<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=2749" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2017-10-12T11:25:06+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=2749</id>
<entry>
<author><name><![CDATA[dain]]></name></author>
<updated>2017-10-12T11:25:06+01:00</updated>
<published>2017-10-12T11:25:06+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2749&amp;p=9853#p9853</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2749&amp;p=9853#p9853"/>
<title type="html"><![CDATA[Re: Invalid public key in attestation certificate]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2749&amp;p=9853#p9853"><![CDATA[
The certificate you posted it seems to be corrupted. I've tracked down the real certificate with that serial number, and it looks like a few bits are wrong in both the public key and the signature.<br /><br />Can you test the device against our demo server at demo.yubico.com/u2f ?<br />If that doesn't give you an error, then the certificate corruption must be happening on your end. If it does give you an error, please copy and paste it here.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=504">dain</a> — Thu Oct 12, 2017 11:25 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[fremen1983]]></name></author>
<updated>2017-10-11T10:22:22+01:00</updated>
<published>2017-10-11T10:22:22+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2749&amp;p=9851#p9851</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2749&amp;p=9851#p9851"/>
<title type="html"><![CDATA[Invalid public key in attestation certificate]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2749&amp;p=9851#p9851"><![CDATA[
As a relying party, we need to verify registration data when enrolling yubico token into our system.<br />Verification should be done using the public key certified in the attestation certificate. Unfortunately, that public key seems to be invalid.<br /><br />This is the public key (decompressed value of EC point at P-256 curve) from the certificate:<br />042fe1a23effa55bff461d59a43522d79748981cba6d289a98f1bd7dff656680dbbbfdbc2bae607e6ef772f576b04d54c4e5f32f596f26e61115c7272cf6ca7594<br /><br />Whole attestation certificate which is returned in registration response message follows:<br /><br />-----BEGIN CERTIFICATE-----<br />MIICTzCCATegAwIBAgIEKtlq8zANBgkqhkiG9w0BAQsFADAuMSwwKgYDVQQDEyNZ<br />dWJpY28gVTJGIFJvb3QgQ0EgU2VyaWFsIDQ1NzIwMDYzMTAgFw0xNDA4MDEwMDAw<br />MDBaGA8yMDUwMDkwNDAwMDAwMFowMTEvMC0GA1UEAwwmWXViaWNvIFUyRiBFRSBT<br />ZXJpYWwgMjM5MjU3MzQ1MTY1NTAzODcwWTATBgcqhkjOPQIBBggqhkjOPQMBBwNC<br />AAQv4aI+/6Vb/0YdWaQ1IteXSJgcum0ompjxvX3/ZWaA27v9vCuuYH5u93L1drBN<br />VMTl8y9ZbybmERXHJyz2ynWUozswOTAiBgkrBgEEAYLECgIEFTEuMy42LjEuNC4x<br />LjQxNDgyLjEuMjATBgsrBgEEAYLlHAIBAQQEAwIEMDANBgkqhkiG9w0BAQsFAAOC<br />AQEAhWr6i89P/2JfKRvBFY48/70lUrz3VwdT9RIdpqVNJMzP7ifO1qsxEowp/1tb<br />iQXdoCAXkx8fX1klk1lR/ABLy+IK3X2NBS+VQ7NJbBW4MQ4Qy9m7BTgnT1g+rR9F<br />EojD6nbQcK1E5Tr+qPItH3NiX/LVif4w3yZiy3y7fJlhgK3P6YpNASzzE0bNEXRq<br />WEjo/+3z4wzL2cHdIhZxsoOIYfZaRTYjtRjVVn+o8KPOEF308TlT4RTqWeCn8v5m<br />iGdDLlL9ai9k9zxIzZs48t+6LHpLOxEo3ybWaiT4ld2gthGA9BRPa3B1wxikmuCL<br />WNNq2x4wU2crF8Whn38KIvEOlA==<br />-----END CERTIFICATE-----<br /><br />Also, we do not understand, why subject of the certificate is:<br />CN = Yubico U2F EE Serial 23925734516550387<br />while serial number is 718891763 (‎2a d9 6a f3 in hex). But this is not as serious as issue mentioned above.<br /><br />Has anyone experienced similar problems?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4928">fremen1983</a> — Wed Oct 11, 2017 10:22 am</p><hr />
]]></content>
</entry>
</feed>