Is the PIVKey Admin Key Blocked?

If you enter the wrong Admin Key more than 5 times in a row, the Admin Key will be permanently blocked, and cannot be used for unblocking or other purposes. If your card is blocked, it is still functional.  For most users the only change is that they cannot unblock their User PIN. 

How can you tell if the Admin key is blocked?

You can do this by changing the admin key. Make sure you have the correct Admin Key, or the process of trying to change the Admin Key itself may block the Admin Key.

To use the pivkeytool.exe utility, run the following command using your actual Admin Key:

pivkeytool.exe --changeadminkey "000000000000000000000000000000000000000000000000" --adminkey "000000000000000000000000000000000000000000000000"

Admin key changed

If you see the "Admin key changed" message, your Admin Key is not blocked, and has been reset to 5 tries.

Change admin key failed. X attempts remaining

If you see the "Change admin key failed. X attempts remaining" message, you are most likely using the wrong Admin Key. You card is not blocked, but you have only 4,3,2 or 1 attempts left, after which the card will be blocked. Verify the correct Admin Key before you use the Admin key again.  NOTE:  See this article for possible problems with the Admin Key.

Change admin key failed. -1 attempts remaining

If you see the "Change admin key failed. -1 attempts remaining" error, your card is blocked.

Using the VSEC Utility

To check the Admin key using the VSEC utility, go to the "Change Admin Key" tab. Enter the current Admin key as both the current and new admin key. Click "Copy" and then click "Change Key".

 If the cards is blocked you will see the following error:

Blocking a card

The steps to a blocked card are as followed:

Have more questions? Submit a request


Article is closed for comments.
Powered by Zendesk