> For the complete documentation index, see [llms.txt](https://yubico.gitbook.io/yubikey5/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://yubico.gitbook.io/yubikey5/guides/understanding-pins/piv.md).

# PIV

An explanation of the PINs associated to the PIV interface.

## <mark style="color:red;">❊ PIV</mark>

PIV is a technology / interface on your Yubikey, which stands for **Personal Identity Verification**.

This interface allows you to create certificates which are stored on your Yubikey in the PIV interface and interact with non-web interfaces / applications.

Imported certificates in your PIV allow you to do some cool things such as:

* Unlock a <mark style="color:red;">**Bitlocker**</mark> encrypted drive.
* Encrypt / Decrypt individual files using EFS for Microsoft Windows.
* Sign into a server you own with <mark style="color:red;">**`SSH`**</mark> (even passwordless if you want).
* Sign documents with programs like <mark style="color:red;">**`Adobe Acrobat`**</mark>.
* Sign code with programs such as Microsoft's <mark style="color:red;">**`Signtool`**</mark> or Windows Powershell's <mark style="color:red;">**`Set-AuthenticodeSignature`**</mark> command.

If none of these sound appealing to you, then you may never use PIV.&#x20;

### <mark style="color:blue;">PIV PINs</mark>

Now we'll explain the 2 PINs for the PIV interface.

One PIN is simply called <mark style="color:red;">**PIN**</mark> and the other is the <mark style="color:red;">**PUK**</mark>.

<table><thead><tr><th width="142.33333333333331">Type</th><th>Name</th><th>Default</th></tr></thead><tbody><tr><td><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20(1).png?alt=media&amp;token=8ac71312-243b-4852-999d-74eaa595ec54" alt=""> <a href="#pin-user"><mark style="color:red;"><strong>PIN</strong></mark></a></td><td>Personal Identification Number</td><td>123456</td></tr><tr><td><img src="https://3439786616-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FFqFACNHWgp8HSNubDNCu%2Fuploads%2FvruVNIOWoWHUaDrROjUK%2Flink%20(1).png?alt=media&amp;token=8ac71312-243b-4852-999d-74eaa595ec54" alt=""> <a href="#puk-admin"><mark style="color:red;"><strong>PUK</strong></mark></a></td><td>PIN Unblocking Key</td><td>12345678</td></tr></tbody></table>

#### <mark style="color:yellow;">PIN (User)</mark>

99% of the time if you do anything related to the PIV interface and a PIN dialog appears; it will be asking for this PIN. It is the normal user PIN. It usually pops up if you try to unlock your Bitlocker drive, when you sign code, when you authenticate with SSH, encrypt/decrypt with EFS, or any other regular action.

#### <mark style="color:yellow;">PUK (Admin)</mark>

The PUK only has one purpose. It is used if you type your regular USER PIN incorrectly too many times and you get locked out.  When you do things like sign into SSH using your PIV certificates, you're only allowed to incorrectly give your user PIN a certain number of times. If you supply your user PIN incorrectly too many times, your <mark style="color:red;">**`user PIN`**</mark> will then be <mark style="color:red;">**`locked`**</mark> out. You will then need to use the <mark style="color:blue;">**`PUK`**</mark> in order to <mark style="color:blue;">**`unlock`**</mark> your user PIN.

### <mark style="color:blue;">PIV Management Key</mark>

The last code you need to know about for PIV is the <mark style="color:red;">**Management Key**</mark>.

<table><thead><tr><th width="223">Name</th><th>Default</th></tr></thead><tbody><tr><td>Management Key</td><td>010203040506070801020304050607080102030405060708</td></tr></tbody></table>

This is a long code that is typically asked for you to enter if you do administrative tasks such as importing a x509 certificate onto your Yubikey. Or it will ask you to enter this code if you generate a new certificate on your Yubikey using programs like Yubikey Manager or the ykman command-line.

If you never use PIV, then you'll never need this.
