<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=35&amp;t=2690" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2017-09-10T09:51:56+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=35&amp;t=2690</id>
<entry>
<author><name><![CDATA[nesos]]></name></author>
<updated>2017-09-10T09:51:56+01:00</updated>
<published>2017-09-10T09:51:56+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2690&amp;p=9734#p9734</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2690&amp;p=9734#p9734"/>
<title type="html"><![CDATA[Re: Cannot move 4096 bit GnuPG key to YubiKey 4]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2690&amp;p=9734#p9734"><![CDATA[
i also have a new key and it has firmware 4.3.5 but here everything works.<br />one difference is that i generated the key on my pc and moved to the card/yubikey instead of generating it diretly there (never tried).<br />from what i have understood the fact that it says 2048 is normal as it is a default value but it doesn't mean that you can't push a 4096 bit key.<br />i'm not gpg expert but another thing: have you issued <em>toggle</em> command before using key to card?<br />according to the gpg manual toggle switches between public and private key so i guess you are trying to push public key and thus the error &quot;no private key usable&quot;<br /><br />this is what i followed to store the key on the yubikey:<br /><!-- m --><a class="postlink" href="https://developers.yubico.com/PGP/Importing_keys.html">https://developers.yubico.com/PGP/Importing_keys.html</a><!-- m --><br /><br />i understand that you might prefer to generate it directly on the yubikey but in that way you have no way of making a backup, also an &quot;evil pc&quot; could try wrong pins and destroy your keys.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4885">nesos</a> — Sun Sep 10, 2017 9:51 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[patrickkox79]]></name></author>
<updated>2017-08-21T18:04:42+01:00</updated>
<published>2017-08-21T18:04:42+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2690&amp;p=9712#p9712</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2690&amp;p=9712#p9712"/>
<title type="html"><![CDATA[Cannot move 4096 bit GnuPG key to YubiKey 4]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2690&amp;p=9712#p9712"><![CDATA[
A few weeks ago I purchased the YubiKey 4 bundle (1 white and 1 black YubiKey 4).<br />I have written 2 different 4096 bit GPG keys to them without problem.<br /><br />Today I received another bundle I ordered (to have spare/replacements) but I cannot move my 4096 bit keys to them.<br /><br />When I check with the YubiKey Personalization tool I see my &quot;old&quot; keys have firmware 4.3.4 and the &quot;new&quot; have firmware 4.3.5,<br />so I would guess this should be possible since the firmware is even newer.<br /><br />When I run gpg2 --card-status I get the card information and the <strong>key attributes are set to 2048</strong><br /><br />I tried to generate a new keypair on the YubiKey and when I select 4096 and getting a warning that this might not work, the newly generated key seems to be a 4096 bit one. <br /><br />when I check again the key attributes are now set to 4096 but I still cannot move a new key (keytocard) to the YubiKey.<br />The only key that I can move to the YubiKey is a 2048 one but I need my 4096 bit key not a 2048 bit one or a new one.<br /><br />Here is the output from gpg when I do keytocard:<br /><br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />gpg&gt; keytocard<br />Really move the primary key? (y/N) y<br />Please select where to store the key:<br />   (1) Signature key<br />   (3) Authentication key<br />Your selection? 3<br /><br />gpg: WARNING: such a key has already been stored on the card!<br /><br />Replace existing key? (y/N) y<br />gpg: KEYTOCARD failed: Onbruikbare geheime sleutel<br /><br />gpg&gt;<br /></div><br />The error in Dutch is : &quot;Unusable secret key&quot;<br /><br />I've found a post here with a similar problem, but that person had an error after entering a PIN, this is before the PIN is asked.<br /><br />Anyone have an Idea ?<br /><br />Patrick<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4875">patrickkox79</a> — Mon Aug 21, 2017 6:04 pm</p><hr />
]]></content>
</entry>
</feed>