<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=1986" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2015-07-31T20:56:20+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=1986</id>
<entry>
<author><name><![CDATA[darco]]></name></author>
<updated>2015-07-31T20:56:20+01:00</updated>
<published>2015-07-31T20:56:20+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1986&amp;p=7663#p7663</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1986&amp;p=7663#p7663"/>
<title type="html"><![CDATA[[QUESTION] Yubico-PIV-Manager: Generating ECC P256 CSRs]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1986&amp;p=7663#p7663"><![CDATA[
Hello everyone, I'm having trouble generating a valid certificate signing request from the yubico PIV manager when the key is an ECC P256 key.<br /><br />Whenever I have the tool generate a CSR using ECC P256, the generated CSR is invalid. The issue appears to be with the ECDSA signature on the certificate request, which appears to be stored incorrectly:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">    Certificate Request:<br />        Data:<br />            Version: 0 (0x0)<br />            Subject: DC=net, DC=voria, DC=token, CN=Yubikey NEO 35XXXXX<br />            Subject Public Key Info:<br />                Public Key Algorithm: id-ecPublicKey<br />                EC Public Key: <br />                    pub: <br />                        04:dd:91:86:6a:92:69:90:d9:cd:f0:81:ca:a3:40:<br />                        80:d8:64:e3:ad:13:3a:ed:43:0e:42:a0:95:b2:1e:<br />                        8c:2c:46:60:f3:5b:75:33:92:38:51:52:b8:6c:0c:<br />                        1a:b8:b0:6f:ee:f1:33:7a:9a:37:a8:79:d7:c8:de:<br />                        19:92:43:23:83<br />                    ASN1 OID: prime256v1<br />            Attributes:<br />                a0:00<br />        Signature Algorithm: ecdsa-with-SHA256<br />            30:46:02:21:00:c3:7d:49:a6:da:e9:fe:25:18:26:7d:20:3e:<br />            6a:80:22:04:a4:9d:a8:fb:72:9a:7c:99:c5:48:02:e2:28:0b:<br />            65:02:21:00:d6:58:07:d0:f5:a5:f9:d9:f1:53:49:5d:3b:8a:<br />            5c:75:87:66:43:32:da:ce:97:67:33:0d:9b:8e:78:54:3a:17<br />    Check that the request matches the signature<br />    Signature verification problems....<br />    20298:error:0D0C50A1:asn1 encoding routines:ASN1_item_verify:unknown message digest algorithm:/SourceCache/OpenSSL098/OpenSSL098-52.30.1/src/crypto/asn1/a_verify.c:164:<br /></div><br /><br />I filed <a href="https://github.com/Yubico/yubikey-piv-manager/issues/1" class="postlink">issue number 1</a> against the project on GitHub, but I haven't gotten any responses.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3288">darco</a> — Fri Jul 31, 2015 8:56 pm</p><hr />
]]></content>
</entry>
</feed>