<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=1768" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2015-04-23T18:45:32+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=1768</id>
<entry>
<author><name><![CDATA[Uriel]]></name></author>
<updated>2015-04-23T18:45:32+01:00</updated>
<published>2015-04-23T18:45:32+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7236#p7236</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7236#p7236"/>
<title type="html"><![CDATA[Re: [Q?] NEO does not show up in Keychain (nor in Apple Mail]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7236#p7236"><![CDATA[
I'm sorry - I did not make it clear that my main problem is with the NEO PIV applet. NEO OpenPGP applet appears fine, and indeed works fine with Apple Mail (with the GPG Tools installed).<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3568">Uriel</a> — Thu Apr 23, 2015 6:45 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[rbondi]]></name></author>
<updated>2015-04-18T03:06:16+01:00</updated>
<published>2015-04-18T03:06:16+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7201#p7201</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7201#p7201"/>
<title type="html"><![CDATA[Re: [Q?] NEO does not show up in Keychain (nor in Apple Mail]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7201#p7201"><![CDATA[
<div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />My main problem is getting the NEO recognized by Keychain, and/or my Apple Mail. OpenSC software (but not tokend) and yubico-piv-tool work well enough with the NEO's PIV applet.<br /></div><br /><br />This question (<a href="http://forum.yubico.com/viewtopic.php?f=23&amp;t=1843" class="postlink">http://forum.yubico.com/viewtopic.php?f=23&amp;t=1843</a>) has some (unsatisfactory) ways to get the encryption key into the OSX GPG Keychain; and if there's an answer, it may offer a better way(s). FWIW all of these methods then had OSX Mail working automatically for me. I could even eject the Yubikey and *not* be able to read mail, which is exactly what should happen; and be able to read it again after re-inserting the Yubikey. <br /><br />Hope this helps, /rb<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3659">rbondi</a> — Sat Apr 18, 2015 3:06 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[uri]]></name></author>
<updated>2015-03-20T03:56:11+01:00</updated>
<published>2015-03-20T03:56:11+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7078#p7078</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7078#p7078"/>
<title type="html"><![CDATA[Re: [Q?] NEO does not show up in Keychain (nor in Apple Mail]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7078#p7078"><![CDATA[
&lt;blushing&gt; <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":-)" title="Smile" /><br /><br />Yeah, that worked. Got a ton of logs, for both CAC and NEO. Will analyze and post here.<br /><br />One weird thing - with CAC, even though it can't be unlocked by Keychain Access (and its certs don't seem visible by Apple Mail), I could successfully configure MS Outlook 2011 to use CAC to sign email (verified - it worked). But Keychain saw and reported on the private keys as well, just couldn't unlock.<br /><br />With NEO - Keychain does not see the private keys at all, only the certs. And no other tokend-related app (that I tried) was able to do anything with NEO PIV. (So far, that is.)<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3524">uri</a> — Fri Mar 20, 2015 3:56 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[zviratko]]></name></author>
<updated>2015-03-19T15:10:27+01:00</updated>
<published>2015-03-19T15:10:27+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7073#p7073</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7073#p7073"/>
<title type="html"><![CDATA[Re: [Q?] NEO does not show up in Keychain (nor in Apple Mail]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7073#p7073"><![CDATA[
You can<br /><br />/Library/OpenSC/etc/opensc.conf<br /><br />search for &quot;tokend&quot; <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":-)" title="Smile" /><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3463">zviratko</a> — Thu Mar 19, 2015 3:10 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Uriel]]></name></author>
<updated>2015-03-19T14:59:47+01:00</updated>
<published>2015-03-19T14:59:47+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7072#p7072</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7072#p7072"/>
<title type="html"><![CDATA[Re: [Q?] NEO does not show up in Keychain (nor in Apple Mail]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7072#p7072"><![CDATA[
Yes, we talk about both: original CAC cards, and Yubikey NEO.<br /><br />Yes,the do seem to have different problems. <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":-)" title="Smile" /><br /><br />However, at this point I have a few solutions that seem to work well with CAC on Mac:<br /><ul><li> CACKey package <a href="http://cacformac.com/downloads.htm" class="postlink">http://cacformac.com/downloads.htm</a></li><li> SmartCard Services <a href="http://smartcardservices.macosforge.org/trac/wiki/installers" class="postlink">http://smartcardservices.macosforge.org/trac/wiki/installers</a> (remove the <em>CAC.tokend</em> from <em>/System/Library/Security/tokend/</em> directory)</li><li> PKard</li><li> Centrify Express</li><li> OpenSC.tokend <a href="https://github.com/OpenSC/OpenSC.tokend" class="postlink">https://github.com/OpenSC/OpenSC.tokend</a> sees the CAC and all its certs, <strong>but does not work with it</strong></li></ul><br />For NEO PIV applet - only <em>OpenSC.tokend</em> even sees the token, but just like with CAC, it refuses to do anything useful with it. Which means that all the applications that rely on tokend, don't even see the NEO token (in PIV mode). <br /><br />I wish I could enable debugging output of <em>OpenSC.tokend</em>...<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3568">Uriel</a> — Thu Mar 19, 2015 2:59 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[zviratko]]></name></author>
<updated>2015-03-19T09:33:02+01:00</updated>
<published>2015-03-19T09:33:02+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7069#p7069</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7069#p7069"/>
<title type="html"><![CDATA[Re: [Q?] NEO does not show up in Keychain (nor in Apple Mail]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7069#p7069"><![CDATA[
Original CAC might be a different beast - are we talking about it, or about the PIV applet that we initialize ourselves? I reckon the original CAC and DoD cards will have a different structure than what yubico-piv-tool gives us, and different problems.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3463">zviratko</a> — Thu Mar 19, 2015 9:33 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[uri]]></name></author>
<updated>2015-03-19T03:35:22+01:00</updated>
<published>2015-03-19T03:35:22+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7066#p7066</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7066#p7066"/>
<title type="html"><![CDATA[Re: [Q?] NEO does not show up in Keychain (nor in Apple Mail]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7066#p7066"><![CDATA[
Related: <!-- m --><a class="postlink" href="https://github.com/OpenSC/OpenSC.tokend/issues/11">https://github.com/OpenSC/OpenSC.tokend/issues/11</a><!-- m --><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3524">uri</a> — Thu Mar 19, 2015 3:35 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Uriel]]></name></author>
<updated>2015-03-18T22:13:53+01:00</updated>
<published>2015-03-18T22:13:53+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7064#p7064</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7064#p7064"/>
<title type="html"><![CDATA[Re: [Q?] NEO does not show up in Keychain (nor in Apple Mail]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7064#p7064"><![CDATA[
The certificate(s) were visible in the &quot;Certificates&quot; tab of Keychain Access. Nothing was visible in &quot;My Certificates&quot; tab.<br /><br />Re. OpenSC FAQ: it does not seem to be correct, what can I say. What it states contradicts my direct experience. <br /><br />Deleting everything in /var/db/TokenCache/config and /var/db/TokenCache/tokens resulted in both NEO and CAC not being recognized any more.<br /><br />Continuing experiments. <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":-)" title="Smile" /><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3568">Uriel</a> — Wed Mar 18, 2015 10:13 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[zviratko]]></name></author>
<updated>2015-03-18T19:39:01+01:00</updated>
<published>2015-03-18T19:39:01+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7063#p7063</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7063#p7063"/>
<title type="html"><![CDATA[Re: [Q?] NEO does not show up in Keychain (nor in Apple Mail]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7063#p7063"><![CDATA[
I don't think OSX cares about the slots themselves - the certificates should definetly be visible, in my case they 100% are.<br /><br />Keychain unlocking has nothing to do with actually using the keys - it is just a cosmetic feature. It might cause PIN to get cached by Keychain for some tokens, but even in &quot;locked&quot; state it is completely usable (assuming everything else works).<br />Quoting from OpenSC FAQ:<br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />Q: It seems to be impossible to unlock the smart card keychain in Keychain Access.app ?<br /><br />A: The padlock in the Keychain Access GUI is just a GUI feature, it does not relate to unlocking smart card items with a PIN code. The PIN for the related key will be asked if used (for example, with Google Chrome for SSL authentication)<br /></div><br /><br /><br />I don't know what else to suggest - maybe try deleting the contents of /var/db/TokenCache - but that should not be an issue if you changed the CHUID...<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3463">zviratko</a> — Wed Mar 18, 2015 7:39 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Uriel]]></name></author>
<updated>2015-03-18T19:02:30+01:00</updated>
<published>2015-03-18T19:02:30+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7062#p7062</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7062#p7062"/>
<title type="html"><![CDATA[Re: [Q?] NEO does not show up in Keychain (nor in Apple Mail]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7062#p7062"><![CDATA[
1. Putting the same cert in 9a had no visible effect. The card is still visible as &quot;PIV-II&quot; in Keychain. It shows <span style="text-decoration: underline">one</span> certificate (which makes sense, because neither PIV Auth nor Card Auth are supposed to be usable by applications such as Keychain, AFAIK). It is still not unlock-able.<br /><br />Naturally, when I select  &quot;My Certificates&quot; (which means - certificates for which I have private keys) is shows <span style="text-decoration: underline">nothing</span>.<br /><br />2. Unlocking is not pointless - it enables access to the private keys. Since it turns out impossible - I'm not surprised that neither Apple Mail nor MS Outlook-2011 even saw my certs on the NEO. So of course I was unable to sign with it. <br /><br />6. Darn. So how to get OpenSC.tokend to work with NEO???  (And maybe Centrify?)<br /><br />7. Yeah, except that the card has no room for the intermediate certs - that's what belongs to the Keychain <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":)" title="Smile" />. But I've got that .p12 imported just fine, so doubt that part is a problem.<br /><br />Yeah, I've rebooted many times by now. Yeah, right now the only tokend in /System/Library/Security/tokend is OpenSC.tokend:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">$ ll /System/Library/Security/tokend<br />total 0<br />drwxr-xr-x  5 root  wheel  170 Mar 17 17:21 ./<br />drwxr-xr-x  8 root  wheel  272 Mar 16 13:05 ../<br />drwxr-xr-x  3 root  wheel  102 Oct 30 06:12 OpenSC.tokend/<br />drwxr-xr-x  7 root  wheel  238 Mar 17 17:21 tmp/<br />drwxr-xr-x  5 root  wheel  170 Apr 17  2014 uiplugins/<br /></div><br /><br />I think this is the relevant part of the logs:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Mar 18 11:48:51 hostname com.apple.SecurityServer&#91;38&#93;: Token reader Yubico Yubikey NEO OTP+U2F+CCID 00 00 inserted into system<br />Mar 18 11:48:53 hostname com.apple.SecurityServer&#91;38&#93;: reader Yubico Yubikey NEO OTP+U2F+CCID 00 00 inserted token &quot;PIV_II&quot; (c62cfe2c4e51372d76c7a0492489dda9b7c12671) subservice 12 using driver com.apple.tokend.opensc<br />Mar 18 11:49:00 hostname secd&#91;597&#93;:  SecErrorGetOSStatus unknown error domain: com.apple.security.sos.error for error: The operation couldn’t be completed. (com.apple.security.sos.error error 2 - Public Key not available - failed to register before call)<br />Mar 18 11:49:00 hostname secd&#91;597&#93;:  securityd_xpc_dictionary_handler Keychain Access&#91;44833&#93; DeviceInCircle The operation couldn’t be completed. (com.apple.security.sos.error error 2 - Public Key not available - failed to register before call)<br />...<br />Mar 18 13:27:06 hostname com.apple.SecurityServer&#91;38&#93;: reader Yubico Yubikey NEO OTP+U2F+CCID 00 00 removed token &quot;PIV_II&quot; (c62cfe2c4e51372d76c7a0492489dda9b7c12671) subservice 12<br />Mar 18 13:27:15 hostname com.apple.SecurityServer&#91;38&#93;: Token reader Yubico Yubikey NEO OTP+U2F+CCID 00 00 inserted into system<br />Mar 18 13:27:17 hostname com.apple.SecurityServer&#91;38&#93;: reader Yubico Yubikey NEO OTP+U2F+CCID 00 00 inserted token &quot;PIV_II&quot; (c62cfe2c4e51372d76c7a0492489dda9b7c12671) subservice 12 using driver com.apple.tokend.opensc<br />...<br />Mar 18 13:40:32 hostname apsd&#91;588&#93;: CFNetwork SSLHandshake failed (-9806)<br />Mar 18 13:40:40 hostname authexec&#91;78741&#93;: executing /Library/Frameworks/VirusScanPreferences.framework/Versions/Current/Resources/prefsHelperTool<br />Mar 18 13:40:48 hostname secd&#91;597&#93;:  SecErrorGetOSStatus unknown error domain: com.apple.security.sos.error for error: The operation couldn’t be completed. (com.apple.security.sos.error error 2 - Public Key not available - failed to register before call)<br />Mar 18 13:40:48 hostname secd&#91;597&#93;:  securityd_xpc_dictionary_handler Keychain Access&#91;78549&#93; DeviceInCircle The operation couldn’t be completed. (com.apple.security.sos.error error 2 - Public Key not available - failed to register before call)<br />Mar 18 13:40:48 hostname secd&#91;597&#93;:  SecErrorGetOSStatus unknown error domain: com.apple.security.sos.error for error: The operation couldn’t be completed. (com.apple.security.sos.error error 2 - Public Key not available - failed to register before call)<br />Mar 18 13:40:48 hostname secd&#91;597&#93;:  securityd_xpc_dictionary_handler Keychain Access&#91;78549&#93; DeviceInCircle The operation couldn’t be completed. (com.apple.security.sos.error error 2 - Public Key not available - failed to register before call)<br />Mar 18 13:40:48 hostname secd&#91;597&#93;:  SecErrorGetOSStatus unknown error domain: com.apple.security.sos.error for error: The operation couldn’t be completed. (com.apple.security.sos.error error 2 - Public Key not available - failed to register before call)<br />Mar 18 13:40:48 hostname secd&#91;597&#93;:  securityd_xpc_dictionary_handler Keychain Access&#91;78549&#93; DeviceInCircle The operation couldn’t be completed. (com.apple.security.sos.error error 2 - Public Key not available - failed to register before call)<br />Mar 18 13:40:48 hostname secd&#91;597&#93;:  SecErrorGetOSStatus unknown error domain: com.apple.security.sos.error for error: The operation couldn’t be completed. (com.apple.security.sos.error error 2 - Public Key not available - failed to register before call)<br />Mar 18 13:40:48 hostname secd&#91;597&#93;:  securityd_xpc_dictionary_handler Keychain Access&#91;78549&#93; DeviceInCircle The operation couldn’t be completed. (com.apple.security.sos.error error 2 - Public Key not available - failed to register before call)<br />Mar 18 13:40:48 hostname secd&#91;597&#93;:  SecErrorGetOSStatus unknown error domain: com.apple.security.sos.error for error: The operation couldn’t be completed. (com.apple.security.sos.error error 2 - Public Key not available - failed to register before call)<br />Mar 18 13:40:48 hostname secd&#91;597&#93;:  securityd_xpc_dictionary_handler Keychain Access&#91;78549&#93; DeviceInCircle The operation couldn’t be completed. (com.apple.security.sos.error error 2 - Public Key not available - failed to register before call)<br /></div><br /><br />And maybe this (happens with PKCS11.tokend):<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Mar 17 01:02:59 MacBook-Air.local com.apple.SecurityServer&#91;15&#93;: Token reader Yubico Yubikey NEO OTP+U2F+CCID 00 00 inserted into system<br />Mar 17 01:03:04 MacBook-Air.local com.apple.SecurityServer&#91;15&#93;: token in reader Yubico Yubikey NEO OTP+U2F+CCID 00 00 cannot be used (error 2147549225)<br /></div><br /><br />And this - on the same (MacBook Air) machine but with OpenSC.tokend:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Mar 17 01:53:27 MacBook-Air.local com.apple.SecurityServer&#91;15&#93;: Token reader Yubico Yubikey NEO OTP+U2F+CCID 00 00 inserted into system<br />Mar 17 01:53:31 MacBook-Air.local com.apple.SecurityServer&#91;15&#93;: reader Yubico Yubikey NEO OTP+U2F+CCID 00 00 inserted token &quot;PIV_II&quot; (5269d71a0501b05bbffa28e25bd8e73d569b21b2) subservice 7 using driver com.apple.tokend.opensc<br />.....<br />Mar 17 01:53:49 MacBook-Air.local launchservicesd&#91;80&#93;: Application App:&quot;iTerm&quot; asn:0x0-20020 pid:371 refs=7 @ 0x7fbc52519d60 tried to be brought forward, but isn't in fPermittedFrontApps ( ( &quot;LSApplication:0x0-0x22022 pid=455 &quot;SecurityAgent&quot;&quot;)), so denying. : LASSession.cp #1481 SetFrontApplication() q=LSSession 100004/0x186a4 queue<br />Mar 17 01:53:49 MacBook-Air.local WindowServer&#91;112&#93;: &#91;cps/setfront&#93; Failed setting the front application to iTerm, psn 0x0-0x20020, securitySessionID=0x186a4, err=-13066<br />Mar 17 01:53:49 MacBook-Air kernel&#91;0&#93;: Sandbox: mDNSResponder(65) deny file-read-data /<br />Mar 17 01:53:49 --- last message repeated 4 times ---<br />Mar 17 01:53:49 MacBook-Air kernel&#91;0&#93;: Sandbox: apsd(87) deny file-read-data /<br />Mar 17 01:53:50 MacBook-Air.local sandboxd&#91;282&#93; (&#91;87&#93;): apsd(87) deny file-read-data /<br />Mar 17 01:54:03 --- last message repeated 3 times ---<br /></div><br /><br />Though the last message could be from gpg-agent...<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3568">Uriel</a> — Wed Mar 18, 2015 7:02 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[zviratko]]></name></author>
<updated>2015-03-16T23:48:44+01:00</updated>
<published>2015-03-16T23:48:44+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7052#p7052</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7052#p7052"/>
<title type="html"><![CDATA[Re: [Q?] NEO does not show up in Keychain (nor in Apple Mail]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7052#p7052"><![CDATA[
Post logs, I'll take a look tomorrow.<br />Are you sure you cleaned all the tokends from the system? Have you tried rebooting?<br /><br />Maybe something is different on your 10.9.5 - CCID driver most probably? I know that some yubico software actually patches the supported readers, but I don't remember which one - not sure what messages you would get if it wasn't supported (but my guess would be no message at all, not even the 229 error). 10.9 should actually work better than 10.10...<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3463">zviratko</a> — Mon Mar 16, 2015 11:48 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[zviratko]]></name></author>
<updated>2015-03-16T23:44:40+01:00</updated>
<published>2015-03-16T23:44:40+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7051#p7051</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7051#p7051"/>
<title type="html"><![CDATA[Re: [Q?] NEO does not show up in Keychain (nor in Apple Mail]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7051#p7051"><![CDATA[
1. maybe try putting the same cert in 9a as well if it doesn't work with only 9c, it could by mandatory in some implementations<br />2. I don't have PKard, but can you post a few previous lines? This doesn't really tell if the PKard tokend was used. This (229 code) is however the same I got when my card was not provisioned to the tokend's liking (empty or &quot;wrong&quot; slots)<br /><br />As for OpenSC - do not try unlocking it in keychain - it's pointless and just UI. Try using it (sign an email), that will tell you if it works.<br /><br />6. Both OpenSC and Centrify work for me (now)<br /><br />7. Yes. Typically, what you want on card is:<br />a) the private key<br />b) the certificate signed by authority<br />c) all intermediate certificates, possibly including the root authority<br />(this is what I have in my .p12)<br /><br />I don't think intermediate CAs are imported by yubico-piv-tool (I don't know if that's even supported with PIV applet), so you might need to import the intermediate CAs into keychain to use the identity. But this will come after you see the card in keychain and has is irrelevant at this point. It's just a common problem when trying to actually use it without having all the anchors up to the trusted root (and I guess it's a bug that software like Firefox needs it).<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3463">zviratko</a> — Mon Mar 16, 2015 11:44 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Uriel]]></name></author>
<updated>2015-03-16T22:01:24+01:00</updated>
<published>2015-03-16T22:01:24+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7050#p7050</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7050#p7050"/>
<title type="html"><![CDATA[Re: [Q?] NEO does not show up in Keychain (nor in Apple Mail]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7050#p7050"><![CDATA[
1. I will blast the PIV applet, and re-create as you suggest, one slot at a time. Starting with 9c.<br /><br /><strong>Update.</strong> tried with filling the 9c slot only, same result: NEO PIV not recognized by Keychain, because no tokend seems comfortable with it.<br /><br />2. The original (fully provisioned) NEO PIV (will try slot-by-slot later).<br /><br />With Thursby PKard:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Mar 16 16:42:48 &lt;hostname&gt; PKard&#91;29341&#93;: TSSCardClass: presence NOT detected '/Library/Logs/com.thursby.pki.caching.disabled' uid=91<br />Mar 16 16:42:48 &lt;hostname&gt; com.apple.SecurityServer&#91;38&#93;: token in reader Yubico Yubikey NEO OTP+U2F+CCID 00 00 cannot be used (error 229)<br /></div><br /><br />With OpenSC (first token inserted was CAC - wanted to see if it can unlock it; it couldn't. Second inserted token was NEO):<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Mar 16 00:02:46 &lt;hostname&gt; apsd&#91;671&#93;: CFNetwork SSLHandshake failed (-9806)<br />...skipping...<br />ken &quot;PIV_II&quot; (d8e21ddbb4709a69c13ba7fc55908a4a8dd94afe) subservice 7<br />Mar 16 16:47:26 &lt;hostname&gt; apsd&#91;671&#93;: CFNetwork SSLHandshake failed (-9806)<br />Mar 16 16:47:38 &lt;hostname&gt; com.apple.SecurityServer&#91;38&#93;: Token reader Yubico Yubikey NEO OTP+U2F+CCID 00 00 inserted into system<br />Mar 16 16:47:40 &lt;hostname&gt; com.apple.SecurityServer&#91;38&#93;: reader Yubico Yubikey NEO OTP+U2F+CCID 00 00 inserted token &quot;PIV_II&quot; (930ec3d62bec500b8c71636d353d5b821e51378d) subservice 6 using driver com.apple.tokend.opensc<br />Mar 16 16:47:56 &lt;hostname&gt; apsd&#91;671&#93;: CFNetwork SSLHandshake failed (-9806)<br /></div><br /><br />4. Will try after this.<br /><strong>Update</strong>. Failed, behavior as before (i.e., as with the fully-provisioned card).<br /><br />5. I don't know, but would expect that any UUID in the right format should work. Your experience seems to confirm this assumption.<br /><br />6. Can you tell me which one you have installed right now, that seems to work OK with the NEO PIV?<br /><br />7. So that PKCS12 file contains your private key, and the corresponding public key (probably with signatures, so it's actually a cert)?<br /><br /><strong>Update.</strong> Figured that out, converting between different key+cert formats on the fly. Thanks, OpenSSL! <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":-)" title="Smile" /><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3568">Uriel</a> — Mon Mar 16, 2015 10:01 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[zviratko]]></name></author>
<updated>2015-03-16T21:10:17+01:00</updated>
<published>2015-03-16T21:10:17+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7049#p7049</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7049#p7049"/>
<title type="html"><![CDATA[Re: [Q?] NEO does not show up in Keychain (nor in Apple Mail]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7049#p7049"><![CDATA[
1. Test with just one slot, then fill it gradually - security and purpose of the slots differ, so I'd try not complicating things unless at least something works<br /><br />2. Then look at /var/log/system.log - it could hint at what's wrong (and which tokend is actually used)<br /><br />3. yeah, you're right here<br /><br />4. with OpenSC.tokend, I need to put my cert in the 9c slot. Putting the same cert in 9a slot doesn't work (everything seems fine but it can't sign anything - but I am not sure 100% that there isn't something else wrong here)<br /><br />5. Yes, just a &quot;-a set-chuid&quot; to yubico-piv-tool. I haven't investigated the purpose of CHUID, looks to me that as long as it is a new UUID it should work, even if it isn't the &quot;right&quot; number. No?<br /><br />6. I always just keep one. Don't leave more than one tokend installed (unless it's for a different card).<br /><br />7. My certificate comes from StartSSL and it was generated in Firefox. I exported it from here and haven't touched it afterwards. It contains my key+cert, and the Startcom Intermediate CA and root CA certificates (those don't get to the card).<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3463">zviratko</a> — Mon Mar 16, 2015 9:10 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Uriel]]></name></author>
<updated>2015-03-16T20:56:48+01:00</updated>
<published>2015-03-16T20:56:48+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7048#p7048</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7048#p7048"/>
<title type="html"><![CDATA[Re: [Q?] NEO does not show up in Keychain (nor in Apple Mail]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1768&amp;p=7048#p7048"><![CDATA[
Strange indeed. <img src="https://forum.yubico.com/images/smilies/icon_e_sad.gif" alt=":-(" title="Sad" /><br /><br />1. Yes I filled all the slots - but with different keys/certificates (of course <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":)" title="Smile" /> ).<br /><br />2. At this time I'm just trying to ascertain that the card is usable <span style="text-decoration: underline">by the OS apps (such as Mail and Keychain, and Safari/Chrome)</span> in the PIV mode - and the simplest way I know of checking it is via Keychain.<br /><br />3. Keychain doesn't see/detect the NEO <span style="text-decoration: underline">at all</span>. So I'd guess it's not a question of seeing a wrong cert.<br /><br />4. What do you mean by &quot;OpenSC works...with 9c slot&quot;? <br /><br />5. Centrify - what did you do with/for CHUID? Initiated it via &quot;yubico-piv-tool&quot; to a (sort of) random value? Or constructed a meaningful one, and fed to the card? If latter - how exactly did you construct it, and how did you write it to the card?<br /><br />6. How many tokend's do you currently have installed (and appearing in /System/Library/Security/tokend)?<br /><br />7. How did you create your cert.pkcs12?  (Just to make sure)<br /><br />Thanks!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3568">Uriel</a> — Mon Mar 16, 2015 8:56 pm</p><hr />
]]></content>
</entry>
</feed>