<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=2211" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2016-02-16T20:01:51+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=2211</id>
<entry>
<author><name><![CDATA[Uriel]]></name></author>
<updated>2016-02-16T20:01:51+01:00</updated>
<published>2016-02-16T20:01:51+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2211&amp;p=8335#p8335</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2211&amp;p=8335#p8335"/>
<title type="html"><![CDATA[Re: [BUG] S/MIME Mail Signing / Decryption not working]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2211&amp;p=8335#p8335"><![CDATA[
I've had problems with Thunderbird decrypting S/MIME on different machines with different PKCS11 middleware (including Windows). So I'm certain there's something about Thunderbird itself.<br /><br />I've also successfully did signature &amp; verification (using RSA and ECC), and encryption &amp; decryption (using RSA) with Yubikey NEO and Yubikey 4 on Mac, using Apple Mail, MS Outlook 2011, and Thunderbird. <br /><br />Apple Mail often loses track of the token authentication status, and fails to sign outgoing. Possibly Yubikey's problem, but people were reporting similar issues with DoD CAC.<br /><br />Thunderbird on some Mac boxes is very unreliable and refuses to send encrypted. Observed only with Yubikey on Mac (so far  <img src="https://forum.yubico.com/images/smilies/icon_e_wink.gif" alt=";)" title="Wink" /> ), works reliably on other platforms with other tokens and middleware.<br /><br />Thunderbird on many different boxes refuses to decrypt when the decryption key is on a hardware token. This was evidenced consistently on several different platforms with several different token types and different middleware. Definitely not a Yubikey problem.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3568">Uriel</a> — Tue Feb 16, 2016 8:01 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[tzn]]></name></author>
<updated>2016-02-16T13:11:21+01:00</updated>
<published>2016-02-16T13:11:21+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2211&amp;p=8332#p8332</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2211&amp;p=8332#p8332"/>
<title type="html"><![CDATA[Re: [BUG] S/MIME Mail Signing / Decryption not working]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2211&amp;p=8332#p8332"><![CDATA[
For further information, we also tested another USB-based token device that stores s/mime certificates and uses the opensc-pkcs11 module. It works on the same machine using the same software stack without issues. IMHO that strengthens my assumption, that it is a yubikey-related issue.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4163">tzn</a> — Tue Feb 16, 2016 1:11 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[tzn]]></name></author>
<updated>2016-02-15T17:03:07+01:00</updated>
<published>2016-02-15T17:03:07+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2211&amp;p=8326#p8326</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2211&amp;p=8326#p8326"/>
<title type="html"><![CDATA[Re: [BUG] S/MIME Mail Signing / Decryption not working]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2211&amp;p=8326#p8326"><![CDATA[
I managed to set-ccc by setting a new management key but that did not change anything. The error still persists.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4163">tzn</a> — Mon Feb 15, 2016 5:03 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[tzn]]></name></author>
<updated>2016-02-15T15:16:54+01:00</updated>
<published>2016-02-15T15:16:54+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2211&amp;p=8323#p8323</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2211&amp;p=8323#p8323"/>
<title type="html"><![CDATA[Re: [BUG] S/MIME Mail Signing / Decryption not working]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2211&amp;p=8323#p8323"><![CDATA[
After removing anything smartcard related from the system, then reinstalling the yubico packages using the yubico PPA I now have the newest stable version of yubico-piv-tool. Obviously, the one in the official ubuntu PPA is outdated.<br /><br />Checking the status:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">&gt; yubico-piv-tool -a status<br />CHUID: &lt;very long hex number&gt;<br />CCC:   No data available<br />Slot 9c:   <br />   &lt;...&gt; <br />Slot 9d:   <br />    &lt;....&gt;<br />PIN tries left:   3<br /></div><br /><br />So indeed, CCC is apparently not set. However, I can't do set-ccc due to some authentication problem that I can't get around:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">&gt; yubico-piv-tool -a set-ccc<br />Failed authentication with the application.<br /></div><br /><br />In fact, I can't do anything that requires authentication (reset, set-mgm-key, ...). I never changed the management key and it should be default.<br /><br />Also, I wonder, if &quot;set-ccc&quot; is such a critical setting, why is there no documentation about it, and why is this option not included in the stable ubuntu PPA release? Not even the yubico-piv-tool documentation <a href="https://www.yubico.com/wp-content/uploads/2015/04/Yubico-PIV-Management-Tools_v1.0.pdf" class="postlink">https://www.yubico.com/wp-content/uploads/2015/04/Yubico-PIV-Management-Tools_v1.0.pdf</a> mentions it.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4163">tzn</a> — Mon Feb 15, 2016 3:16 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[tzn]]></name></author>
<updated>2016-02-15T10:00:59+01:00</updated>
<published>2016-02-15T10:00:59+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2211&amp;p=8320#p8320</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2211&amp;p=8320#p8320"/>
<title type="html"><![CDATA[Re: [BUG] S/MIME Mail Signing / Decryption not working]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2211&amp;p=8320#p8320"><![CDATA[
<div class="quotetitle">Uriel wrote:</div><div class="quotecontent"><br />Just to make sure: did you fully initialize your Yubikey NEO with yubico-piv-tool? You need to look at &quot;set-chuid&quot; and &quot;set-ccc&quot;. Without these two your Yubikey is not PIV-compliant enough for other software to use it.<br /></div><br /><br />I would like to verify that, unfortunately, my system suddenly does not recognize any smart card reader anymore.<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">&gt; yubico-piv-tool -a set-chuid<br />Failed to connect to reader.</div><br /><br />Anyway, there does not seem to be a &quot;set-ccc&quot; option / action:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">&gt; yubico-piv-tool -a set-ccc<br />yubico-piv-tool: invalid argument, &quot;set-ccc&quot;, for option `--action' (`-a')<br />&gt; yubico-piv-tool --set-ccc<br />yubico-piv-tool: unrecognized option '--set-ccc'<br />&gt; man yubico-piv-tool | grep set-ccc<br /><br /></div><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4163">tzn</a> — Mon Feb 15, 2016 10:00 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Uriel]]></name></author>
<updated>2016-02-12T23:14:46+01:00</updated>
<published>2016-02-12T23:14:46+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2211&amp;p=8312#p8312</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2211&amp;p=8312#p8312"/>
<title type="html"><![CDATA[Re: [BUG] S/MIME Mail Signing / Decryption not working]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2211&amp;p=8312#p8312"><![CDATA[
Just to make sure: did you fully initialize your Yubikey NEO with yubico-piv-tool? You need to look at &quot;set-chuid&quot; and &quot;set-ccc&quot;. Without these two your Yubikey is not PIV-compliant enough for other software to use it.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3568">Uriel</a> — Fri Feb 12, 2016 11:14 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[tzn]]></name></author>
<updated>2016-02-12T12:28:24+01:00</updated>
<published>2016-02-12T12:28:24+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2211&amp;p=8303#p8303</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2211&amp;p=8303#p8303"/>
<title type="html"><![CDATA[[BUG] S/MIME Mail Signing / Decryption not working]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2211&amp;p=8303#p8303"><![CDATA[
Hello,<br /><br />we are trying to get S/MIME-based email signing and decryption working using Yubikey Neo and Yubikey 4 with Thunderbird / opensc on Linux. Unfortunately we always encounter the same problems.<br /><br /><strong>Thunderbird cannot reliably communicate with Yubikey and always looses the reference to the certificate.</strong><br /><br />The first time we try to send a signed mail or decrypt a stored mail it works. Thunderbirds asks for the PIN (strangely called master password for some reason) and resumes operation as expected. However, after that, both signing and decryption ceases to function.<br /><br />Trying to sign mails fails with:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Sending of the message failed.<br />You specified that this message should be digitally signed, but the application either failed to find the signing certificate specified in your Mail &amp; Newsgroup Account Settings, or the certificate has expired.<br /></div><br /><br />Decrypting mails fails with:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Thunderbird cannot decrypt this message<br />The sender encrypted this message to you using one of your digital certificates, however Thunderbird was not able to find this certificate and corresponding private key.<br /></div><br /><br />Sometimes Thunderbird will repeatedly ask for the &quot;master password for PIV&quot; without managing to log into the key, sometimes it will not ask at all. In any case it does not work.<br /><br />The only solution we found so far was to eject and reinsert the Yubikey. Then the next single signing or decryption operation will succeed. After that, the error reoccurs.<br /><br />We have confirmed that on two different machines running two newly installed flavors of Ubuntu. I am unsure whether this is Yubikey or opensc related, so it could as well be an opensc bug. But since opensc is apparently the only driver for Yubikey it's effectively a Yubikey problem.<br /><br />Software:<br />xubuntu / ubunut-gnome 15.10 x86_64 4.2.0-27-generic<br />Thunderbird 38.5.1<br />OpenSC 0.15.0 [gcc  4.9.2]<br /><br />Best regards<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4163">tzn</a> — Fri Feb 12, 2016 12:28 pm</p><hr />
]]></content>
</entry>
</feed>