<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=35&amp;t=2428" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2016-09-17T22:34:53+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=35&amp;t=2428</id>
<entry>
<author><name><![CDATA[drmhv]]></name></author>
<updated>2016-09-17T22:34:53+01:00</updated>
<published>2016-09-17T22:34:53+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2428&amp;p=9022#p9022</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2428&amp;p=9022#p9022"/>
<title type="html"><![CDATA[OpenPGP and PIV - is coexistence possible?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2428&amp;p=9022#p9022"><![CDATA[
I've loaded up my Yubikey 4 with my OpenPGP keys, and my X.509 certificates (which I use for S/MIME). I'm using Fedora 24, and NSS has been configured to use the OpenSC PKCS#11 module and it all seems to work with Thunderbird, Evolution, Firefox, etc. The trouble is both GnuPG and OpenSC seem to dislike sharing the toys.<br /><br /><ul><li> If I launch an NSS-based application with the OpenSC module, it locks the Yubikey and I can't GnuPG with it until I quit that application.</li><li> Conversely, if I've run GnuPG first I have to kill scdaemon (and re-plug) before I can use PIV functionality again.</li></ul><br />This is all a bit clunky. Is there something I've missed to get seamless co-existence of GnuPG and OpenSC, or are these just known shortcomings with multi-application smartcards?<br /><br />I can't really unload the OpenSC module completely from NSS as it's needed for my work smart card. So far the only workaround I've found is to bodge together a local OpenSC config file to use the wrong driver for the YK4 ATR (thereby disabling it), and use environment variables to flip between it and the default config for when I need the keys stored in the Yubikey's PIV applet.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4443">drmhv</a> — Sat Sep 17, 2016 10:34 pm</p><hr />
]]></content>
</entry>
</feed>