<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=2609" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2017-10-19T10:18:08+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=2609</id>
<entry>
<author><name><![CDATA[bozho]]></name></author>
<updated>2017-10-19T10:18:08+01:00</updated>
<published>2017-10-19T10:18:08+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9891#p9891</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9891#p9891"/>
<title type="html"><![CDATA[Re: [QUESTION] PIN caching for SSL certificates]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9891#p9891"><![CDATA[
Ah, this seems to be the cause: <a href="https://forum.yubico.com/viewtopic.php?f=26&amp;t=2739" class="postlink">https://forum.yubico.com/viewtopic.php?f=26&amp;t=2739</a><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3834">bozho</a> — Thu Oct 19, 2017 10:18 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[bozho]]></name></author>
<updated>2017-10-18T19:47:04+01:00</updated>
<published>2017-10-18T19:47:04+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9888#p9888</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9888#p9888"/>
<title type="html"><![CDATA[Re: [QUESTION] PIN caching for SSL certificates]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9888#p9888"><![CDATA[
Well, it may have been fixed, but I can't test it as it actually stopped working for me.<br /><br />I haven't tried remoting in a few weeks now and I was setting up a new machine. Today I went to test it and I can't get Windows to behave with my Yubikey.<br /><br />So, nothing has changed with the Yubikey - it still has the same self-signed cert in the authentication slot. At first, I thought it's the new machine, but I've just checked with the old machine where this used to work and I get the same result.<br /><br />In short, on the machine where it used to work, I performed these steps:<br />1. Delete the cert from Cert:\CurrentUser\My\ (it was there previously).<br />2. Plug in Yubikey - the certificate appears in the store.<br />3. Run the code from my original post - get the message along the lines &quot;The smart card cannot perform this action.. &quot;. I didn't get the entire message, because I can't repeat it (read on <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":)" title="Smile" /><br />4. Unplug Yubikey and delete the certificate again.<br />5. Plugin Yubikey - the certificate does not reappear in the certificate store. Rebooting doesn't help, cussing at it doesn't help.<br /><br /><br />I can't get it to work on the new machine, either (both machines run Win10 Pro with latest updates).<br /><br />If I import the certificate from the PFX file and not use Yubikey, everything works as expected.<br /><br />Is there something I need to do with Yubikey?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3834">bozho</a> — Wed Oct 18, 2017 7:47 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Chris77]]></name></author>
<updated>2017-10-18T09:08:29+01:00</updated>
<published>2017-10-18T09:08:29+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9886#p9886</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9886#p9886"/>
<title type="html"><![CDATA[Re: [QUESTION] PIN caching for SSL certificates]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9886#p9886"><![CDATA[
I can confirm that it has been fixed. Endlich!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4758">Chris77</a> — Wed Oct 18, 2017 9:08 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[DarkainMX]]></name></author>
<updated>2017-10-13T18:48:29+01:00</updated>
<published>2017-10-13T18:48:29+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9860#p9860</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9860#p9860"/>
<title type="html"><![CDATA[Re: [QUESTION] PIN caching for SSL certificates]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9860#p9860"><![CDATA[
ITS FIXED!!! It is finally freaggin fixed!<br /><br />Windows Update ran this week. Not sure which update specifically which update was applied. But when I went to open a PuTTY session today, I noticed that the pin key window was behaving normally (it popped up and took focus, rather than opening behind all other windows). So I gave it a try a second time, and PuTTY authenticated without asking for another prompt. <br /><br />That only took... what... 7 months to fix!? Thanks Microsoft <img src="https://forum.yubico.com/images/smilies/icon_razz.gif" alt=":P" title="Razz" /><br /><br /><br />UPDATE: It is KB4041676<br /><!-- m --><a class="postlink" href="https://support.microsoft.com/en-us/help/4041676/windows-10-update-kb4041676">https://support.microsoft.com/en-us/hel ... -kb4041676</a><!-- m --><br /><br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />Addressed issue where Personal Identity Verification (PIV) smart card PINs are not cached on a per-application basis. This caused users to see the PIN prompt multiple times in a short time period; normally, the PIN prompt only displays once.<br /></div><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4781">DarkainMX</a> — Fri Oct 13, 2017 6:48 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[bozho]]></name></author>
<updated>2017-06-23T11:26:34+01:00</updated>
<published>2017-06-23T11:26:34+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9631#p9631</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9631#p9631"/>
<title type="html"><![CDATA[Re: [QUESTION] PIN caching for SSL certificates]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9631#p9631"><![CDATA[
Tested on the Creators update with the latest updates, still no luck (although I would expect security updates not to be tied to these &quot;big&quot; Windows feature updates)<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3834">bozho</a> — Fri Jun 23, 2017 11:26 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Chris77]]></name></author>
<updated>2017-05-02T23:14:37+01:00</updated>
<published>2017-05-02T23:14:37+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9566#p9566</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9566#p9566"/>
<title type="html"><![CDATA[Re: [QUESTION] PIN caching for SSL certificates]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9566#p9566"><![CDATA[
I did some debugging on this issue but didn't find a solution.<br /><br />- The issue was introduced by Windows Update KB3013429 (Released March 2017) which is included in every later cumulative Update.<br />- Removing any Windows Update 10 and installing KB3213986 (Released Jan 2017) fixes the issue, but is a security disaster.<br />- New Profile doesn't help<br />- Disabling PIN completly is not possible!?<br /><br /><br />I tried to install and configure OpenSC but either I did something wrong or it doesn't help.<br /><br />I got an Yubico support response recommending to open a ticket with Microsoft. <br /><br /><br />Similar issue is mentioned on the web for others services including Citrix without solution:<br /><br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />Before installing KB4013429 a client would be asked for their password just once when signing the soap request and each subsequent request to sign the soap request would not come up with a password box to reenter their credentials.<br /></div><a href="https://answers.microsoft.com/en-us/windows/forum/windows_10-update/update-kb4013429-causing-another-problem-with-our/e3cb3a00-020e-45ec-a838-41f94a231557" class="postlink">https://answers.microsoft.com/en-us/windows/forum/windows_10-update/update-kb4013429-causing-another-problem-with-our/e3cb3a00-020e-45ec-a838-41f94a231557</a><br /><br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />The user enters the smart card PIN at the Receiver prompt but is returned back to the PIN prompt again without any failure message.<br /></div><a href="http://discussions.citrix.com/topic/385836-receiver-smart-card-login-direct-to-storefront-broken-on-windows-10-after-kb4013429-update" class="postlink">http://discussions.citrix.com/topic/385836-receiver-smart-card-login-direct-to-storefront-broken-on-windows-10-after-kb4013429-update</a><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4758">Chris77</a> — Tue May 02, 2017 11:14 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[DarkainMX]]></name></author>
<updated>2017-05-02T17:53:05+01:00</updated>
<published>2017-05-02T17:53:05+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9564#p9564</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9564#p9564"/>
<title type="html"><![CDATA[Re: [QUESTION] PIN caching for SSL certificates]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9564#p9564"><![CDATA[
PIN caching is still broken with creating a fresh user profile, too. This is effecting every developer that I know which uses Windows 10 currently. Win10 is requesting PIN on every single signing request, which for programming is a lot. For instance, running a git submodule update could pull 10+ packages all at once, every single one requesting PIN now.<br /><br />My current work around: coding on Windows 10, but doing all git operations through a Windows 7 virtual machine.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4781">DarkainMX</a> — Tue May 02, 2017 5:53 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Chris77]]></name></author>
<updated>2017-04-13T12:18:46+01:00</updated>
<published>2017-04-13T12:18:46+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9544#p9544</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9544#p9544"/>
<title type="html"><![CDATA[Re: [QUESTION] PIN caching for SSL certificates]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9544#p9544"><![CDATA[
The latest cumulative update for Windows 10 (April 2017 / KB4015217) doesn't fix PIN caching issue.<br /><br />So currently the only workaround is to not install March/April 2017 updates <img src="https://forum.yubico.com/images/smilies/icon_e_sad.gif" alt=":-(" title="Sad" /><br /><br /><br />On windowsreports.com they recommend to try a new and empty user profile. We're going to test that now.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4758">Chris77</a> — Thu Apr 13, 2017 12:18 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[bozho]]></name></author>
<updated>2017-04-05T15:42:47+01:00</updated>
<published>2017-04-05T15:42:47+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9531#p9531</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9531#p9531"/>
<title type="html"><![CDATA[Re: [QUESTION] PIN caching for SSL certificates]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9531#p9531"><![CDATA[
No, I didn't have time to chase this up with Microsoft... I'm holding off on applying Windows updates for now.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3834">bozho</a> — Wed Apr 05, 2017 3:42 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Chris77]]></name></author>
<updated>2017-04-03T17:09:43+01:00</updated>
<published>2017-04-03T17:09:43+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9529#p9529</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9529#p9529"/>
<title type="html"><![CDATA[Re: [QUESTION] PIN caching for SSL certificates]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9529#p9529"><![CDATA[
Any news on this issue?<br /><br />Uninstalling official Windows Updates can't be permanent solution for this issue ... <br /><br />Chris<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4758">Chris77</a> — Mon Apr 03, 2017 5:09 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[bozho]]></name></author>
<updated>2017-03-23T23:14:57+01:00</updated>
<published>2017-03-23T23:14:57+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9496#p9496</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9496#p9496"/>
<title type="html"><![CDATA[Re: [QUESTION] PIN caching for SSL certificates]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9496#p9496"><![CDATA[
Hi Matthew,<br /><br />It would appear that it's not KB4013418, but one of these two: KB3150513, KB4015438.<br /><br />I managed to revert to an earlier restore point on one system and uninstall these two updates on another and certificate PIN caching now works fine.<br /><br />Marko<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3834">bozho</a> — Thu Mar 23, 2017 11:14 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[mattlegitt]]></name></author>
<updated>2017-03-23T19:08:38+01:00</updated>
<published>2017-03-23T19:08:38+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9495#p9495</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9495#p9495"/>
<title type="html"><![CDATA[Re: [QUESTION] PIN caching for SSL certificates]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9495#p9495"><![CDATA[
Hello Bozho,<br /><br />Yes the latest Windows 10 Update KB4013418 is causing quite a few issues. you can read more at link below.<br /><!-- m --><a class="postlink" href="http://windowsreport.com/fix-windows-10-kb4013418-bugs/">http://windowsreport.com/fix-windows-10-kb4013418-bugs/</a><!-- m --><br /><br />Best Regards,<br />Matthew<br />Yubico Support<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4123">mattlegitt</a> — Thu Mar 23, 2017 7:08 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[bozho]]></name></author>
<updated>2017-03-23T11:35:22+01:00</updated>
<published>2017-03-23T11:35:22+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9493#p9493</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9493#p9493"/>
<title type="html"><![CDATA[Re: [QUESTION] PIN caching for SSL certificates]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9493#p9493"><![CDATA[
Just a quick follow up: I've tried the same scenario on a Win 8.1 machine and PIN caching works as expected. It looks like Windows 10 broke something in the last update.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3834">bozho</a> — Thu Mar 23, 2017 11:35 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[bozho]]></name></author>
<updated>2017-03-22T19:17:55+01:00</updated>
<published>2017-03-22T19:17:55+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9491#p9491</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9491#p9491"/>
<title type="html"><![CDATA[[QUESTION] PIN caching for SSL certificates]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2609&amp;p=9491#p9491"><![CDATA[
Hi all,<br /><br />I'm using Yubikey NEO to store a custom personal SSL certificate in slot 9a. I use the certificate to authenticate against remote Windows machines for remote execution in PowerShell.<br /><br />I have a PS workflow I'm working on and the usual behaviour is when I start the workflow, I get a popup dialogue asking me for the PIN and then the workflow carries on. The workflow does connect several times to the remote machine, but I used to get the PIN dialogue only once.<br /><br />However, today I started getting the popup several times while the workflow is running. I tried reverting to yesterday's code, even though there were no changes that should affect this behaviour, with no luck.<br /><br />I'm running Windows 10 Pro with the latest updates. I've tried rebooting the machine and using a different USB port. <br /><br /><br />EDIT: Minimal example to replicate the problem is to open a Powershell CIM session to a remote computer:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">$option = New-CimSessionOption -SkipCACheck -SkipCNCheck -SkipRevocationCheck -UseSsl<br />$cert = gi Cert:\CurrentUser\My\XXXXXXXXXXXXXXXXXXXXXXXX<br />$s = New-CimSession -ComputerName machine.example.com -CertificateThumbprint $cert.Thumbprint -SessionOption $option<br /></div><br />Running the last line for the first time pops up the PIN dialogue. Running the line again in the same Powershell window was not prompting for the PIN again. However, today I get the PIN dialogue every time - tested on two different Win10 Pro machines.<br /><br />How could I determine what is causing the change in behaviour?<br /><br />On a possibly unrelated note, PIN caching for my PGP keys works as expected.<br /><br />Thank you,<br />Marko<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3834">bozho</a> — Wed Mar 22, 2017 7:17 pm</p><hr />
]]></content>
</entry>
</feed>