Devices
From the Devices view, you can access a comprehensive set of functionalities to manage and interact with your devices.
Here, you can select a device, authenticate to it, and perform various management actions, such as changing or unblocking the PIN.
Open Crescendo Manager and insert your Crescendo Key or Card. The Devices view opens by default unless you have set a different starting screen. In such case, click Devices in the left navigation pane.
Connected devices are shown as tiles.
A device's content is fully loaded when the device's ID is displayed under the device's name.
Actions Available From the Devices View
The actions available from the Devices view depend on the token type and its configuration.
Notably, fewer options are available for , where most features are read-only.
Note: All PIN-related functionalities affect only the -related PIN. The PIN is unaffected unless a shared PIN is set up.
You can select a device by clicking on the respective tile with the device's interface in the Devices view.
You can also select a device from any view via the token selector in the right of the title bar.
Authenticate to a selected device from any view by clicking the authentication button in the right of the title bar.
- A closed red lock symbol indicates that the PIN hasn't been entered, and the device is locked.
- Upon entering the PIN, the symbol changes to an open lock and turns blue , indicating successful authentication.
This authentication applies to future actions performed with the device, although some actions may still require the PIN for confirmation.
If you do not authenticate to a token using the authentication button, some operations will prompt for authentication automatically.
To change the PIN for any connected token, click the Change PIN action link in the device's interface in the Devices view, or click the kebab menu button in the top-right corner of that token's interface. (You do not need to have the token selected to perform this action.)
A simple Change PIN dialog will open:
Tip!
-
The default Crescendo PIN is set to eight zeroes (2300 family) or six zeroes (4000 family). You can enter this default value by selecting the default checkbox.
-
To display the PIN, click and hold the visibility eye icon.
When setting a new PIN, the policy regulating PIN entry is displayed in a bubble above the New PIN field:
This policy can be modified via the Update PIN Policies action, accessible through the kebab menu in the device's interface.
This action enables you to reset the PIN in case it is forgotten or when reassigning a device to a new user.
To unblock the PIN for any connected token, click the Unblock PIN action link in the token's interface in the Devices view, or click the kebab menu button in the top-right corner of that token's interface. (You do not need to have the token selected to perform this action.)
To unblock the PIN:
- Select the authentication data to unblock the token:
Management Key: A hexadecimal string of 32 characters (-128 encryption) or 48 characters ( encryption). For devices in their default state, the management key consists of all zeroes.
Check the default checkbox to enter the default management key.
Unblock Code (PUK): If a has been configured, it can be used here for unblocking. If no PUK has been set up, this method is not available.
Challenge & Response: A string is generated, which has to be encrypted by the administrator using the management key. The resulting output, known as the response, is then entered into the Response field. This method ensures that the management key does not need to be disclosed to the user.
- Insert the new PIN and confirm by entering it into the Confirm PIN field.
- Click Submit to change the PIN.
To manage a device's , navigate to the Devices view and click the kebab menu button in the top-right corner of the token's interface. (You do not need to have the token selected to perform this action.)
This feature allows you to:
- Set new PUK: The PUK can be an 8-digit decimal or a 16-digit hexadecimal number. You can use the Generate button to generate a new hexadecimal PUK.
- Get current PUK: Recover the PUK if you have forgotten it.
- Delete current PUK: Delete an existing PUK.
All the actions above require confirmation with your current PIN unless you have already authenticated to the device using the authentication button in the title bar.
To update the used by your device, navigate to the Devices view and click the kebab menu button in the top-right corner of the token's interface. (You do not need to have the token selected to perform this action.).
Follow these steps to change the management key:
- Select the authentication method for authorizing the management key change (by PIN or by the management key).
If you are already authenticated to the device, you will not be prompted to authorize the key change in the last step.
If you selected to authenticate with PIN, see point 3.
- If you selected to authenticate with the management key, enter the current management key in the provided Old Management Key field. If you are using the default key, select the default checkbox.
- Enter the New Management Key you wish to set. For enhanced security, you can select:
- Random key to generate a new, random AES key.
- Random key to generate a new, random TDES key.
- Click Change Key to finalize the action.
To access Update PIN Policies, navigate to the Devices view and click the kebab menu button in the top-right corner of the token's interface.
This feature allows you to view and update the current PIN policies set for your token. These policies may vary depending on the device type and profile.
Note: For
Crescendo 4000 family devices, the PIN must be in its
initial state for certain policies to be updated. A PIN is in its initial state in factory settings before any changes have been made to it. Once the default PIN has been changed, the only way to restore it to its initial state is by
recycling the device.
Pin Policy Options
-
Min/Max PIN Length: Specify the minimum and maximum PIN length.
-
PIN Format: Choose whether the PIN can include both letters and numbers (alphanumeric format) or numbers only (numeric format).
-
Force PIN Change: When enabled, the token will not allow the user to perform any action until the PIN is changed. Whenever such a token is inserted, Crescendo Manager will display a warning requiring PIN change.
Note: This PIN policy only affects Crescendo 4000 family devices. For the Crescendo 2300 family, setting the Force PIN Change policy will only result in a prompt being displayed upon and will not impact token usage.
-
Challenge Type: Select between static or dynamic mode.
Note: The Static option has been deprecated since the introduction of the Crescendo 4000 family.
-
Control: When this policy is enabled, Crescendo Manager and other Crescendo family tools will not allow the user to select a PIN that is overly simple.
Note: This policy is enforced by the software only; therefore, a weak PIN may still be set using, e.g., the
APDU Access tool.
For enhanced performance, Crescendo Manager internally caches the state of the connected tokens (including token properties, certificates, keys, OTPs, etc.).
Additionally, since Crescendo Manager communicates with devices via Crescendo Minidrivers (one for the Crescendo 2300 family and one for the Crescendo 4000 family), these components also create cache externally to Crescendo Manager.
This action clears both the Minidriver and Crescendo Manager caches for the selected token. This is particularly useful in rare instances when the device's internal state (cache), as recorded by Crescendo Manager, becomes invalid due to external programs communicating with the device or because of an internal error. The Clear Cache functionality is designed to resolve such inconsistencies by reloading the device state.
To clear a token's caches:
-
Navigate to the Devices view and click the kebab menu button in the top-right corner of the token's interface.
-
Click Clear Cache.
-
The caches for the selected token will be cleared.
This action resets the token configuration to its original state, as it was when it left manufacturing.
Warning! The Recycle Device action erases all data from your token, resetting the management key, PIN, and PIN policies to factory default settings.
To recycle a device
-
Navigate to the Devices view and click the kebab menu button in the top-right corner of the token's interface.
-
Select Recycle Device.
-
Authenticate to confirm this action.