<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=35&amp;t=2237" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2016-02-27T00:55:37+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=35&amp;t=2237</id>
<entry>
<author><name><![CDATA[tommd]]></name></author>
<updated>2016-02-25T07:34:15+01:00</updated>
<published>2016-02-25T07:34:15+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2237&amp;p=8405#p8405</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2237&amp;p=8405#p8405"/>
<title type="html"><![CDATA[Re: [Question] Trouble with GPG --card-status]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2237&amp;p=8405#p8405"><![CDATA[
ChrisHalos already had the answer here on the forum, the purpose of keeping a forum of old answers right?  So thanks to yubikey and Chris.<br /><br />The Ubuntu system did not work immediately but after running:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">gpg-connect-agent --hex<br />&gt; scd apdu 00 44 00 00<br /></div><br /><br />Things work all right.  I say all right because <br /><br />1. I still need to test the key on the Mac.<br /><br />2. I can't figure out how to require the yubikey button to be pressed prior to performing a gpg signature/encryption.  Any pointers?<br /><br />After confirming 1 I'll mark this question answered and open a new topic on question 2.<br /><br />EDIT:<br /><br />As for issue 2, touch can be enabled as detailed on the getting started OpenPGP page (<!-- m --><a class="postlink" href="https://developers.yubico.com/PGP/Card_edit.html">https://developers.yubico.com/PGP/Card_edit.html</a><!-- m -->).  Humorously, the shell script they refer to is A. not hosted on a yubikey account (though the user is part of the yubico organization as identified by github) and B. lacking any documentation such as what 'aut' means in the arguments.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4223">tommd</a> — Thu Feb 25, 2016 7:34 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[tommd]]></name></author>
<updated>2016-02-27T00:55:37+01:00</updated>
<published>2016-02-24T23:22:50+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2237&amp;p=8402#p8402</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2237&amp;p=8402#p8402"/>
<title type="html"><![CDATA[[Resolved] Trouble with GPG --card-status]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2237&amp;p=8402#p8402"><![CDATA[
I'm can't seem to get gpg2/scdaemon to recognize my yubikey 4.  I've seen similar issues online but have not been successful myself.<br /><br />I'm on Darwin:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">$ uname -a<br />Darwin HalfAndHalf 15.3.0 Darwin Kernel Version 15.3.0: Thu Dec 10 18:40:58 PST 2015; root:xnu-3248.30.4~1/RELEASE_X86_64 x86_64<br /></div><br /><br />On the surface, gpg2 does not work (installed via `brew`, but the dmg from gpgtools behaves the same).<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">$ gpg2 --card-status<br />gpg: OpenPGP card not available: Not supported<br /></div><br /><br />This yields the common &quot;can't select application `openpgp': Not supported&quot; error message from scdaemon:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">$ tail -n 5 scdaemon.log<br />2016-02-24 14:08:00 scdaemon&#91;526&#93; pcsc_control failed: invalid parameter (0x80100004)<br />2016-02-24 14:08:00 scdaemon&#91;526&#93; pcsc_vendor_specific_init: GET_FEATURE_REQUEST failed: 65538<br />2016-02-24 14:08:00 scdaemon&#91;526&#93; can't select application `openpgp': Not supported<br />2016-02-24 14:08:00 scdaemon&#91;526&#93; updating slot 0 status: 0x0000-&gt;0x0007 (0-&gt;1)<br />2016-02-24 14:08:01 scdaemon&#91;526&#93; scdaemon (GnuPG) 2.0.29 stopped<br /></div><br /><br />My configuration is pretty typical, though I've certainly tried various things:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">$ tail gpg.conf<br />use-agent<br />$ cat gpg-agent.conf<br />enable-ssh-support<br /></div><br /><br />The most common suggestion online is to set the reader-port, which I have done:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">$ cat scdaemon.conf<br />reader-port &quot;Yubico Yubikey 4 OTP+CCID&quot;<br />log-file /Users/tommd/.gnupg/scdaemon.log<br /></div><br /><br />opensc sees the card fine:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">$ opensc-tool -l<br /># Detected readers (pcsc)<br />Nr.  Card  Features  Name<br />0    Yes             Yubico Yubikey 4 OTP+CCID<br />$ opensc-tool -lv<br /># Detected readers (pcsc)<br />Nr.  Card  Features  Name<br />0    Yes             Yubico Yubikey 4 OTP+CCID<br />     3b:f8:13:00:00:81:31:fe:15:59:75:62:69:6b:65:79:34:d4 PIV-II card<br /></div><br /><br />pcsc test also reports positive looking things:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Testing SCardEstablishContext    : Command successful.<br />Testing SCardGetStatusChange<br />Please insert a working reader   : Command successful.<br />Testing SCardListReaders         : Command successful.<br />Reader 01: Yubico Yubikey 4 OTP+CCID<br />Enter the reader number          : 01<br />Waiting for card insertion<br />                                 : Command successful.<br />Testing SCardConnect             : Command successful.<br />Testing SCardStatus              : Command successful.<br />Current Reader Name              : Yubico Yubikey 4 OTP+CCID<br />Current Reader State             : 0x54<br />Current Reader Protocol          : 0x1<br />Current Reader ATR Size          : 18 (0x12)<br />Current Reader ATR Value         : 3B F8 13 00 00 81 31 FE 15 59 75 62 69 6B 65 79 34 D4<br />Testing SCardDisconnect          : Command successful.<br />Testing SCardReleaseContext      : Command successful.<br /></div><br /><br />gpg1, which I'd prefer not to use, has different behavior:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">% gpg --card-status<br />gpg: detected reader `Yubico Yubikey 4 OTP+CCID'<br />Please insert the card and hit return or enter 'c' to cancel:<br />... repeat the above on 'return'...<br /></div><br /><br />I'll update this thread when I get around to trying on my Ubuntu system, but regardless of success there I'm going to need this working on the Mac.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4223">tommd</a> — Wed Feb 24, 2016 11:22 pm</p><hr />
]]></content>
</entry>
</feed>