<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=33&amp;t=1662" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2014-12-16T21:09:05+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=33&amp;t=1662</id>
<entry>
<author><name><![CDATA[tlockley]]></name></author>
<updated>2014-12-16T20:13:51+01:00</updated>
<published>2014-12-16T20:13:51+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1662&amp;p=6527#p6527</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1662&amp;p=6527#p6527"/>
<title type="html"><![CDATA[Re: [QUESTION] What do I do with this certificate?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1662&amp;p=6527#p6527"><![CDATA[
Thanks for the info. I was figuring that was the case with the &quot;extra&quot; certificate, but I could never find a solid explanation in the spec documents.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3384">tlockley</a> — Tue Dec 16, 2014 8:13 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[darco]]></name></author>
<updated>2014-12-16T21:09:05+01:00</updated>
<published>2014-12-16T19:24:21+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1662&amp;p=6521#p6521</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1662&amp;p=6521#p6521"/>
<title type="html"><![CDATA[Re: [QUESTION] What do I do with this certificate?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1662&amp;p=6521#p6521"><![CDATA[
Short answer: Ignore it.<br /><br />Long answer: It is used to verify the service that a device was manufactured by a specific manufacturer in a specific batch. It is generally only interesting to very paranoid companies. It is not really useful information for end users, and most non-debug implementations should hide it from view. All consumer U2F tokens do not use the attestation certificate to uniquely identify the device (for privacy reasons), so the private key for the attestation certificate (not to be confused with the &quot;device master secret&quot;, which is unique to each device) is shared by batches of tokens.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3288">darco</a> — Tue Dec 16, 2014 7:24 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[tlockley]]></name></author>
<updated>2014-12-16T20:14:05+01:00</updated>
<published>2014-12-16T18:36:34+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1662&amp;p=6518#p6518</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1662&amp;p=6518#p6518"/>
<title type="html"><![CDATA[[SOLVED] What do I do with this certificate?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1662&amp;p=6518#p6518"><![CDATA[
Been playing with a U2F NEO and so far everything is making sense except for this certificate I get back when I complete a registration. Is that the attestation certificate for my device or something else?<br /><br />I ask because I am unsure where it gets used, if at all and why I would want to keep it.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3384">tlockley</a> — Tue Dec 16, 2014 6:36 pm</p><hr />
]]></content>
</entry>
</feed>