<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=35&amp;t=2279" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2016-04-21T22:11:37+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=35&amp;t=2279</id>
<entry>
<author><name><![CDATA[mattlegitt]]></name></author>
<updated>2016-04-21T22:11:37+01:00</updated>
<published>2016-04-21T22:11:37+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2279&amp;p=8563#p8563</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2279&amp;p=8563#p8563"/>
<title type="html"><![CDATA[Re: Yubikey Corporate certificate]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2279&amp;p=8563#p8563"><![CDATA[
unfortunately the behavior you are seeing is due to Microsoft Windows using cached credentials you can read more about this behavior at the following link.<br /><br /><!-- m --><a class="postlink" href="https://technet.microsoft.com/en-us/library/hh994565.aspx">https://technet.microsoft.com/en-us/lib ... 94565.aspx</a><!-- m --><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4123">mattlegitt</a> — Thu Apr 21, 2016 10:11 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[mcx]]></name></author>
<updated>2016-04-14T13:28:51+01:00</updated>
<published>2016-04-14T13:28:51+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2279&amp;p=8549#p8549</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2279&amp;p=8549#p8549"/>
<title type="html"><![CDATA[Re: Yubikey Corporate certificate]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2279&amp;p=8549#p8549"><![CDATA[
Any takers on this?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4283">mcx</a> — Thu Apr 14, 2016 1:28 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[mcx]]></name></author>
<updated>2016-04-11T14:31:03+01:00</updated>
<published>2016-04-11T14:31:03+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2279&amp;p=8541#p8541</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2279&amp;p=8541#p8541"/>
<title type="html"><![CDATA[Re: Yubikey Corporate certificate]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2279&amp;p=8541#p8541"><![CDATA[
<div class="quotetitle">Tom2 wrote:</div><div class="quotecontent"><br />You have to delete it with yubico-piv-tools action delete-certificate.<br /><!-- m --><a class="postlink" href="https://developers.yubico.com/yubico-piv-tool/">https://developers.yubico.com/yubico-piv-tool/</a><!-- m --><br /></div><br /><br />Hm... thanks for the tip... but the whole issue is that it keeps re-appearing in certmgr.msc... after I delete it from it... like the OS takes the key+cert and installs it on the OS certmgr... instead of it just remaining on the Yubikey4... 9c slot.<br /><br />A successful usage case would be: if Yubikey is not in slot, no-one can sign or read encrypted mails with the certificate on the slot...<br /><br />What's happening is: After the 1st insertion of Yubikey + PIN unlock the certificate is stored on the local PC's certmgr... so after 1st use, the usb token isn't needed for a succesfull sign/read operation (tested it 2-3 times now... it's actually installed on the OS on first use).<br /><br />Please advise!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4283">mcx</a> — Mon Apr 11, 2016 2:31 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Tom2]]></name></author>
<updated>2016-04-11T12:53:28+01:00</updated>
<published>2016-04-11T12:53:28+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2279&amp;p=8540#p8540</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2279&amp;p=8540#p8540"/>
<title type="html"><![CDATA[Re: Yubikey Corporate certificate]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2279&amp;p=8540#p8540"><![CDATA[
You have to delete it with yubico-piv-tools action delete-certificate.<br /><!-- m --><a class="postlink" href="https://developers.yubico.com/yubico-piv-tool/">https://developers.yubico.com/yubico-piv-tool/</a><!-- m --><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3364">Tom2</a> — Mon Apr 11, 2016 12:53 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[mcx]]></name></author>
<updated>2016-04-11T08:11:47+01:00</updated>
<published>2016-04-11T08:11:47+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2279&amp;p=8539#p8539</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2279&amp;p=8539#p8539"/>
<title type="html"><![CDATA[Yubikey Corporate certificate]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2279&amp;p=8539#p8539"><![CDATA[
Hello all!<br /><br />Strange behavior on my Yubikey slot 9c certificate usage.<br /><br />I exported my Windows Enterprise CA (Intermediate) personal certificate from certmgr.msc and imported it with Yubikey PIV Tool to slot 9c. Then deleted the certificate from certmgr.msc and verified I couldn't login to our VPN (requires certificate) or read entrypted (Outlook S/MIME) emails. Inserted the key and could (after entering pin) read the encrypted emails, connect to vpn etc. Then I removed it and every time I clicked on an encrypted mail it was asking for the card... as expected. All fine you'll say?<br /><br />Now the strange part... next day, after a reboot (if that matters, not sure it does)... I click on an encrypted email and it opens up... without the card in the slot. I look in certmgr.msc... and sure as hell... certificate is back! I delete it... everything works back with the cert on the key as expected... but the certmgr.msc reports that it has the key I just deleted... but still asks for the &quot;Card&quot; when I click on encrypted stuff... like the private key is on the card but the cert is there... but the icon (and details of it) on certmgr... still mention that &quot;You have a private key that corresponds to the Certificate&quot; even when my Yubikey4 is out... Since it works though... I don't pay much attention to it....<br /><br />Next day, another reboot later... I can read the encrypted emails without any problem... without Yubikey4 connected...<br /><br />Please... assist... I think I'm going crazy here... why does the certificate reappear on certmgr.msc every time?<br /><br />Andreas<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4283">mcx</a> — Mon Apr 11, 2016 8:11 am</p><hr />
]]></content>
</entry>
</feed>