<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=23&amp;t=2828" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2018-01-23T22:02:43+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=23&amp;t=2828</id>
<entry>
<author><name><![CDATA[RadiatorMints]]></name></author>
<updated>2018-01-23T22:02:43+01:00</updated>
<published>2018-01-23T22:02:43+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10131#p10131</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10131#p10131"/>
<title type="html"><![CDATA[Re: YubiKey 4 for PIV stopped working]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10131#p10131"><![CDATA[
<div class="quotetitle">JamesA wrote:</div><div class="quotecontent"><br />For enroll on behalf of (EOBO) you also need to set the publish and enroll in the &quot;Enrollment Agent&quot; template as covered in the Smart Card Deployment Guide. <br /><br />Regarding your issue with self-enrollment, please open a support ticket for further troubleshooting. <!-- m --><a class="postlink" href="https://www.yubico.com/support/get-support/">https://www.yubico.com/support/get-support/</a><!-- m --><br /></div><br /><br />The Enrollment Agent template was also published.  I was able to pull the cert and get almost all the way through enrollment before it failed due to policy.<br /><br />Today I extinguished all doubt by troubleshooting the entire PKI stack with this guide:<br /><!-- m --><a class="postlink" href="https://blogs.technet.microsoft.com/askds/2007/11/06/how-to-troubleshoot-certificate-enrollment-in-the-mmc-certificate-snap-in/">https://blogs.technet.microsoft.com/ask ... e-snap-in/</a><!-- m --><br /><br />I ran RSOP.msc to see if there were any conflicts with GPOs but everything was configured the way I expected.<br />I was still getting the 'blocked by computer policy' error so I disabled all of my computer GPOs and self enrollment worked.  By turning things back on one at a time I determined that my Yubikey GPO was to blame.  I believe it's one or both of my registry edits: <br /><br />BlockPUKOnMGMUpgrade<br />or<br />NewKeyTouchPolicy<br /><br />What I'm working backwards to understand is how the YubiKeys were getting the certificate installed in 9a -only with the PIV Manager- but weren't able to authenticate.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=5062">RadiatorMints</a> — Tue Jan 23, 2018 10:02 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[JamesA]]></name></author>
<updated>2018-01-23T21:47:21+01:00</updated>
<published>2018-01-23T21:47:21+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10130#p10130</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10130#p10130"/>
<title type="html"><![CDATA[Re: YubiKey 4 for PIV stopped working]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10130#p10130"><![CDATA[
For enroll on behalf of (EOBO) you also need to set the publish and enroll in the &quot;Enrollment Agent&quot; template as covered in the Smart Card Deployment Guide. <br /><br />Regarding your issue with self-enrollment, please open a support ticket for further troubleshooting. <!-- m --><a class="postlink" href="https://www.yubico.com/support/get-support/">https://www.yubico.com/support/get-support/</a><!-- m --><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4981">JamesA</a> — Tue Jan 23, 2018 9:47 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[RadiatorMints]]></name></author>
<updated>2018-01-22T20:20:54+01:00</updated>
<published>2018-01-22T20:20:54+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10127#p10127</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10127#p10127"/>
<title type="html"><![CDATA[Re: YubiKey 4 for PIV stopped working]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10127#p10127"><![CDATA[
Found rev B which has auto-enrollment stuff in it.<br /><!-- m --><a class="postlink" href="https://www.yubico.com/wp-content/uploads/2017/10/YubiKey_Smart_Card_Deployment_Guide_10_2017_RevB.pdf">https://www.yubico.com/wp-content/uploa ... 7_RevB.pdf</a><!-- m --><br />Actions taken today (1/22/2018):<br />Revoked all previous user certs except the one that works.<br />Reissued the root domain cert and verified through cert chains that it is being used.<br />Pushed all the auto-enrollment config via GPO and found it in the system tray.  (Fails with a message about &quot;Prohibited by Computer Policy&quot; weather it's launched from the tray or certmgr)<br />Added a brand new PC to the domain and logged in via the one working YubiKey 4 on the first boot with no configuration other than previously configured GPOs.<br /><br />EDIT: per the documentation under the Cryptography tab: <br />Provider Category is now Key Storage Provider<br />Algo is RSA, length is default: 2048<br />Provider is Microsoft Smart Card Key Storage Provider<br /><br />What am I missing?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=5062">RadiatorMints</a> — Mon Jan 22, 2018 8:20 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[RadiatorMints]]></name></author>
<updated>2018-01-22T20:55:53+01:00</updated>
<published>2018-01-19T16:51:41+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10123#p10123</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10123#p10123"/>
<title type="html"><![CDATA[YubiKey 4 for PIV stopped working]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2828&amp;p=10123#p10123"><![CDATA[
Earlier this month I purchased one YubiKey 4 for a proof of concept for OTP login using a 3rd party solution. In the interest of compatibility and simplicity we chose to back down to PIV. I followed the deployment instructions and in a matter of nearly no time my YubiKey 4 was doing PIV smartcard login on domain computers.<br /><br />So I purchased the rest of the YubiKeys I needed for my users, implemented the Enroll on behalf of CA Template and that's when everything went completely sideways. Enroll on behalf of didn't seem to work at all, the template couldn't find the signature &gt; no certificate on the YubiKey &gt; cert enrollment failure on the CA. So I'm back to user self enrollment and I can get a certificate on a YubiKey. The PIV manager recognizes it, it's published in the Certificate Authority but any time I try to use it for login the endpoint says that &quot;No valid certificates were found on this smart card.&quot;<br /><br />My original YubiKey and cert still works flawlessly. Changing out YubiKeys yields the same results (failure). I changed the name of the original template and recreated a new one from scratch with the following settings:<br /><br /><strong>General</strong><br />Validity period is 2 years<br />Cert is published in AD<br /><strong>Compatibility</strong><br />CA is Server 2016<br />Recipient is Windows 7<br /><strong>Request handling</strong><br />Signature and encryption<br />Include symmetric algorithms allowed by the subject<br />Prompt user during enrollment<br /><strong>Cryptography</strong><br />Note: italicized text refers to a configuration that has since been changed<br />Key Storage Provider<br />RSA<br />Key Size 2048<br />Requests must use Microsoft Smart Card Key Storage Provider<br /><br /><em>Legacy Cryptographic Service Provider<br />Algo determined by CSP<br />Requests must use Microsoft Enhanced Cryptographic Provider v1.0</em><br /><br /><strong>Security</strong><br />Authenticated users may read and enroll<br />Admins can read, write, and enroll<br /><br />I'm happy to answer any questions (within the realm of reason).<br /><br />Update: I replicated those template settings with a new, longer, unique name, made sure it was published to the CA and waited the 20 minutes.  It still isn't working.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=5062">RadiatorMints</a> — Fri Jan 19, 2018 4:51 pm</p><hr />
]]></content>
</entry>
</feed>