<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2018-01-30T09:26:55+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php</id>
<entry>
<author><name><![CDATA[Tom2]]></name></author>
<updated>2018-01-30T09:26:55+01:00</updated>
<published>2018-01-30T09:26:55+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2835&amp;p=10136#p10136</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2835&amp;p=10136#p10136"/>
<title type="html"><![CDATA[[Community] - Forum going read only. New KDB on its way.]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2835&amp;p=10136#p10136"><![CDATA[
For the security and experience of our user community, we have decided to set the forum as read-only and wipe all user account information. All historical posts and announcements will be archived and remain publicly searchable. <br /><br />In 2018, we will be publishing a searchable knowledge-base system that allows the community to provide direct feedback on articles and make suggestions that will be reviewed by Yubico staff. We sincerely appreciate the participation of our user forum over the years and hope to continue serving your for years to come.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3364">Tom2</a> — Tue Jan 30, 2018 9:26 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[ChrisHalos]]></name></author>
<updated>2018-01-30T09:10:29+01:00</updated>
<published>2018-01-30T09:10:29+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2834&amp;p=10135#p10135</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2834&amp;p=10135#p10135"/>
<title type="html"><![CDATA[Yubikey NEO • Re: Yubikey Resetting code]]></title>

<category term="Yubikey NEO" scheme="https://forum.yubico.com/viewforum.php?f=26" label="Yubikey NEO"/>
<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2834&amp;p=10135#p10135"><![CDATA[
<!-- l --><a class="postlink-local" href="https://forum.yubico.com/viewtopic.php?f=26&amp;t=2147">viewtopic.php?f=26&amp;t=2147</a><!-- l --><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3140">ChrisHalos</a> — Tue Jan 30, 2018 9:10 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[jfjallid]]></name></author>
<updated>2018-01-29T13:13:21+01:00</updated>
<published>2018-01-29T13:13:21+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2834&amp;p=10134#p10134</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2834&amp;p=10134#p10134"/>
<title type="html"><![CDATA[Yubikey NEO • Yubikey Resetting code]]></title>

<category term="Yubikey NEO" scheme="https://forum.yubico.com/viewforum.php?f=26" label="Yubikey NEO"/>
<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2834&amp;p=10134#p10134"><![CDATA[
So I have read that you can configure a Resetting Code for the OpenPGP applet which can be used to reset the pin.<br />The command to be used is supposed to be: RESET RETRY COUNTER but I've not found any information on how to send the command. <br />Are there any utilities to use the Resetting Code for the yubikey, or how is it supposed to work?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=5075">jfjallid</a> — Mon Jan 29, 2018 1:13 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[jkl]]></name></author>
<updated>2018-01-25T17:25:41+01:00</updated>
<published>2018-01-25T17:25:41+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2833&amp;p=10133#p10133</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2833&amp;p=10133#p10133"/>
<title type="html"><![CDATA[Computer Logon - Windows | Linux | MacOS | freeBSD • [QUESTION] Keep Win10 system from crashing -- network share]]></title>

<category term="Computer Logon - Windows | Linux | MacOS | freeBSD" scheme="https://forum.yubico.com/viewforum.php?f=23" label="Computer Logon - Windows | Linux | MacOS | freeBSD"/>
<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2833&amp;p=10133#p10133"><![CDATA[
I have Yubikey 4 set up for several different users on non-domain Windows 10 systems using the Windows Logon Tool.  I have a network share set up on each system for users to transfer files.  They have a random, but persistent problem of the system crashing and rebooting when accessing the file share.  From the logs, there is a fatal error in the lsass.exe process, requiring the system to reboot.  Upon reboot, the Windows Logon Tool no longer authenticates the user with the configured Yubikey and requires reconfiguration to log in.  Note that the crash does not occur when the Windows Logon Tool is disabled.<br /><br /><br />[*]Users authenticate with the Yubikey inserted into the server hosting the share (or identically configured Yubikeys inserted into both the client and server).  <br />[*]When crashes occur, it is usually at or near the end of a file transfer.  <br />[*]Crashes appear more likely if systems connect to each other in serial.  <br />[*]Once crashes occur, it appears to be more likely that crashes will continue to occur.<br /><br /><br />Do you have any information on what can be done to prevent these crashes?<br /><br /><br />As an afterthought, are there group policy security settings that could be interfering with Windows Logon Tool authentication over the network and making it unstable (but mostly functional)?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=5069">jkl</a> — Thu Jan 25, 2018 5:25 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Murali]]></name></author>
<updated>2018-01-24T11:30:14+01:00</updated>
<published>2018-01-24T11:30:14+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2832&amp;p=10132#p10132</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2832&amp;p=10132#p10132"/>
<title type="html"><![CDATA[YubiKey 4 • YubiKey 4  on MAC - ABORT has been sent to the transform]]></title>

<category term="YubiKey 4" scheme="https://forum.yubico.com/viewforum.php?f=35" label="YubiKey 4"/>
<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2832&amp;p=10132#p10132"><![CDATA[
Hi,<br /><br />I am trying to sign some data with the certificate PrivateKey ( Certificate was loaded into slot 9c(Digital signature) on My YubiKey4 using Yubikey PIV Manager v1.4.2) on Mac High Sierra.<br /><br />Below  OSX APIs were used to sign the data using the certificate,<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">    SecTransformRef signingTransform = NULL;<br />    signingTransform = SecSignTransformCreate(privateKeyRef, NULL);<br />    NSString *stingSign = @&quot;Some string&quot;;<br />    CFDataRef sourceData = CFDataCreate(<br />                                        kCFAllocatorDefault,<br />                                        (const unsigned char *)&#91;stingSign UTF8String&#93;,<br />                                        stingSign.length<br />                                        );<br />    CFErrorRef error = NULL;<br />    SecTransformSetAttribute(<br />                             signingTransform,<br />                             kSecTransformInputAttributeName,<br />                             sourceData,<br />                             &amp;error);<br />    if (error)<br />      {<br />        NSLog(@&quot;Error : %@&quot;,&#91;((__bridge NSError*)error) description&#93;);<br />      }<br />   ..... Remaining execution code goes here<br /></div><br />but i am getting <div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />Error : Error Domain=com.apple.security.transforms.error Code=20 &quot;ABORT has been sent to the transform (Error Domain=Internal CSSM error Code=-25304 &quot;Internal error #ffff9d28 at SignTransform_block_invoke /BuildRoot/Library/Caches/com.apple.xbs/Sources/Security/Security-58286.31.2/OSX/libsecurity_transform/lib/SecSignVerifyTransform.c:411&quot; UserInfo={NSDescription=Internal error #ffff9d28 at SignTransform_block_invoke /BuildRoot/Library/Caches/com.apple.xbs/Sources/Security/Security-58286.31.2/OSX/libsecurity_transform/lib/SecSignVerifyTransform.c:411, Originating Transform=CoreFoundationObject})&quot; UserInfo={NSDescription=ABORT has been sent to the transform (Error Domain=Internal CSSM error Code=-25304 &quot;Internal error #ffff9d28 at SignTransform_block_invoke /BuildRoot/Library/Caches/com.apple.xbs/Sources/Security/Security-58286.31.2/OSX/libsecurity_transform/lib/SecSignVerifyTransform.c:411&quot; UserInfo={NSDescription=Internal error #ffff9d28 at SignTransform_block_invoke /BuildRoot/Library/Caches/com.apple.xbs/Sources/Security/Security-58286.31.2/OSX/libsecurity_transform/lib/SecSignVerifyTransform.c:411, Originating Transform=CoreFoundationObject})}<br /></div><br /><br />Do I need to do any extra configuration to execute this code? or am I missing something while setup? same code is working fine if I sign with the same certificate on eToken smartcard.<br /><br />Please help us.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=5066">Murali</a> — Wed Jan 24, 2018 11:30 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[RadiatorMints]]></name></author>
<updated>2018-01-23T22:02:43+01:00</updated>
<published>2018-01-23T22:02:43+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10131#p10131</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10131#p10131"/>
<title type="html"><![CDATA[Computer Logon - Windows | Linux | MacOS | freeBSD • Re: YubiKey 4 for PIV stopped working]]></title>

<category term="Computer Logon - Windows | Linux | MacOS | freeBSD" scheme="https://forum.yubico.com/viewforum.php?f=23" label="Computer Logon - Windows | Linux | MacOS | freeBSD"/>
<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10131#p10131"><![CDATA[
<div class="quotetitle">JamesA wrote:</div><div class="quotecontent"><br />For enroll on behalf of (EOBO) you also need to set the publish and enroll in the &quot;Enrollment Agent&quot; template as covered in the Smart Card Deployment Guide. <br /><br />Regarding your issue with self-enrollment, please open a support ticket for further troubleshooting. <!-- m --><a class="postlink" href="https://www.yubico.com/support/get-support/">https://www.yubico.com/support/get-support/</a><!-- m --><br /></div><br /><br />The Enrollment Agent template was also published.  I was able to pull the cert and get almost all the way through enrollment before it failed due to policy.<br /><br />Today I extinguished all doubt by troubleshooting the entire PKI stack with this guide:<br /><!-- m --><a class="postlink" href="https://blogs.technet.microsoft.com/askds/2007/11/06/how-to-troubleshoot-certificate-enrollment-in-the-mmc-certificate-snap-in/">https://blogs.technet.microsoft.com/ask ... e-snap-in/</a><!-- m --><br /><br />I ran RSOP.msc to see if there were any conflicts with GPOs but everything was configured the way I expected.<br />I was still getting the 'blocked by computer policy' error so I disabled all of my computer GPOs and self enrollment worked.  By turning things back on one at a time I determined that my Yubikey GPO was to blame.  I believe it's one or both of my registry edits: <br /><br />BlockPUKOnMGMUpgrade<br />or<br />NewKeyTouchPolicy<br /><br />What I'm working backwards to understand is how the YubiKeys were getting the certificate installed in 9a -only with the PIV Manager- but weren't able to authenticate.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=5062">RadiatorMints</a> — Tue Jan 23, 2018 10:02 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[JamesA]]></name></author>
<updated>2018-01-23T21:47:21+01:00</updated>
<published>2018-01-23T21:47:21+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10130#p10130</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10130#p10130"/>
<title type="html"><![CDATA[Computer Logon - Windows | Linux | MacOS | freeBSD • Re: YubiKey 4 for PIV stopped working]]></title>

<category term="Computer Logon - Windows | Linux | MacOS | freeBSD" scheme="https://forum.yubico.com/viewforum.php?f=23" label="Computer Logon - Windows | Linux | MacOS | freeBSD"/>
<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10130#p10130"><![CDATA[
For enroll on behalf of (EOBO) you also need to set the publish and enroll in the &quot;Enrollment Agent&quot; template as covered in the Smart Card Deployment Guide. <br /><br />Regarding your issue with self-enrollment, please open a support ticket for further troubleshooting. <!-- m --><a class="postlink" href="https://www.yubico.com/support/get-support/">https://www.yubico.com/support/get-support/</a><!-- m --><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4981">JamesA</a> — Tue Jan 23, 2018 9:47 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[tinkster]]></name></author>
<updated>2018-01-23T21:03:14+01:00</updated>
<published>2018-01-23T21:03:14+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2831&amp;p=10129#p10129</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2831&amp;p=10129#p10129"/>
<title type="html"><![CDATA[Yubikey NEO • Re: [QUESTION] Neo &amp; ssh ... works on Linux, not on Mac]]></title>

<category term="Yubikey NEO" scheme="https://forum.yubico.com/viewforum.php?f=26" label="Yubikey NEO"/>
<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2831&amp;p=10129#p10129"><![CDATA[
<div class="quotetitle">tinkster wrote:</div><div class="quotecontent"><br />Hi,<br /><br />I have installed the yubi_u2f PAM module on my linux workstation. Connecting via ssh to localhost works - I type ssh andrej@host, get<br />a password prompt, and get connected when I push the button on the neo after that; plugging  the neo into my macbook air and trying <br />to connect to my linux box via ssh fails; ought to say that I could happily connect to it from the mac yesterday (w/o the yubi_u2f), using<br />either password or public-key access.  Now it's no-show. What am I doing wrong? :)<br /><br />Cheers,<br />Andrej<br /></div><br /><br /><br />So ... for shits &amp; giggles I tried to connect from the Mac to Linux box while the Neo was on the linux box.  Doing the password<br />typy-typy thing on the mac and then pushing the button attached to the Linux box established a session. Huh? :D<br /><br />What *did* I do wrong?<br /><br /><br />Cheers,<br />Andrej<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=5067">tinkster</a> — Tue Jan 23, 2018 9:03 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[tinkster]]></name></author>
<updated>2018-01-23T20:45:36+01:00</updated>
<published>2018-01-23T20:45:36+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2831&amp;p=10128#p10128</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2831&amp;p=10128#p10128"/>
<title type="html"><![CDATA[Yubikey NEO • [QUESTION] Neo &amp; ssh ... works on Linux, not on Mac]]></title>

<category term="Yubikey NEO" scheme="https://forum.yubico.com/viewforum.php?f=26" label="Yubikey NEO"/>
<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2831&amp;p=10128#p10128"><![CDATA[
Hi,<br /><br />I have installed the yubi_u2f PAM module on my linux workstation. Connecting via ssh to localhost works - I type ssh andrej@host, get<br />a password prompt, and get connected when I push the button on the neo after that; plugging  the neo into my macbook air and trying <br />to connect to my linux box via ssh fails; ought to say that I could happily connect to it from the mac yesterday (w/o the yubi_u2f), using<br />either password or public-key access.  Now it's no-show. What am I doing wrong? :)<br /><br />Cheers,<br />Andrej<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=5067">tinkster</a> — Tue Jan 23, 2018 8:45 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[RadiatorMints]]></name></author>
<updated>2018-01-22T20:20:54+01:00</updated>
<published>2018-01-22T20:20:54+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10127#p10127</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10127#p10127"/>
<title type="html"><![CDATA[Computer Logon - Windows | Linux | MacOS | freeBSD • Re: YubiKey 4 for PIV stopped working]]></title>

<category term="Computer Logon - Windows | Linux | MacOS | freeBSD" scheme="https://forum.yubico.com/viewforum.php?f=23" label="Computer Logon - Windows | Linux | MacOS | freeBSD"/>
<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10127#p10127"><![CDATA[
Found rev B which has auto-enrollment stuff in it.<br /><!-- m --><a class="postlink" href="https://www.yubico.com/wp-content/uploads/2017/10/YubiKey_Smart_Card_Deployment_Guide_10_2017_RevB.pdf">https://www.yubico.com/wp-content/uploa ... 7_RevB.pdf</a><!-- m --><br />Actions taken today (1/22/2018):<br />Revoked all previous user certs except the one that works.<br />Reissued the root domain cert and verified through cert chains that it is being used.<br />Pushed all the auto-enrollment config via GPO and found it in the system tray.  (Fails with a message about &quot;Prohibited by Computer Policy&quot; weather it's launched from the tray or certmgr)<br />Added a brand new PC to the domain and logged in via the one working YubiKey 4 on the first boot with no configuration other than previously configured GPOs.<br /><br />EDIT: per the documentation under the Cryptography tab: <br />Provider Category is now Key Storage Provider<br />Algo is RSA, length is default: 2048<br />Provider is Microsoft Smart Card Key Storage Provider<br /><br />What am I missing?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=5062">RadiatorMints</a> — Mon Jan 22, 2018 8:20 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[gg94700]]></name></author>
<updated>2018-01-22T13:17:17+01:00</updated>
<published>2018-01-22T13:17:17+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2830&amp;p=10126#p10126</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2830&amp;p=10126#p10126"/>
<title type="html"><![CDATA[YubiKey 4 • Occurred while decrypting a message the hand is invalid]]></title>

<category term="YubiKey 4" scheme="https://forum.yubico.com/viewforum.php?f=35" label="YubiKey 4"/>
<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2830&amp;p=10126#p10126"><![CDATA[
Hi,<br /><br />When trying open a keepass database protected with a certificate on the yubikey into a 2008R2 (inside a ICA session citrix XenApp 6.5), i run across the following message :<br /><br />An error occurred while decrypting a message: The handle is invalid.<br /><br />First i have the PIN prompt and after PIN validation, i have the error as you can see on the image.<br /><br /><strong>It work very well inside a RDP session on the same server !<br />And it works also in a ICA session citrix XenApp version 7.9 !</strong><br /><br />When i use putty and pageant wincrypt, i have the following error : <br />__________________________________________________________________________________________<br />login as: root<br />Authenticating with public key &quot;cert://cn=adminrescue,thumbprint=6786370c2e56f50                    6679a116758951a1e0cd7686d&quot; from agent<br />Server refused public-key signature despite accepting key!<br />Using keyboard-interactive authentication.<br />Password:<br />__________________________________________________________________________________________<br /><br />it tells me incorrect signature ???<br /><br />Can you help me to track what's going wrong ?<br /><br /><br />Thanks<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=5065">gg94700</a> — Mon Jan 22, 2018 1:17 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[jbenfeld]]></name></author>
<updated>2018-01-21T21:56:56+01:00</updated>
<published>2018-01-21T21:56:56+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2829&amp;p=10125#p10125</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2829&amp;p=10125#p10125"/>
<title type="html"><![CDATA[Yubikey NEO • Re: gpg --card-status and Card error message]]></title>

<category term="Yubikey NEO" scheme="https://forum.yubico.com/viewforum.php?f=26" label="Yubikey NEO"/>
<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2829&amp;p=10125#p10125"><![CDATA[
having tried again, <br />I get this message:<br /><br />C:\Users\myaccount&gt;gpg --card-status<br /><br />gpg: OpenPGP card not available: Not supported<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=5064">jbenfeld</a> — Sun Jan 21, 2018 9:56 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[jbenfeld]]></name></author>
<updated>2018-01-21T21:32:31+01:00</updated>
<published>2018-01-21T21:32:31+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2829&amp;p=10124#p10124</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2829&amp;p=10124#p10124"/>
<title type="html"><![CDATA[Yubikey NEO • gpg --card-status and Card error message]]></title>

<category term="Yubikey NEO" scheme="https://forum.yubico.com/viewforum.php?f=26" label="Yubikey NEO"/>
<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2829&amp;p=10124#p10124"><![CDATA[
Microsoft Windows [Version 10.0.16299.192]<br />(c) 2017 Microsoft Corporation. All rights reserved.<br /><br />C:\Users\myaccount&gt;gpg --card-status<br />gpg: selecting openpgp failed: Card error<br />gpg: OpenPGP card not available: Card error<br /><br />Does anyone know how to solve this error?<br /><br />regards<br />JB<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=5064">jbenfeld</a> — Sun Jan 21, 2018 9:32 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[RadiatorMints]]></name></author>
<updated>2018-01-22T20:55:53+01:00</updated>
<published>2018-01-19T16:51:41+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10123#p10123</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10123#p10123"/>
<title type="html"><![CDATA[Computer Logon - Windows | Linux | MacOS | freeBSD • YubiKey 4 for PIV stopped working]]></title>

<category term="Computer Logon - Windows | Linux | MacOS | freeBSD" scheme="https://forum.yubico.com/viewforum.php?f=23" label="Computer Logon - Windows | Linux | MacOS | freeBSD"/>
<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10123#p10123"><![CDATA[
Earlier this month I purchased one YubiKey 4 for a proof of concept for OTP login using a 3rd party solution. In the interest of compatibility and simplicity we chose to back down to PIV. I followed the deployment instructions and in a matter of nearly no time my YubiKey 4 was doing PIV smartcard login on domain computers.<br /><br />So I purchased the rest of the YubiKeys I needed for my users, implemented the Enroll on behalf of CA Template and that's when everything went completely sideways. Enroll on behalf of didn't seem to work at all, the template couldn't find the signature &gt; no certificate on the YubiKey &gt; cert enrollment failure on the CA. So I'm back to user self enrollment and I can get a certificate on a YubiKey. The PIV manager recognizes it, it's published in the Certificate Authority but any time I try to use it for login the endpoint says that &quot;No valid certificates were found on this smart card.&quot;<br /><br />My original YubiKey and cert still works flawlessly. Changing out YubiKeys yields the same results (failure). I changed the name of the original template and recreated a new one from scratch with the following settings:<br /><br /><strong>General</strong><br />Validity period is 2 years<br />Cert is published in AD<br /><strong>Compatibility</strong><br />CA is Server 2016<br />Recipient is Windows 7<br /><strong>Request handling</strong><br />Signature and encryption<br />Include symmetric algorithms allowed by the subject<br />Prompt user during enrollment<br /><strong>Cryptography</strong><br />Note: italicized text refers to a configuration that has since been changed<br />Key Storage Provider<br />RSA<br />Key Size 2048<br />Requests must use Microsoft Smart Card Key Storage Provider<br /><br /><em>Legacy Cryptographic Service Provider<br />Algo determined by CSP<br />Requests must use Microsoft Enhanced Cryptographic Provider v1.0</em><br /><br /><strong>Security</strong><br />Authenticated users may read and enroll<br />Admins can read, write, and enroll<br /><br />I'm happy to answer any questions (within the realm of reason).<br /><br />Update: I replicated those template settings with a new, longer, unique name, made sure it was published to the CA and waited the 20 minutes.  It still isn't working.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=5062">RadiatorMints</a> — Fri Jan 19, 2018 4:51 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[woocash]]></name></author>
<updated>2018-01-19T13:06:51+01:00</updated>
<published>2018-01-19T13:06:51+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2826&amp;p=10121#p10121</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2826&amp;p=10121#p10121"/>
<title type="html"><![CDATA[YubiKey 4 • S/MIME basics]]></title>

<category term="YubiKey 4" scheme="https://forum.yubico.com/viewforum.php?f=35" label="YubiKey 4"/>
<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2826&amp;p=10121#p10121"><![CDATA[
Hi, first post here <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":)" title="Smile" /><br /><br />I am using SMIME certificate on Yubikey for a year now. Now i need to exchange it for a renewed one. Two questions I have:<br /><br />1. Why in all docs it says that &quot;certificate&quot; is on the yubikey, nothing about &quot;private key&quot;, even though it also is there? Is the term &quot;certificate&quot; used for a package of public+private key, not only public one?<br />2. How do I save new smime cert while retaining the old one for stored mail decryption?<br /><br />Cheers!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=5060">woocash</a> — Fri Jan 19, 2018 1:06 pm</p><hr />
]]></content>
</entry>
</feed>