<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=1414" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2014-06-27T13:10:40+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=1414</id>
<entry>
<author><name><![CDATA[Klas]]></name></author>
<updated>2014-06-27T13:10:40+01:00</updated>
<published>2014-06-27T13:10:40+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1414&amp;p=5365#p5365</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1414&amp;p=5365#p5365"/>
<title type="html"><![CDATA[Re: [Q] Yubikey neo piv - contact vs contact-less behavior]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1414&amp;p=5365#p5365"><![CDATA[
Hello,<br /><br />Replies follow inline below..<br /><br /><div class="quotetitle">mkosterlund wrote:</div><div class="quotecontent"><br />Is the Yubikey NEO piv applet usable with a contact-less CCID reader?<br /></div><br /><br />Yes.<br /><br /><div class="quotetitle">mkosterlund wrote:</div><div class="quotecontent"><br />Can you please verify in what way, if any, you plan to change the current functionality?<br />eg. Will all certificate slots be available for both usb and contact-less reading?<br /></div><br /><br />There are no stated plans in this regard, but the current behaviour is in violation of the PIV spec. We might make a bit that can be toggled with the auth key or something like that. If a standard secure messaging implementation gets builtin for host-side software we will probably implement that and might enforce it for contactless functionality.<br /><br /><div class="quotetitle">mkosterlund wrote:</div><div class="quotecontent"><br />is this also the case in contact less reading?<br /></div><br /><br />Yes, the applet does not check whether it's used in contact or contact-less mode. The 9e slot does not require pin for the authenticate operation.<br /><br /><div class="quotetitle">mkosterlund wrote:</div><div class="quotecontent"><br />Can you name 1 or 2 contact-less usb CCID readers that work in your experience, also under windows.<br />Perhaps omnikey 5321 v2 ?<br /></div><br /><br />I think this has been discussed on the forum earlier.. : <!-- l --><a class="postlink-local" href="http://forum.yubico.com/viewtopic.php?f=26&amp;t=1345&amp;p=5070">viewtopic.php?f=26&amp;t=1345&amp;p=5070</a><!-- l --><br />The Omnikey 5321 works fine but is a bit bulky if you only want a contactless reader. Genereally any standard reader should work, but we've not had the opportunity yet.<br /><br /><div class="quotetitle">mkosterlund wrote:</div><div class="quotecontent"><br />We have been able to store, and do windows logon, with certificates stored in the following slots:<br />9a, 9d and 9e - however pin was always checked, this was using contact interface - is this expected behavior?<br /></div><br /><br />For 9e pin is not required, but this might be a windows thing that it always checks the pin. 9c should work but windows could restrict usage of 9c to signature operations and not allow it for authentication (if one is to think more on it 9d shouldn't be used for authentication either, only decryption)<br /><br />/klas<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2019">Klas</a> — Fri Jun 27, 2014 1:10 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[mkosterlund]]></name></author>
<updated>2014-06-27T10:18:47+01:00</updated>
<published>2014-06-27T10:18:47+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1414&amp;p=5364#p5364</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1414&amp;p=5364#p5364"/>
<title type="html"><![CDATA[[Q] Yubikey neo piv - contact vs contact-less behavior]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1414&amp;p=5364#p5364"><![CDATA[
Hi,<br /><br />Is the Yubikey NEO piv applet usable with a contact-less CCID reader?<br /><br />According to your statement: &quot;Currently all functionality are available over both contact and contactless interfaces (contrary to what the specifications mandate).&quot;<br />I'm guessing yes. In our production environment, some users require three distinct certificates, for authentication.<br /><br />Can you please verify in what way, if any, you plan to change the current functionality?<br />eg. Will all certificate slots be available for both usb and contact-less reading?<br /><br />Currently it seems all certificate slots, in usb reading requires the pin,<br />is this also the case in contact less reading?<br /><br />Are you planning on changing the pin requirement in either contact and / or contact-less reading<br />for any of the slots in the future?<br /><br />Can you name 1 or 2 contact-less usb CCID readers that work in your experience, also under windows.<br />Perhaps omnikey 5321 v2 ?<br /><br />We have been able to store, and do windows logon, with certificates stored in the following slots:<br />9a, 9d and 9e - however pin was always checked, this was using contact interface - is this expected behavior?<br /><br />According to below output from piv tool, pin should never be checked with slot 9e?<br />9a is for PIV Authentication<br />9c is for Digital Signature (PIN always checked)<br />9d is for Key Management<br />9e is for Card Authentication (PIN never checked)<br /><br />We have not been able to authenticate, using windows logon with a certificate stored in slot 9c, do you know why?<br /> -eg the certiface does not show.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2846">mkosterlund</a> — Fri Jun 27, 2014 10:18 am</p><hr />
]]></content>
</entry>
</feed>