<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=1832" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2015-04-18T01:57:26+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=1832</id>
<entry>
<author><name><![CDATA[rbondi]]></name></author>
<updated>2015-04-16T21:53:51+01:00</updated>
<published>2015-04-16T21:53:51+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1832&amp;p=7193#p7193</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1832&amp;p=7193#p7193"/>
<title type="html"><![CDATA[Re: [QUESTION]: Fix for &quot;Key does not match the card's capab]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1832&amp;p=7193#p7193"><![CDATA[
I figured it out: the Neo cannot accept keys longer than 2048 bits.<br /><br />When I generate a keypair outside the Neo, on a desktop GnuPG, if it is 2048 bits, 'keytocard' works just fine. If the key length is greater than that, I get the above error message.<br /><br />So the error message is accurate if albeit vague: the key indeed does not match the card's capability, when it is greater than 2048 bits. <br /><br />Googling uncovered this thoughtful explanation by Yubico of this limitation: <!-- m --><a class="postlink" href="https://www.yubico.com/2015/02/big-debate-2048-4096-yubicos-stand/">https://www.yubico.com/2015/02/big-deba ... cos-stand/</a><!-- m --><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3659">rbondi</a> — Thu Apr 16, 2015 9:53 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[rbondi]]></name></author>
<updated>2015-04-18T01:57:26+01:00</updated>
<published>2015-04-16T19:14:15+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1832&amp;p=7191#p7191</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1832&amp;p=7191#p7191"/>
<title type="html"><![CDATA[[SOLVED]: Fix for &quot;Key does not match the card's capabilit]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1832&amp;p=7191#p7191"><![CDATA[
Does anyone know how to get past this `keytocard` error please?<br /><br />Sequence of commands to get the error:<br /><br />```<br />$&gt;gpg --edit-key [my key id]<br />/snip/<br />Secret key is available. <br />/snip/<br />gpg&gt;toggle<br />/snip/<br />gpg&gt;key 1<br />/snip/<br />gpg&gt;keytocard<br />/snip/<br />Please select where to store the key:<br />(2) Encryption key<br />Your selection? 2<br />Key does not match the card's capability.<br />```<br /><br /># What I'm using:<br /><br />gpg (GnuPG/MacGPG2) 2.0.27<br />libgcrypt 1.6.3<br /><br />OSX 10.10.3 (14D131)<br /><br />ykpersonalize -V<br />Firmware version 3.4.0 Touch level 1797 Program sequence 2<br />Unsupported firmware revision - some features may not be available<br />Please see <!-- m --><a class="postlink" href="https://developers.yubico.com/..">https://developers.yubico.com/..</a><!-- m -->. for more information.<br />1.16.0<br />Yubikey core error: unsupported firmware version<br /><br />OSX Yubikey Personalization Tool says it's firmware 3.4.0, Slot 1 configured, no errors. (If there was a way to do all this in the OSX YPT, I'd do it there, but AFAIK there is not; I can't even set -m28 with it. Grrr.)<br /><br />Thanks much in advance, /rb<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3659">rbondi</a> — Thu Apr 16, 2015 7:14 pm</p><hr />
]]></content>
</entry>
</feed>