<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=16&amp;t=2190" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2016-02-01T21:37:10+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=16&amp;t=2190</id>
<entry>
<author><name><![CDATA[ChrisHalos]]></name></author>
<updated>2016-02-01T21:37:10+01:00</updated>
<published>2016-02-01T21:37:10+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2190&amp;p=8241#p8241</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2190&amp;p=8241#p8241"/>
<title type="html"><![CDATA[Re: [QUESTION] Yubikey 4 and 4096 Key Length]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2190&amp;p=8241#p8241"><![CDATA[
It's probably your gpg version. Works fine for me using gpg v 2.0.29 on Windows. I follow the instructions here - <!-- m --><a class="postlink" href="https://developers.yubico.com/PGP/Importing_keys.html">https://developers.yubico.com/PGP/Importing_keys.html</a><!-- m --><br /><br />[apologies in advance for the length]<br /><br />C:\Users\Chris&gt;gpg --edit-key 6B23937C<br />gpg (GnuPG) 2.0.29; Copyright (C) 2015 Free Software Foundation, Inc.<br />This is free software: you are free to change and redistribute it.<br />There is NO WARRANTY, to the extent permitted by law.<br /><br />Secret key is available.<br /><br />pub  4096R/6B23937C  created: 2015-12-02  expires: 2018-12-01  usage: SC<br />                     trust: ultimate      validity: ultimate<br />sub  4096R/2FD28DC8  created: 2015-12-02  expires: 2018-12-01  usage: E<br />[ultimate] (1). Chris Halos (testing addcardkey) &lt;chris@yubico.com&gt;<br /><br />gpg&gt; addkey<br />Key is protected.<br /><br />You need a passphrase to unlock the secret key for<br />user: &quot;Chris Halos (testing addcardkey) &lt;chris@yubico.com&gt;&quot;<br />4096-bit RSA key, ID 6B23937C, created 2015-12-02<br /><br />Please select what kind of key you want:<br />   (3) DSA (sign only)<br />   (4) RSA (sign only)<br />   (5) Elgamal (encrypt only)<br />   (6) RSA (encrypt only)<br />Your selection? 4<br />RSA keys may be between 1024 and 4096 bits long.<br />What keysize do you want? (2048) 4096<br />Requested keysize is 4096 bits<br />Please specify how long the key should be valid.<br />         0 = key does not expire<br />      &lt;n&gt;  = key expires in n days<br />      &lt;n&gt;w = key expires in n weeks<br />      &lt;n&gt;m = key expires in n months<br />      &lt;n&gt;y = key expires in n years<br />Key is valid for? (0) 3y<br />Key expires at 12/01/18 15:10:24 Pacific Standard Time<br />Is this correct? (y/N) y<br />Really create? (y/N) y<br />We need to generate a lot of random bytes. It is a good idea to perform<br />some other action (type on the keyboard, move the mouse, utilize the<br />disks) during the prime generation; this gives the random number<br />generator a better chance to gain enough entropy.<br /><br />pub  4096R/6B23937C  created: 2015-12-02  expires: 2018-12-01  usage: SC<br />                     trust: ultimate      validity: ultimate<br />sub  4096R/2FD28DC8  created: 2015-12-02  expires: 2018-12-01  usage: E<br />sub  4096R/911B11FD  created: 2015-12-02  expires: 2018-12-01  usage: S<br />[ultimate] (1). Chris Halos (testing addcardkey) &lt;chris@yubico.com&gt;<br /><br />gpg&gt; toggle<br /><br />sec  4096R/6B23937C  created: 2015-12-02  expires: 2018-12-01<br />ssb  4096R/2FD28DC8  created: 2015-12-02  expires: never<br />ssb  4096R/911B11FD  created: 2015-12-02  expires: 2018-12-01<br />(1)  Chris Halos (testing addcardkey) &lt;chris@yubico.com&gt;<br /><br />gpg&gt; key 2<br /><br />sec  4096R/6B23937C  created: 2015-12-02  expires: 2018-12-01<br />ssb  4096R/2FD28DC8  created: 2015-12-02  expires: never<br />ssb* 4096R/911B11FD  created: 2015-12-02  expires: 2018-12-01<br />(1)  Chris Halos (testing addcardkey) &lt;chris@yubico.com&gt;<br /><br />gpg&gt; keytocard<br />Signature key ....: 857D 4C3A D9D3 3F04 CD5E  7959 DB6B EB55 D8C6 FD6E<br />Encryption key....: 6201 28E7 5D81 8D83 EE46  0CA0 196D CB20 A991 18D0<br />Authentication key: 8338 0EF3 4758 8E95 7328  5D5C 7D60 935F F9F6 21B9<br /><br />Please select where to store the key:<br />   (1) Signature key<br />   (3) Authentication key<br />Your selection? 1<br /><br />gpg: WARNING: such a key has already been stored on the card!<br /><br />Replace existing key? (y/N) y<br /><br />You need a passphrase to unlock the secret key for<br />user: &quot;[User ID not found]&quot;<br />4096-bit RSA key, ID 911B11FD, created 2015-12-02<br /><br /><br />sec  4096R/6B23937C  created: 2015-12-02  expires: 2018-12-01<br />ssb  4096R/2FD28DC8  created: 2015-12-02  expires: never<br />ssb* 4096R/911B11FD  created: 2015-12-02  expires: 2018-12-01<br />                     card-no: 0006 04227930<br />(1)  Chris Halos (testing addcardkey) &lt;chris@yubico.com&gt;<br /><br />gpg&gt; key 2<br /><br />sec  4096R/6B23937C  created: 2015-12-02  expires: 2018-12-01<br />ssb  4096R/2FD28DC8  created: 2015-12-02  expires: never<br />ssb  4096R/911B11FD  created: 2015-12-02  expires: 2018-12-01<br />                     card-no: 0006 04227930<br />(1)  Chris Halos (testing addcardkey) &lt;chris@yubico.com&gt;<br /><br />gpg&gt; key 1<br /><br />sec  4096R/6B23937C  created: 2015-12-02  expires: 2018-12-01<br />ssb* 4096R/2FD28DC8  created: 2015-12-02  expires: never<br />ssb  4096R/911B11FD  created: 2015-12-02  expires: 2018-12-01<br />                     card-no: 0006 04227930<br />(1)  Chris Halos (testing addcardkey) &lt;chris@yubico.com&gt;<br /><br />gpg&gt; keytocard<br />Signature key ....: 72E9 E258 6A1D 4658 F976  72A2 3F42 0515 911B 11FD<br />Encryption key....: 6201 28E7 5D81 8D83 EE46  0CA0 196D CB20 A991 18D0<br />Authentication key: 8338 0EF3 4758 8E95 7328  5D5C 7D60 935F F9F6 21B9<br /><br />Please select where to store the key:<br />   (2) Encryption key<br />Your selection? 2<br /><br />gpg: WARNING: such a key has already been stored on the card!<br /><br />Replace existing key? (y/N) y<br /><br />You need a passphrase to unlock the secret key for<br />user: &quot;Chris Halos (testing addcardkey) &lt;chris@yubico.com&gt;&quot;<br />4096-bit RSA key, ID 2FD28DC8, created 2015-12-02<br /><br /><br />sec  4096R/6B23937C  created: 2015-12-02  expires: 2018-12-01<br />ssb* 4096R/2FD28DC8  created: 2015-12-02  expires: never<br />                     card-no: 0006 04227930<br />ssb  4096R/911B11FD  created: 2015-12-02  expires: 2018-12-01<br />                     card-no: 0006 04227930<br />(1)  Chris Halos (testing addcardkey) &lt;chris@yubico.com&gt;<br /><br />gpg&gt; toggle<br /><br />pub  4096R/6B23937C  created: 2015-12-02  expires: 2018-12-01  usage: SC<br />                     trust: ultimate      validity: ultimate<br />sub  4096R/2FD28DC8  created: 2015-12-02  expires: 2018-12-01  usage: E<br />sub  4096R/911B11FD  created: 2015-12-02  expires: 2018-12-01  usage: S<br />[ultimate] (1). Chris Halos (testing addcardkey) &lt;chris@yubico.com&gt;<br /><br />gpg&gt; addcardkey<br />Signature key ....: 72E9 E258 6A1D 4658 F976  72A2 3F42 0515 911B 11FD<br />Encryption key....: 3304 484D 0AA3 DD93 FE0C  2570 7B28 34B5 2FD2 8DC8<br />Authentication key: 8338 0EF3 4758 8E95 7328  5D5C 7D60 935F F9F6 21B9<br /><br />Please select the type of key to generate:<br />   (1) Signature key<br />   (2) Encryption key<br />   (3) Authentication key<br />Your selection? 3<br /><br />gpg: WARNING: such a key has already been stored on the card!<br /><br />Replace existing key? (y/N) y<br />What keysize do you want for the Authentication key? (4096) 4096<br />Key is protected.<br /><br />You need a passphrase to unlock the secret key for<br />user: &quot;Chris Halos (testing addcardkey) &lt;chris@yubico.com&gt;&quot;<br />4096-bit RSA key, ID 6B23937C, created 2015-12-02<br /><br />Please specify how long the key should be valid.<br />         0 = key does not expire<br />      &lt;n&gt;  = key expires in n days<br />      &lt;n&gt;w = key expires in n weeks<br />      &lt;n&gt;m = key expires in n months<br />      &lt;n&gt;y = key expires in n years<br />Key is valid for? (0) 3y<br />Key expires at 12/01/18 15:15:55 Pacific Standard Time<br />Is this correct? (y/N) y<br />Really create? (y/N) y<br /><br />pub  4096R/6B23937C  created: 2015-12-02  expires: 2018-12-01  usage: SC<br />                     trust: ultimate      validity: ultimate<br />sub  4096R/2FD28DC8  created: 2015-12-02  expires: 2018-12-01  usage: E<br />sub  4096R/911B11FD  created: 2015-12-02  expires: 2018-12-01  usage: S<br />sub  4096R/B062AF76  created: 2015-12-02  expires: 2018-12-01  usage: A<br />[ultimate] (1). Chris Halos (testing addcardkey) &lt;chris@yubico.com&gt;<br /><br />gpg&gt; save<br /><br />C:\Users\Chris&gt;gpg --card-status<br />Application ID ...: D2760001240102010006042279300000<br />Version ..........: 2.1<br />Manufacturer .....: Yubico<br />Serial number ....: 04227930<br />Name of cardholder: Halos Chris<br />Language prefs ...: [not set]<br />Sex ..............: unspecified<br />URL of public key : [not set]<br />Login data .......: [not set]<br />Signature PIN ....: not forced<br />Key attributes ...: 4096R 4096R 4096R<br />Max. PIN lengths .: 127 127 127<br />PIN retry counter : 3 0 3<br />Signature counter : 5<br />Signature key ....: 72E9 E258 6A1D 4658 F976  72A2 3F42 0515 911B 11FD<br />      created ....: 2015-12-02 23:10:06<br />Encryption key....: 3304 484D 0AA3 DD93 FE0C  2570 7B28 34B5 2FD2 8DC8<br />      created ....: 2015-12-02 23:07:26<br />Authentication key: 278E 7DCD 1840 B5F5 51C2  355C 0694 6E03 B062 AF76<br />      created ....: 2015-12-02 23:15:47<br />General key info..: pub  4096R/911B11FD 2015-12-02 Chris Halos (testing addcardkey) &lt;chris@yubico.com&gt;<br />sec   4096R/6B23937C  created: 2015-12-02  expires: 2018-12-01<br />ssb&gt;  4096R/2FD28DC8  created: 2015-12-02  expires: 2018-12-01<br />                      card-no: 0006 04227930<br />ssb&gt;  4096R/911B11FD  created: 2015-12-02  expires: 2018-12-01<br />                      card-no: 0006 04227930<br />ssb&gt;  4096R/B062AF76  created: 2015-12-02  expires: 2018-12-01<br />                      card-no: 0006 04227930<br /><br />C:\Users\Chris&gt;<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3140">ChrisHalos</a> — Mon Feb 01, 2016 9:37 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Crumb]]></name></author>
<updated>2016-02-01T16:18:59+01:00</updated>
<published>2016-02-01T16:18:59+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2190&amp;p=8238#p8238</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2190&amp;p=8238#p8238"/>
<title type="html"><![CDATA[[QUESTION] Yubikey 4 and 4096 Key Length]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2190&amp;p=8238#p8238"><![CDATA[
I have a key pair that I use to sign e-mails and encrypt documents. I bought the Yubikey 4 because the website states that the 4 supports 4096 key length, but for some reason every time I issue the keytocard command I get an error that makes it sound like the key is expecting a 2048 key. The Yubikey 4 supports higher key lengths right? Is there a step by step guide for importing a key? Maybe I'm missing a step...<br /><br />I appreciate any input you can provide.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4168">Crumb</a> — Mon Feb 01, 2016 4:18 pm</p><hr />
]]></content>
</entry>
</feed>