<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=35&amp;t=2654" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2017-06-21T10:56:36+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=35&amp;t=2654</id>
<entry>
<author><name><![CDATA[ChrisHalos]]></name></author>
<updated>2017-06-20T16:06:22+01:00</updated>
<published>2017-06-20T16:06:22+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2654&amp;p=9629#p9629</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2654&amp;p=9629#p9629"/>
<title type="html"><![CDATA[Re: [Q?] YubiKey 4, RSA3072 with public exponent 3 for signi]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2654&amp;p=9629#p9629"><![CDATA[
RSA 3072 can only be done on the OpenPGP applet via gpg2 commands. 3072 is not a supported algorithm in the PIV spec.<br /><br />No, exponent 3 is not supported. We only accept F4 as an exponent since 3 is considered weak and could lead to some theoretical attacks. This also follows the specifications of the OpenPGP card which supports this behavior.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3140">ChrisHalos</a> — Tue Jun 20, 2017 4:06 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[rebane]]></name></author>
<updated>2017-06-21T10:56:36+01:00</updated>
<published>2017-06-20T15:29:00+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2654&amp;p=9628#p9628</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2654&amp;p=9628#p9628"/>
<title type="html"><![CDATA[[S!] YubiKey 4, RSA3072 with public exponent 3 for signing]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2654&amp;p=9628#p9628"><![CDATA[
I would like to use YubiKey 4 to sign arbitrary binary blobs.<br /><br />1) Is it possible to generate (or import) RSA 3072 keys on YubiKey 4? How?<br /><br />I have tried to use the PIV tool (which currently only supports up to RSA 2048 keys) and pkcs11-tool (which does not list a suitable mechanism, e.g. RSA-PKCS-KEY-PAIR-GEN).<br /><br />2) Does YubiKey 4 support RSA keys with public exponent other than 65537 (0x10001)?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4823">rebane</a> — Tue Jun 20, 2017 3:29 pm</p><hr />
]]></content>
</entry>
</feed>