<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=2146" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2016-01-20T16:50:26+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=2146</id>
<entry>
<author><name><![CDATA[KenMacD]]></name></author>
<updated>2016-01-20T16:50:26+01:00</updated>
<published>2016-01-20T16:50:26+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8205#p8205</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8205#p8205"/>
<title type="html"><![CDATA[Re: YubiKey 4 - cannot set PIN retry counter to desired valu]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8205#p8205"><![CDATA[
Thanks Tom.<br /><br />I've decided instead of generating my authentication key on the Yubikey to generate it off-key so I can create a backup just in case.<br /><br />I'll keep an eye out to see how the new spec, or your implementation, will handle locked keys.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4150">KenMacD</a> — Wed Jan 20, 2016 4:50 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Tom2]]></name></author>
<updated>2016-01-20T14:16:46+01:00</updated>
<published>2016-01-20T14:16:46+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8204#p8204</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8204#p8204"/>
<title type="html"><![CDATA[Re: YubiKey 4 - cannot set PIN retry counter to desired valu]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8204#p8204"><![CDATA[
We hear you guys and we thought about bringing back this feature for YK4. However, since this feature might be included in the future spec of OpenPGP, we may decide to wait to implement this conforming to the standard.<br /><br />In short, we are currently waiting observing developments which will decide how we will bring this back.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3364">Tom2</a> — Wed Jan 20, 2016 2:16 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[KenMacD]]></name></author>
<updated>2016-01-20T03:52:45+01:00</updated>
<published>2016-01-20T03:52:45+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8201#p8201</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8201#p8201"/>
<title type="html"><![CDATA[Re: YubiKey 4 - cannot set PIN retry counter to desired valu]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8201#p8201"><![CDATA[
I agree with Uriel. With the Admin PIN this value should be able to be modified. 3 is just too risky for a password of over 30 characters.<br /><br />Also is there anything to prevent malware from coming along and locking the pins?<br /><br />It would be really nice if there was a way for the counter to reset with every power-off. This is the way encrypted WD My Passport drives work, and seems like it would make a brute-force attack pretty much impossible.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4150">KenMacD</a> — Wed Jan 20, 2016 3:52 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Uriel]]></name></author>
<updated>2016-01-08T20:32:42+01:00</updated>
<published>2016-01-08T20:32:42+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8133#p8133</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8133#p8133"/>
<title type="html"><![CDATA[Re: YubiKey 4 - cannot set PIN retry counter to desired valu]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8133#p8133"><![CDATA[
<div class="quotetitle">Tom2 wrote:</div><div class="quotecontent"><br />That's by specification. <br />Open PGP<br /><!-- m --><a class="postlink" href="http://g10code.com/docs/openpgp-card-3.0.pdf">http://g10code.com/docs/openpgp-card-3.0.pdf</a><!-- m --><br /></div><br /><br />Thank you for the reference. I notice that none of the OpenPGP specs (v1.0, 2.0, 3.0) actually include setting the retry counter to a specific value. They only say that at the reset it should return to the default.<br /><br />However I find it very convenient and user-friendly that NEO extends this and allows me to set it to (say) 5 instead of 3, because (a) this is the policy where I employ it, and (b) it is perfectly convenient for me. So I'm very much disappointed that Yubico decided to get &quot;strict&quot; with Yubikey 4. There doesn't seem to be a reason (nor a need) for it.<br /><br /><strong>Update</strong><br />It is understandable why the standard may want to preclude <span style="text-decoration: underline">users</span> from being able to change the retry counter. Preventing the <span style="text-decoration: underline">organizations</span> that own and deploy such devices from setting whatever policy on the number of retries they see fit, seems very wrong - and I've yet to see a standard explicitly demanding this.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3568">Uriel</a> — Fri Jan 08, 2016 8:32 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Tom2]]></name></author>
<updated>2016-01-08T16:39:53+01:00</updated>
<published>2016-01-08T16:39:53+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8131#p8131</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8131#p8131"/>
<title type="html"><![CDATA[Re: YubiKey 4 - cannot set PIN retry counter to desired valu]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8131#p8131"><![CDATA[
That's by specification.<br /><br />Open PGP<br /><br /><!-- m --><a class="postlink" href="http://g10code.com/docs/openpgp-card-3.0.pdf">http://g10code.com/docs/openpgp-card-3.0.pdf</a><!-- m --><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3364">Tom2</a> — Fri Jan 08, 2016 4:39 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[mouse008]]></name></author>
<updated>2016-01-07T04:12:54+01:00</updated>
<published>2016-01-07T04:12:54+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8123#p8123</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8123#p8123"/>
<title type="html"><![CDATA[Re: YubiKey 4 - cannot set PIN retry counter to desired valu]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8123#p8123"><![CDATA[
<div class="quotetitle">Tom2 wrote:</div><div class="quotecontent"><br />That feature is not available on the YubiKey 4<br /></div><br /><br />Wha...? Are you saying that on YubiKey 4 pin-retries is <strong>hard-coded</strong> to be &quot;three times&quot;?!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4029">mouse008</a> — Thu Jan 07, 2016 4:12 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Tom2]]></name></author>
<updated>2016-01-05T12:17:53+01:00</updated>
<published>2016-01-05T12:17:53+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8114#p8114</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8114#p8114"/>
<title type="html"><![CDATA[Re: YubiKey 4 - cannot set PIN retry counter to desired valu]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8114#p8114"><![CDATA[
That feature is not available on the YubiKey 4<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3364">Tom2</a> — Tue Jan 05, 2016 12:17 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[mouse008]]></name></author>
<updated>2016-01-04T04:36:05+01:00</updated>
<published>2016-01-04T04:36:05+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8109#p8109</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8109#p8109"/>
<title type="html"><![CDATA[YubiKey 4 - cannot set PIN retry counter to desired value?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2146&amp;p=8109#p8109"><![CDATA[
Preface: on YubiKey NEO it works like charm:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">gpg-connect-agent --hex &quot;scd apdu 00 20 00 83 08 31 32 33 34 35 36 37 38&quot; &quot;scd apdu 00 f2 00 00 03 0a 0a 0a&quot; /bye<br />D&#91;0000&#93;  90 00                                              ..<br />OK<br />D&#91;0000&#93;  90 00                                              ..<br />OK<br /></div><br /><br />On YubiKey 4 I'm getting a different result:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">gpg-connect-agent --hex &quot;scd apdu 00 20 00 83 08 31 32 33 34 35 36 37 38&quot; &quot;scd apdu 00 f2 00 00 03 0a 0a 0a&quot; /bye<br />D&#91;0000&#93;  90 00                                              ..<br />OK<br />D&#91;0000&#93;  6D 00                                              m.<br />OK<br />$ gpg --card-status<br />Application ID ...: D2760001240102010006041398550000<br />Version ..........: 2.1<br />......<br />Key attributes ...: 2048R 2048R 2048R<br />Max. PIN lengths .: 127 127 127<br />PIN retry counter : 3 3 3<br />Signature counter : 0<br /></div><br /><br />Does it mean that the command to set retry counters on YubiKey 4 is not f2? What is it then?<br /><br />Help would be appreciated!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4029">mouse008</a> — Mon Jan 04, 2016 4:36 am</p><hr />
]]></content>
</entry>
</feed>