<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=35&amp;t=2747" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2017-10-08T22:44:30+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=35&amp;t=2747</id>
<entry>
<author><name><![CDATA[goerz]]></name></author>
<updated>2017-10-08T22:42:46+01:00</updated>
<published>2017-10-08T22:42:46+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2747&amp;p=9836#p9836</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2747&amp;p=9836#p9836"/>
<title type="html"><![CDATA[Re: [SOLVED] Disable 6 second delay for openpgp touch prompt]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2747&amp;p=9836#p9836"><![CDATA[
Ok, since it seems it's working for you without the 6 second delay, I just de- and then re-activated the touch feature, and now it seems to work immediately. This was on MacOS, btw.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4925">goerz</a> — Sun Oct 08, 2017 10:42 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Morthawt]]></name></author>
<updated>2017-10-08T21:49:19+01:00</updated>
<published>2017-10-08T21:49:19+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2747&amp;p=9834#p9834</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2747&amp;p=9834#p9834"/>
<title type="html"><![CDATA[Re: [QUESTION] Disable 6 second delay for openpgp touch prom]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2747&amp;p=9834#p9834"><![CDATA[
I have tracked it down: <!-- m --><a class="postlink" href="https://developers.yubico.com/yubikey-manager-qt/Releases/">https://developers.yubico.com/yubikey-m ... /Releases/</a><!-- m --><br /><br />I did:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">C:\Program Files (x86)\Yubico\YubiKey Manager&gt;ykman openpgp touch aut on<br />Current touch policy of AUTHENTICATE key is OFF.<br />Set touch policy of AUTHENTICATE key to ON? &#91;y/N&#93;: y<br />Enter admin PIN:<br />Touch policy successfully set.<br /><br />C:\Program Files (x86)\Yubico\YubiKey Manager&gt;ykman openpgp touch enc on<br />Current touch policy of ENCRYPT key is OFF.<br />Set touch policy of ENCRYPT key to ON? &#91;y/N&#93;: y<br />Enter admin PIN:<br />Touch policy successfully set.<br /><br />C:\Program Files (x86)\Yubico\YubiKey Manager&gt;ykman openpgp touch sig on<br />Current touch policy of SIGN key is OFF.<br />Set touch policy of SIGN key to ON? &#91;y/N&#93;: y<br />Enter admin PIN:<br />Touch policy successfully set.</div><br /><br />Then I unplugged and plugged back in. Now as soon as I type in my pin to sign, it sits there forever waiting. So then I press the button and it works. I repeat, same thing only I can press it as soon as I want and it will complete. same with decrypting things, I enter my pin and tough the contact on the Yubikey, else it sits there, presumably until it times out or something. I like this feature and it should be part of the normal personalisation tool in my opinion. <br /><br />If you are using linux, perhaps there is a difference between that and the windows version? It is BETA after all, so I don't know what else to tell you. I am going to leave the feature disabled I think though, because if I cannot protect my Neo with it, I do not want to the false sense of security that could come from relying on this and forgetting when I use the Neo. But if it were available on both, I would leave it enabled.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1739">Morthawt</a> — Sun Oct 08, 2017 9:49 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Morthawt]]></name></author>
<updated>2017-10-08T21:16:47+01:00</updated>
<published>2017-10-08T21:16:47+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2747&amp;p=9833#p9833</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2747&amp;p=9833#p9833"/>
<title type="html"><![CDATA[Re: [QUESTION] Disable 6 second delay for openpgp touch prom]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2747&amp;p=9833#p9833"><![CDATA[
I cannot find the download link for it. I am on windows. What would I need to experiment with this any way?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1739">Morthawt</a> — Sun Oct 08, 2017 9:16 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Morthawt]]></name></author>
<updated>2017-10-08T21:15:33+01:00</updated>
<published>2017-10-08T21:15:33+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2747&amp;p=9832#p9832</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2747&amp;p=9832#p9832"/>
<title type="html"><![CDATA[Re: [QUESTION] Disable 6 second delay for openpgp touch prom]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2747&amp;p=9832#p9832"><![CDATA[
I don't know, it seems a bit dodgy to me. I can understand, maybe, a full reset of the OpenPGP applet being command-liny and complex looking but if you have to use scripts and things to enable a &quot;feature&quot; it seems more like a beta or test feature than something that Yubico expect users to do. I have been all over the personalisation tool and I have seen no mention anywhere of this. I would be concerned about wrecking something. Does this work on a new Neo too? If this is something I can experiment without breaking either my 4 or Neo then I might give it a try and let you know what happens.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1739">Morthawt</a> — Sun Oct 08, 2017 9:15 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[goerz]]></name></author>
<updated>2017-10-08T20:11:51+01:00</updated>
<published>2017-10-08T20:11:51+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2747&amp;p=9831#p9831</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2747&amp;p=9831#p9831"/>
<title type="html"><![CDATA[Re: [QUESTION] Disable 6 second delay for openpgp touch prom]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2747&amp;p=9831#p9831"><![CDATA[
It's a feature that was introduced on the Yubikey 4 (off by default), and is documented at e.g. <!-- m --><a class="postlink" href="https://developers.yubico.com/PGP/Card_edit.html">https://developers.yubico.com/PGP/Card_edit.html</a><!-- m -->. Personally, I found that it's most easily configured using the ykman command line utility (<!-- m --><a class="postlink" href="https://github.com/Yubico/yubikey-manager">https://github.com/Yubico/yubikey-manager</a><!-- m -->), rather than through the shell script linked in the documentation. In any case the documentation does not mention that there should be any delay.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4925">goerz</a> — Sun Oct 08, 2017 8:11 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Morthawt]]></name></author>
<updated>2017-10-08T13:43:32+01:00</updated>
<published>2017-10-08T13:43:32+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2747&amp;p=9829#p9829</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2747&amp;p=9829#p9829"/>
<title type="html"><![CDATA[Re: [QUESTION] Disable 6 second delay for openpgp touch prom]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2747&amp;p=9829#p9829"><![CDATA[
Is that an undocumented feature? I have never seen that listed anywhere. I need to press my finger to get a TOTP from the authenticator app but openPGP needs nothing other than my pin.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1739">Morthawt</a> — Sun Oct 08, 2017 1:43 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[goerz]]></name></author>
<updated>2017-10-08T22:44:30+01:00</updated>
<published>2017-10-08T00:42:06+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2747&amp;p=9828#p9828</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2747&amp;p=9828#p9828"/>
<title type="html"><![CDATA[[SOLVED] Disable 6 second delay for openpgp touch prompt]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2747&amp;p=9828#p9828"><![CDATA[
I've set up an OpenPGP key on my YubiKey4, and also activated the setting that I have to confirm any use of the key by pressing it (via the command line utility <div class="codetitle"><b>Code:</b></div><div class="codecontent">ykman openpgp touch aut ...</div>). However, whenever I issue a GPG command, there is about a 6 second delay before the YubiKey starts flashing (indicating that it's ready for my finger). More specifically, the YubiKey flickers once (very quickly) immediately after I issue the GPG command, then once more at about 3 seconds, and then start slow-flashing after 6 seconds (for 15 seconds, until it times out).<br /><br />If I touch the key before the 6 seconds, it enters the OTP password.<br /><br />Is there any way to configure the key so that I can touch it immediately after issuing the GPG command? Six seconds feels like an eternity on the command line!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4925">goerz</a> — Sun Oct 08, 2017 12:42 am</p><hr />
]]></content>
</entry>
</feed>