset Heads v2.0+¶
Reasons for resetting to factory settings¶
Your Nitrokey is locked (e.g. due to multiple incorrect PIN entries)
You have lost your Nitrokey (in which case you will first need a new one)
You have installed an operating system yourself (e.g. after changing the hard disk)
Your operating system does not start
Warning
All GPG keys of your Nitrokey will be deleted during this procedure.
Procedure¶
Connect your Nitrokey to the NitroPad.
Turn on the NitroPad and interupt the automatic boot by pressing any key.
Select “Options”.
Select “OEM-Factory Reset /Re-Ownership”.
Confirm reset with “Continue”.
The integrity of your setup will be tested, deppending on your reason to perform the reset this can fail continue with ok anyways
You will be prompted with:
Would you like to use default configuration option? If N, you will be prompted for each option [Y/n]:
Hit enter for the default option (Y).
A second prompt will show:
Would you like to export your public key to an USB drive? [y/N]:
Hit enter for the default option (N).
You will need to touch your Nitrokey during this process when asked.
Now it shows all PINs used by Heads:
You will need them for certain procedure so make sure to remember them.
Confirm the subsequent restart.
After the restart the OTP secret must be created. Confirm the process with Enter.
Enter TPM Owner Password (Default: 12345678)
Scan QR code with Phone to inport TOTP Seceret (Optional) and hit Enter
When asked touch your Nitrokey.
When prompted, enter the Secret App PIN of your Nitrokey (Default: 12345678) and hit Enter
Hit enter and the automatic boot will start.
You will now need to select your default boot, pick the first option and make it default.
This prompt will appear:
Do you wish to add a disk encryption key to the TPM [y/N]:
Hit enter to choose the default option (N).
Please confirm that your GPG card is inserted [Y/n]:
Here also hit enter for the default option (Y).
It will ask for the Admin PIN which is by default (123456).
The reset is done and you are booting in your installed operating system.
Connect your Nitrokey to the NitroPad.
Turn on the NitroPad.
Select “Options”.
Select “OEM-Factory Reset /Re-Ownership”.
Confirm Reset with “Continue”.
The integrity of your Setup will be tested, deppending on your reason to perform the reset this can fail continue with ok anyways
The following Question can all be answered with the Default. Just hit enter if you only want to reset your device.
Would you like to change the current LUKS Disk Recovery Key passphrase? (Highly recommended if you didn't install the Operating System yourself, so that past provisioned passphrase would not permit to access content. Note that without re-encrypting disk, a backuped header could be restored to access encrypted content with old passphrase) [y/N]: N Would you like to re-encrypt LUKS encrypted container and generate new Disk Recovery key? (Highly recommended if you didn't install the operating system yourself: this would prevent any LUKS backuped header to be restored to access encrypted data) [y/N]: N The following security components will be provisioned with defaults or chosen PINs/passwords: TPM Ownership password GPG Admin PIN GPG User PIN Would you like to set a single custom password that will be provisioned to previously stated security components? [y/N]: N Would you like to set distinct PINs/passwords to be provisioned to previously stated security components? [y/N]: N Would you like to set custom user Information for the GnPG key?[y/N]: N Would you like to set custom user information for the GnuPG key? [y/N]: N Checking for USB Security Dongle... Detecting and setting boot device... Boot device set to /dev/nvme0n1p2 Resetting TPM... Resetting GPG Key... (this will take around 3 minuts...) Changing default GPG Admin PIN Changing default GPG User PIN Reading current firmware (this will take a minute or two) Adding generated key to current firmware and re-flashing... Signing boot files and generating checksums
It will show the Default GPG PINS and TPM Password
Confirm the subsequent restart.
After the restart the OTP secret must be created. Confirm the process with Enter.
Enter TPM Password (Default: 12345678)
Scan QR COde with Phone to inport TOTP Seceret (Optional) and hit Enter
When prompted, enter the Admin PIN of your Nitrokey (Default: 12345678) and hit Enter
You should then reach the Start menu.
Press Enter to start the “Default Boot”.
Note
If you see the message that no default exists yet, please follow the procedure described in default boot.
Note
Only for firmware till version 1.4
Connect any USB flash drive to the NitroPad. (You need that USB flash drive for saving your security key)
Connect your Nitrokey to the NitroPad.
Turn on the NitroPad.
Select “Options”.
Select “OEM-Factory Reset”.
Warning
All your data will be lost if you reset your device. Therefore please backup your data before performing the reset.
Confirm the “OEM Factory Reset” with “Continue”.
You will be asked if you want to set the User and Admin/TPM PIN yourself. You press Enter to continue without changing the PINs.
You will then be asked if manual user information should be added. You confirm with
yand enter your name and then the email address.Would you like to set a custom password?[y/N]: Would you like to set custom user Information for the GnPG key?[y/N]: y Please enter the following Information... Real name: "your name" Email adress: "your email-adress" Comment: Checking for USB media... New value of PCR[5]: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx [ xx.xxxxxx] sd 6:0:0:0: [sdb] No Caching mode page found [ xx.xxxxxx] sd 6:0:0:0: [sdb] Assuming drive cache: write through Checking for GPG Key... Detecting and setting boot device... Boot device set to /dev/sda1 Resetting TPM... Resetting GPG Key... (this will take a minute or two)
If you are using Nitrokey Storage, you must then select the drive. If the drives /dev/sdb1, /dev/sdc, /dev/sdd1 are displayed, select /dev/sdd1. If the drives /dev/sdb1, /dev/sdc1, /dev/sdd are displayed, select /dev/sdb1.
The rest of the configuration will be done automatically. You confirm the subsequent restart.
After the restart the OTP secret must be created. Confirm the process with Enter.
Confirm that new OTP Secrets should be created.
When prompted, enter the Admin PIN and TPM password. Both are by default: “12345678”.
You should then reach the Start menu.
Press Enter to start the “Default Boot”.
Note
If you see the message that no default exists yet, please follow the procedure described in “Troubleshooting: Default Boot Menu”.
Once the operating system starts until the encryption password is requested, you are done.
Finally, copy the public PGP key from the data stick to your computer, e.g. to use it for e-mail encryption.