<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=1433" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2014-11-16T13:09:35+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=1433</id>
<entry>
<author><name><![CDATA[yonutz]]></name></author>
<updated>2014-11-16T13:09:35+01:00</updated>
<published>2014-11-16T13:09:35+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1433&amp;p=6234#p6234</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1433&amp;p=6234#p6234"/>
<title type="html"><![CDATA[Re: Applet Upload - mutual_authentication() returns 0x803020]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1433&amp;p=6234#p6234"><![CDATA[
I totally support hqarrse, he's right from all points of view. Since many things are changing lately it should be clear that NEO's up to serial number XXXX / shipping date XXXXX support this and don't support that. <br /><br />An informed customer is a happy customer. As to the announcement on the blog ... what can i say, i relied mostly on your official site rather then the blog.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3005">yonutz</a> — Sun Nov 16, 2014 1:09 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[hqarrse]]></name></author>
<updated>2014-07-25T07:28:28+01:00</updated>
<published>2014-07-25T07:28:28+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1433&amp;p=5434#p5434</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1433&amp;p=5434#p5434"/>
<title type="html"><![CDATA[Re: Applet Upload - mutual_authentication() returns 0x803020]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1433&amp;p=5434#p5434"><![CDATA[
hi Tom,<br /><br />sorry for the slow reply and thanks for yours!  Now I hang my head as yes, my NEO does work fine with the Autherticator app, although I just got connection error messages previously which is when I started on the long road to trying to install the Applet.  I wonder if the cure to my original issue was my adding keys to the NEO or I just screwed something up first time round.<br /><br />Better docs would be good, yes.  Hopefully this thread will help.<br /><br />Thank<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2957">hqarrse</a> — Fri Jul 25, 2014 7:28 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Tom]]></name></author>
<updated>2014-07-22T18:40:22+01:00</updated>
<published>2014-07-22T18:40:22+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1433&amp;p=5428#p5428</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1433&amp;p=5428#p5428"/>
<title type="html"><![CDATA[Re: Applet Upload - mutual_authentication() returns 0x803020]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1433&amp;p=5428#p5428"><![CDATA[
I think there is some confusion here.<br /><br />Your Yubikey NEO, already comes with OpenPGP, YubiOATH(Yubico Authenticator) and PIV installed so you can start using Yubico's applet right away.<br />The developer program is for those customers who would like to upload their custom applets on the Yubikey NEO.<br /><br />If we failed to communicate this to you, then we apologize and I will forward your comments to our website/PR team to make it more clear for everyone.<br /><br />This is a very recent change and lots of resources are currently working on major project and the right way of communicating the changes may have slipped out of our hands.<br /><br />Please, let me know if I misunderstood you.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2195">Tom</a> — Tue Jul 22, 2014 6:40 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[hqarrse]]></name></author>
<updated>2014-07-22T15:38:38+01:00</updated>
<published>2014-07-22T15:38:38+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1433&amp;p=5427#p5427</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1433&amp;p=5427#p5427"/>
<title type="html"><![CDATA[Re: Applet Upload - mutual_authentication() returns 0x803020]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1433&amp;p=5427#p5427"><![CDATA[
Tom,  thank you for getting back to me so quickly.  I'd like to point out a couple of things.<br /><br />Your blog post gives this information that is relevant to owners of new Yubikeys:<br /><br />(Old NEOs:) &quot;the card manager keys were set to a single value to facilitate development.&quot;<br />Yubikeys are &quot;no longer configured with the fixed card manager keys.&quot;<br />&quot;We are setting up a YubiKey NEO Developers program for you to order YubiKey NEO “Developer Edition” that come with the known card manager keys&quot; (from &quot;What does this mean if you want to <strong><span style="text-decoration: underline">develop</span></strong> applets&quot;)<br /><br />Nowhere on your site, except your answer above says that new NEOs cannot use applets <a href="http://www.yubico.com/products/yubikey-hardware/yubikey-neo/" class="postlink">as advertised in the core features</a>.  Not the OATH help files, not your product information page, not the android app, not this forum, not the blog.  Nowhere.<br /><br />If you think I'm being stupid then I would give you this reasoned explanation of  why a user would conclude that a new NEO could use the apps (I will ignore that fact that it is advertised as being able to):<br /><br />- There is now a NEO and a developer edition.  I am not a developer.  I want to use the standard apps - conclusion?  No problem.  If they were called the &quot;standard&quot; and &quot;restricted&quot; versions then I may think otherwise.<br />- There is lots of information on the internet and here about how to set keys on Yubikeys using gpshell so it seems that there is no problem with a lack of default keys.<br />- When you set up your keys you are prompted to change the default admin PIN (this means I don't have to worry about attackers being able to do whatever I can (as they would with the default setup and as referred to in your blog))<br />- The gpinstall.txt file supplied with OATH applet has a connect line containing the default keys which can obviously be edited to non-default ones (this would in fact appear to be the answer to the <a href="http://forum.yubico.com/viewtopic.php?f=26&amp;t=1428" class="postlink">same problem as mine in a previous thread</a>.)<br />- Somewhere is says that the Neo manager can't be used with the new NEOs.  Nowhere does it say that the same applies to uploading applets using gpshell.<br />- and to repeat my main point above - nowhere on here is the really important piece of information given, or even implied that new NEOs don't have the advertised features.<br /><br />Need I say that it took me a while to cool down before writing this.  Please make it clear to customers that new NEOs don't do X,Y,Z to avoid a lot of wasted time and frustration.  It is a job of minutes for you to do.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2957">hqarrse</a> — Tue Jul 22, 2014 3:38 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Tom]]></name></author>
<updated>2014-07-22T07:41:03+01:00</updated>
<published>2014-07-22T07:41:03+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1433&amp;p=5424#p5424</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1433&amp;p=5424#p5424"/>
<title type="html"><![CDATA[Re: Applet Upload - mutual_authentication() returns 0x803020]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1433&amp;p=5424#p5424"><![CDATA[
Hello,<br /><br />Please refer to this blog post <!-- m --><a class="postlink" href="http://www.yubico.com/2014/07/yubikey-neo-updates/">http://www.yubico.com/2014/07/yubikey-neo-updates/</a><!-- m --><br /><br />If you don't have a developer NEO you wont be able to access Yubico applets or add your own.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2195">Tom</a> — Tue Jul 22, 2014 7:41 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[hqarrse]]></name></author>
<updated>2014-07-21T17:30:44+01:00</updated>
<published>2014-07-21T17:30:44+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1433&amp;p=5422#p5422</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1433&amp;p=5422#p5422"/>
<title type="html"><![CDATA[Applet Upload - mutual_authentication() returns 0x80302000]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1433&amp;p=5422#p5422"><![CDATA[
After a long fight to get GPShell working and my 3000000+ Neo in to a fit state to upload an OATH applet to, I am stuck at what feels like the final hurdle.  The upload script fails on the connect command.<br /><br />My card is in the m82 mode.<br /><br />I have added keys to my neo with gpg, and gpg --card-edit shows these clearly:<br /><br />Application ID ...: D2760001240102000006002DC6F40000<br />Version ..........: 2.0<br />Manufacturer .....: unknown<br />Serial number ....: 002DC6F4<br />Name of cardholder: [not set]<br />Language prefs ...: [not set]<br />Sex ..............: unspecified<br />URL of public key : [not set]<br />Login data .......: [not set]<br />Signature PIN ....: forced<br />Key attributes ...: 2048R 2048R 2048R<br />Max. PIN lengths .: 127 127 127<br />PIN retry counter : 3 3 3<br />Signature counter : 5<br />Signature key ....: 1F56 A992 5577 66F3 CEEB  E6D0 8EC0 7DDF 100F D182<br />      created ....: 2014-07-20 20:25:20<br />Encryption key....: 86C5 EC26 501B A2F9 5A3E  31CB 9BC3 13F9 0A97 3908<br />      created ....: 2014-07-20 20:25:20<br />Authentication key: 142D C757 A906 475C F56F  CE34 E1DF 7D9F D086 0530<br />      created ....: 2014-07-20 20:25:20<br />General key info..: <br />pub  2048R/100FD182 2014-07-20 My Name (test) &lt;xxxxx@xxxxx.com&gt;<br />sec&gt;  2048R/100FD182  created: 2014-07-20  expires: never     <br />                      card-no: 0006 002DC6F4<br />ssb&gt;  2048R/D0860530  created: 2014-07-20  expires: never     <br />                      card-no: 0006 002DC6F4<br />ssb&gt;  2048R/0A973908  created: 2014-07-20  expires: never     <br />                      card-no: 0006 002DC6F4<br /><br />I have edited the OATH gpinstall.txt file to point correctly to the supplied .CAP file to contain the keys above.  But I always get:<br /><br />mode_211<br />enable_trace<br />establish_context<br />card_connect<br />select -AID a000000003000000<br />Command --&gt; 00A4040008A000000003000000<br />Wrapped command --&gt; 00A4040008A000000003000000<br />Response &lt;-- 6F658408A000000003000000A5599F6501FF9F6E06479112103800734A06072A864886FC6B01600C060A2A864886FC6B02020101630906072A864886FC6B03640B06092A864886FC6B040255650B06092B8510864864020103660C060A2B060104012A026E01029000<br />open_sc -security 1 -keyind 0 -keyver 0 -mac_key 142DC757A906475CF56FCE34E1DF7D9FD0860530 -enc_key  86C5EC26501BA2F95A3E31CB9BC313F90A973908<br />Command --&gt; 80CA006600<br />Wrapped command --&gt; 80CA006600<br />Response &lt;-- 664C734A06072A864886FC6B01600C060A2A864886FC6B02020101630906072A864886FC6B03640B06092A864886FC6B040255650B06092B8510864864020103660C060A2B060104012A026E01029000<br />Command --&gt; 80500000088376364DA61E2E0300<br />Wrapped command --&gt; 80500000088376364DA61E2E0300<br />Response &lt;-- 00003319002063970936FF020002BD279D5ADBCA986DD27B982077549000<br />mutual_authentication() returns 0x80302000 (The verification of the card cryptogram failed.)<br /><br />Any suggestions very welcome as I'm getting to the point of adjusting the my new NEO with a hammer!<br /><br />_____________<br /><br />gpinstall.txt:<br /><br />mode_211<br />enable_trace<br /><br />establish_context <br />card_connect<br />select -AID a000000003000000<br />open_sc -security 1 -keyind 0 -keyver 0 -mac_key 142DC757A906475CF56FCE34E1DF7D9FD0860530 -enc_key  86C5EC26501BA2F95A3E31CB9BC313F90A973908<br /><br />delete -AID a000000527210101<br />delete -AID a0000005272101<br />      <br />install -file /home/rob/Downloads/ykneo-oath-0.2.1.cap -instParam 00 -priv 00<br />card_disconnect<br />release_context<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2957">hqarrse</a> — Mon Jul 21, 2014 5:30 pm</p><hr />
]]></content>
</entry>
</feed>