<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=2210" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2016-02-13T03:42:54+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=2210</id>
<entry>
<author><name><![CDATA[noah977]]></name></author>
<updated>2016-02-13T03:42:36+01:00</updated>
<published>2016-02-13T03:42:36+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2210&amp;p=8313#p8313</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2210&amp;p=8313#p8313"/>
<title type="html"><![CDATA[Re: [Question] Difference between PIV and PGP]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2210&amp;p=8313#p8313"><![CDATA[
Very helpful.  Thank You<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4194">noah977</a> — Sat Feb 13, 2016 3:42 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Uriel]]></name></author>
<updated>2016-02-12T23:07:30+01:00</updated>
<published>2016-02-12T23:07:30+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2210&amp;p=8311#p8311</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2210&amp;p=8311#p8311"/>
<title type="html"><![CDATA[Re: [Question] Difference between PIV and PGP]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2210&amp;p=8311#p8311"><![CDATA[
For secure email using Android, you have to use PGP because:<br /><ul><li>The only way to communicate with the NEO token from the Android device is NFC.</li><li>The only email application I know on Android that works with hardware tokens (and NFC) is K-9 Mail.</li><li>K-9 Mail supports only PGP, and &quot;outsources&quot; access to the token to OpenKeychain application.</li><li>OpenKeychain app works fine with NEO, but only with its OpenPGP applet. It cannot talk to the PIV applet.</li></ul><br />If you use your token (Yubikey NEO or Yubikey 4) on a computer that has USB (rather than a mobile device that only offers NFC), you can use either PGP or PIV - and most email clients would be happier with PIV out of box (giving you S/MIME capabilities).<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3568">Uriel</a> — Fri Feb 12, 2016 11:07 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[lafien]]></name></author>
<updated>2016-02-12T21:13:37+01:00</updated>
<published>2016-02-12T21:13:37+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2210&amp;p=8309#p8309</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2210&amp;p=8309#p8309"/>
<title type="html"><![CDATA[Re: [Question] Difference between PIV and PGP]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2210&amp;p=8309#p8309"><![CDATA[
If you're intent is to use it <div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />as a hardware based authentication for remote access<br /></div>, meaning SSH, you would rather use the PGP card side, which is what is compatible with gpg-agent etc. and works quite easily (and there are multiple guides online). <br /><br />I just saw it is possible to do the same with PIV, but it is not so straightforward (<!-- m --><a class="postlink" href="https://blog.josefsson.org/2015/06/16/ssh-host-certificates-with-yubikey-neo/">https://blog.josefsson.org/2015/06/16/s ... bikey-neo/</a><!-- m --> and <!-- m --><a class="postlink" href="https://developers.yubico.com/yubico-piv-tool/SSH_with_PIV_and_PKCS11.html">https://developers.yubico.com/yubico-pi ... KCS11.html</a><!-- m -->).<br /><br />I'd expect the PIV card to be used with your browser, for example, for x509 certificate-based authentication to some websites. Or to manage sub-CAs: <!-- m --><a class="postlink" href="https://developers.yubico.com/yubico-piv-tool/Certificate_Authority.html">https://developers.yubico.com/yubico-pi ... ority.html</a><!-- m --> , in general everything that involves CAs (usually not the case for SSH).<br /><br />Also, when setting these things up, remember the PIV and PGP facilities are separate, that means, different PIN, PUK and admin passphrases are independent.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4186">lafien</a> — Fri Feb 12, 2016 9:13 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Fallon]]></name></author>
<updated>2016-02-11T07:40:26+01:00</updated>
<published>2016-02-11T07:40:26+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2210&amp;p=8301#p8301</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2210&amp;p=8301#p8301"/>
<title type="html"><![CDATA[Re: [Question] Difference between PIV and PGP]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2210&amp;p=8301#p8301"><![CDATA[
<div class="quotetitle">noah977 wrote:</div><div class="quotecontent"><br />Hi,<br /><br />I'm new to Yubikey and this area in general.  In the past, I've used digital keys to authenticate remote SSH connections.  <br /><br />Have read about some nice setups where the private key is kept on the yubikey, so that adds another layer of security.<br /><br />I've bought both a NEO and a Yubikey 4 for testing.  It looks like they both have PGP functionality and PIV functionality.  My intent is to use the Yubikey as a hardware based authentication for remote access to several servers I manage. (And possibly for my laptop as well.)<br /><br />From my limited reading, it seems like both PGP and PIV use a series of public/private keypairs for things like authentication, encryption, and signing.  In fact, they look almost identical.  For practical usage, is there any real difference?<br /><br />Can someone point me to a good resource to understand the difference.  Or, can someone explain it here?<br /><br />Thanks!<br /></div><br /><br />PIV uses X.509 format certs &amp; PGP uses PGP formated certs. As far as basics I believe they are pretty similar cryptographically with public &amp; private keys. x.509 is based around a chain of trust from trusted CA's &amp; is the backbone of cryptography for the Internet.<br /><br />PGP is centered around a web of trust. Certs are signed by various peers, hopefully by somebody you know &amp; trust.<br /><br />Generally I'd recomend going with x.509 stuff as it will be more compatible with more stuff.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4197">Fallon</a> — Thu Feb 11, 2016 7:40 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[noah977]]></name></author>
<updated>2016-02-13T03:42:54+01:00</updated>
<published>2016-02-10T15:39:04+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2210&amp;p=8295#p8295</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2210&amp;p=8295#p8295"/>
<title type="html"><![CDATA[[ANSWERED] Difference between PIV and PGP]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2210&amp;p=8295#p8295"><![CDATA[
Hi,<br /><br />I'm new to Yubikey and this area in general.  In the past, I've used digital keys to authenticate remote SSH connections.  <br /><br />Have read about some nice setups where the private key is kept on the yubikey, so that adds another layer of security.<br /><br />I've bought both a NEO and a Yubikey 4 for testing.  It looks like they both have PGP functionality and PIV functionality.  My intent is to use the Yubikey as a hardware based authentication for remote access to several servers I manage. (And possibly for my laptop as well.)<br /><br />From my limited reading, it seems like both PGP and PIV use a series of public/private keypairs for things like authentication, encryption, and signing.  In fact, they look almost identical.  For practical usage, is there any real difference?<br /><br />Can someone point me to a good resource to understand the difference.  Or, can someone explain it here?<br /><br />Thanks!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4194">noah977</a> — Wed Feb 10, 2016 3:39 pm</p><hr />
]]></content>
</entry>
</feed>