<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=23&amp;t=1837" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2015-07-16T22:50:38+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=23&amp;t=1837</id>
<entry>
<author><name><![CDATA[Aefan]]></name></author>
<updated>2015-07-16T22:50:38+01:00</updated>
<published>2015-07-16T22:50:38+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1837&amp;p=7601#p7601</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1837&amp;p=7601#p7601"/>
<title type="html"><![CDATA[Re: [QUESTION]: Why &quot;Make off-card backup of key?&quot;]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1837&amp;p=7601#p7601"><![CDATA[
i think the key you can export there is just a subkey for the encryption that you can import to a new key if you lose your yubikey.<br />this is not the master key that you can't export because it is generated on the yubikey.<br />with your exported subkey you're able to decrypt your files but you can't sign or verify files with it, so just a rescue key before generating a new master key.<br /><br />but i'm not sure and have the same problems to understand this whole process.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3800">Aefan</a> — Thu Jul 16, 2015 10:50 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Tom2]]></name></author>
<updated>2015-04-22T07:49:13+01:00</updated>
<published>2015-04-22T07:49:13+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1837&amp;p=7221#p7221</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1837&amp;p=7221#p7221"/>
<title type="html"><![CDATA[Re: [QUESTION]: Why &quot;Make off-card backup of key?&quot;]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1837&amp;p=7221#p7221"><![CDATA[
When you generate a backup, the key is generated on the host and then imported into the smartcard<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3364">Tom2</a> — Wed Apr 22, 2015 7:49 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[rbondi]]></name></author>
<updated>2015-04-21T00:22:59+01:00</updated>
<published>2015-04-21T00:22:59+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1837&amp;p=7218#p7218</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1837&amp;p=7218#p7218"/>
<title type="html"><![CDATA[Re: [QUESTION]: Why &quot;Make off-card backup of key?&quot;]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1837&amp;p=7218#p7218"><![CDATA[
Let me rephrase the question.<br /><br />At <a href="https://www.yubico.com/2012/12/yubikey-neo-openpgp/" class="postlink">https://www.yubico.com/2012/12/yubikey-neo-openpgp/</a> Yubico says:<br /><br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />WARNING: You cannot backup the secret keys – so if you lose the YubiKey NEO, re-generate another key pair or other [sic] lose the key pair there is no way to retrieve it! When you encrypt a file, make sure you have a plain text backup.<br /></div><br /><br />My question is: that's a false statement, isn't it? <br /><br />Because you <strong>can</strong> backup the secret keys, by answering Y to &quot;Make off-card backup of keys?&quot; -- as I explained above, I was able to reimport totally different secret keys using this method. Either that's by design and you need to correct the above statement, or else there's a bug in Yubikey's OpenPGP.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3659">rbondi</a> — Tue Apr 21, 2015 12:22 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Tom2]]></name></author>
<updated>2015-04-20T09:50:56+01:00</updated>
<published>2015-04-20T09:50:56+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1837&amp;p=7212#p7212</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1837&amp;p=7212#p7212"/>
<title type="html"><![CDATA[Re: [QUESTION]: Why &quot;Make off-card backup of key?&quot;]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1837&amp;p=7212#p7212"><![CDATA[
Yes, you can import sub keys to the card.<br /><br />You cannot export the master key generated on the device.<br /><br />I don't understand you question ?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3364">Tom2</a> — Mon Apr 20, 2015 9:50 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[rbondi]]></name></author>
<updated>2015-04-18T02:21:08+01:00</updated>
<published>2015-04-18T02:21:08+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1837&amp;p=7200#p7200</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1837&amp;p=7200#p7200"/>
<title type="html"><![CDATA[[QUESTION]: Why &quot;Make off-card backup of key?&quot;]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1837&amp;p=7200#p7200"><![CDATA[
I'm confused:<br /><br />1) It's supposed to be impossible to have a copy of the private key generated by:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">gpg --card-edit<br />admin<br />generate<br />//snip<br />pub   2048R/AE297E58 2015-04-20 &#91;expires: 2015-04-21&#93;<br />      Key fingerprint = 9F4D 0F9D 320D 4669 2C0D  AE9D 3637 81ED AE29 7E58<br />uid       &#91;ultimate&#93; Sebastian 1 day &lt;rbondi@gmail.com&gt;<br />sub   2048R/7C083E6A 2015-04-20 &#91;expires: 2015-04-21&#93;<br />sub   2048R/6554AE65 2015-04-20 &#91;expires: 2015-04-21&#93;<br /></div><br /><br />2) But that process prompts me to &quot;Make off-card backup of key?&quot;, and when I do, I'm able to reimport the key.<br />It saved /foo/bla/.gnupg/sk_5E6E7ECD6554AE65.gpg. But I was able to import a totally different backup:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">gpg --edit-key AE297E58<br />toggle<br />bkuptocard /foo/bla/totallydifferentbackup.gpg<br />Signature key ....: 9F4D 0F9D 320D 4669 2C0D  AE9D 3637 81ED AE29 7E58<br />Encryption key....: 82B9 E8D1 7AA3 27ED CA0D  0A24 5E6E 7ECD 6554 AE65<br />Authentication key: 1494 7371 D85C EE5E 3A6B  3C11 82BF 0E60 7C08 3E6A<br /><br />Please select where to store the key:<br />   (1) Signature key<br />   (2) Encryption key<br />   (3) Authentication key<br />Your selection? 2<br />//snip<br /></div><br /><br />So.... it is possible to have a copy of the generated keys? Or not?<br /><br />TMIA, /rb.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3659">rbondi</a> — Sat Apr 18, 2015 2:21 am</p><hr />
]]></content>
</entry>
</feed>