Requirements and Frequently Asked Questions for Using Passkey Authentication
Applicable Products
QuTS hero h6.0.0 and later
FIDO2 Server
Required Environment
To use Passkey (FIDO2) authentication on the QNAP NAS, you need to meet the following requirements:
- Connection method: You must connect to the NAS using
HTTPS + Domain Name. An HTTPS connection with a trusted certificate is required.IP addresses and SmartURLs are not supported. - Required component: Install the FIDO2 Server in the App Center. Note that FIDO2 Server has no user interface and will redirect you to the login settings after installation.
- Authenticator support:
- On-device authenticators: Windows Hello (Face, Fingerprint, PIN), Apple Touch ID, PIN
- External authenticators: FIDO-certified USB security keys, mobile or tablet QR code scanning
Procedure
Register a Passkey device
- Ensure the following:
- FIDO2 Server is installed in the App Center.
- You are accessing the NAS is via HTTPS and Domain Name.
- On the NAS, go to Desktop > Login & Security > 2-step Verification & Passwordless Login.
- Click Add Passkey device.
- Follow the on-screen instructions to complete the setup. The steps may differ depending on the device and browser used.
- Follow the instructions for the default authentication method on your device (for example, fingerprint scan or PIN).
- Once verified, the device is successfully registered and listed under Passkey devices.
Log in using a Passkey
- On the NAS login screen, select Login with Passkey.
- Follow the on-screen instructions to use the hardware key. The steps may differ depending on the hardware model and browser used.
- Follow the instructions for the default authentication method on your device (for example, fingerprint scan or PIN).
- Upon successful verification, you will be logged into the NAS desktop.
Supported Security Key Models
Support for security keys varies by operating systems and browsers. Refer to this website for more details. Make sure to access it through web browsers and platforms that support WebAuthn.
We recommend the following security keys, which we have tested:
| Brand | Model Name |
|---|---|
| THETIS | Thetis FIDO2 Security Key |
| Yubico | YubiKey 5 NFC |
| Yubico | YubiKey 5C NFC |
| IDENTIV | uTrust FIDO2 NFC+ Security Key |
| ONLYKEY | OnlyKey (FIDO2 Edition) |
| SoloKeys | Solo V2 |
Common Issues and Limitations
Browser shows "Not Secure" warning after Domain + SSL setup
Even after configuring the domain and SSL, some browsers may still show a "Not Secure" warning. Try using incognito mode or open a new tab and then reconnect via https://domain name
For details, see this FAQ.
SmartURL (for example, qlink.to) is not supported
SmartURLs may redirect to different URLs over time. If a Passkey is registered before the change, it will no longer work. Therefore, SmartURLs are not supported.
For example: https://qlink.to/alicetest is not supported.
However, myQNAPcloud DDNS is supported. For example: alicetest.myqnapcloud.com
High Availability architecture support
When using HA architecture, ensure that you connect via Domain Name and map the domain to CIP to enable passkey registration and login.
Further Reading
How do I install a Let’s Encrypt SSL certificate for my custom DDNS domain in QTS?
How to purchase and install a myQNAPcloud SSL certificate?
For further assistance, ask other users and QNAP experts in the community. Go to QNAP Community