<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=16&amp;t=2114" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2015-12-06T20:02:39+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=16&amp;t=2114</id>
<entry>
<author><name><![CDATA[Himartin]]></name></author>
<updated>2015-12-06T20:02:39+01:00</updated>
<published>2015-12-06T20:02:39+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2114&amp;p=8052#p8052</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2114&amp;p=8052#p8052"/>
<title type="html"><![CDATA[Re: Yubikey 4 and RSA 4096]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2114&amp;p=8052#p8052"><![CDATA[
Thanks for the information. Indeed it works with longer keys.<br />So the output of gpg was just confusing.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4059">Himartin</a> — Sun Dec 06, 2015 8:02 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[dmonakhov]]></name></author>
<updated>2015-12-02T11:22:10+01:00</updated>
<published>2015-12-02T11:22:10+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2114&amp;p=8040#p8040</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2114&amp;p=8040#p8040"/>
<title type="html"><![CDATA[Re: Yubikey 4 and RSA 4096]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2114&amp;p=8040#p8040"><![CDATA[
subkey import (via &quot;keytocard&quot;) and and subkey generation (via  &quot;addcardkey&quot;)  are also works fine.<br />In this example Sign and Encryption subkeys was imported, Auth subkey was generated on card<br />Application ID ...: D2760001240102010006041615780000<br />Version ..........: 2.1<br />Manufacturer .....: Yubico<br />Serial number ....: 04161578<br />Name of cardholder: [not set]<br />Language prefs ...: [not set]<br />Sex ..............: unspecified<br />URL of public key : [not set]<br />Login data .......: [not set]<br />Signature PIN ....: forced<br />Key attributes ...: 4096R 4096R 4096R<br />Max. PIN lengths .: 127 127 127<br />PIN retry counter : 3 0 3<br />Signature counter : 0<br />Signature key ....: B0ED 248E 6922 E471 B7A7  7EBA F666 8E6D 506B 0421<br />      created ....: 2015-12-02 10:05:57<br />Encryption key....: 84DA 7E09 7FF0 4AE5 57E4  4019 F042 CC5D 71C3 BCD1<br />      created ....: 2015-12-02 09:55:29<br />Authentication key: 5C6B B320 A373 9700 75FA  6C46 D879 48F0 ECE2 B258<br />      created ....: 2015-12-02 10:11:20<br />General key info..: pub  4096R/506B0421 2015-12-02 Dmitry Monakhov (hw-key-gen-test-yubikey-4096) &lt;dmonakhov@opnevz.org&gt;<br />sec   4096R/A6C30BA6  created: 2015-12-02  expires: 2025-11-29<br />ssb&gt;  4096R/71C3BCD1  created: 2015-12-02  expires: 2025-11-29<br />                      card-no: 0006 04161578<br />ssb&gt;  4096R/506B0421  created: 2015-12-02  expires: 2016-12-01<br />                      card-no: 0006 04161578<br />ssb&gt;  4096R/ECE2B258  created: 2015-12-02  expires: 2016-12-01<br />                      card-no: 0006 04161578<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4063">dmonakhov</a> — Wed Dec 02, 2015 11:22 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[dmonakhov]]></name></author>
<updated>2015-12-02T11:00:03+01:00</updated>
<published>2015-12-02T11:00:03+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2114&amp;p=8039#p8039</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2114&amp;p=8039#p8039"/>
<title type="html"><![CDATA[Re: Yubikey 4 and RSA 4096]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2114&amp;p=8039#p8039"><![CDATA[
Yep.. You right. It shows that it support only 2048, but if you manually choose 4096 it will generate it.<br />Application ID ...: D2760001240102010006041615780000<br />Version ..........: 2.1<br />Manufacturer .....: Yubico<br />Serial number ....: 0416xxxx<br />Name of cardholder: [not set]<br />Language prefs ...: [not set]<br />Sex ..............: unspecified<br />URL of public key : [not set]<br />Login data .......: [not set]<br />Signature PIN ....: forced<br />Key attributes ...: 4096R 4096R 4096R<br />Max. PIN lengths .: 127 127 127<br />PIN retry counter : 3 0 3<br />Signature counter : 5<br />Signature key ....: B690 00AC 40B3 B578 A768  18AB B6EF FBE8 7982 EFC2<br />      created ....: 2015-12-02 09:38:37<br />Encryption key....: 3A09 6ACB B7F3 19BB 6E60  2D00 17F5 FF2E 59DC E7D2<br />      created ....: 2015-12-02 09:38:37<br />Authentication key: ABE8 1FFF B778 94BC 4376  8055 D38A AA6E 5FDE 027C<br />      created ....: 2015-12-02 09:38:37<br />General key info..: pub  4096R/7982EFC2 2015-12-02 Dmitry Monakhov (hw-gen-key-test) &lt;dmonakhov@openvz.org&gt;<br />sec&gt;  4096R/7982EFC2  created: 2015-12-02  expires: 2017-12-01<br />                      card-no: 0006 0416xxxx<br />ssb&gt;  4096R/5FDE027C  created: 2015-12-02  expires: 2017-12-01<br />                      card-no: 0006 0416xxxx<br />ssb&gt;  4096R/59DCE7D2  created: 2015-12-02  expires: 2017-12-01<br />                      card-no: 0006 0416xxxx<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4063">dmonakhov</a> — Wed Dec 02, 2015 11:00 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Himartin]]></name></author>
<updated>2015-11-30T22:05:07+01:00</updated>
<published>2015-11-30T22:05:07+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2114&amp;p=8034#p8034</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2114&amp;p=8034#p8034"/>
<title type="html"><![CDATA[Yubikey 4 and RSA 4096]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2114&amp;p=8034#p8034"><![CDATA[
Hi,<br /><br />I recently got a Yubikey 4. According to the feature list, this device should support RSA-Keys up to 4096 bit for GnuPG. However, when I do a <em>gpg2 --card-status</em> I get the following:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Application ID ...: D2760001240102010006041319390000<br />Version ..........: 2.1<br />Manufacturer .....: Yubico<br />Serial number ....: yyyyyyyy<br />Name of cardholder: xxxxxxxxx<br />Language prefs ...: de<br />Sex ..............: unspecified<br />URL of public key : &#91;not set&#93;<br />Login data .......: &#91;not set&#93;<br />Signature PIN ....: not forced<br />Key attributes ...: 2048R 2048R 2048R<br />Max. PIN lengths .: 127 127 127<br />PIN retry counter : 3 0 3<br />Signature counter : 0<br />Signature key ....: &#91;none&#93;<br />Encryption key....: &#91;none&#93;<br />Authentication key: &#91;none&#93;<br />General key info..: &#91;none&#93;<br /></div>In the line Key attributes it only says 2048R, which looks like it only supports 2048-bit keys.<br />Am I misunderstanding the meaning of this value? Or does the device require me to configure something to support longer keys? Has it to do with the GPG-version? (I'm using 2.0.28)<br /><br />Thanks.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4059">Himartin</a> — Mon Nov 30, 2015 10:05 pm</p><hr />
]]></content>
</entry>
</feed>