<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=35&amp;t=2193" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2017-09-26T13:30:57+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=35&amp;t=2193</id>
<entry>
<author><name><![CDATA[techwg]]></name></author>
<updated>2017-09-26T13:30:57+01:00</updated>
<published>2017-09-26T13:30:57+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2193&amp;p=9777#p9777</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2193&amp;p=9777#p9777"/>
<title type="html"><![CDATA[Re: [RESOLVED] Locked Admin PIN]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2193&amp;p=9777#p9777"><![CDATA[
Is all of that still required to reset? Isn't there a factory reset or something in openPGP or something that the PIV manager tool can reset?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4910">techwg</a> — Tue Sep 26, 2017 1:30 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[axel]]></name></author>
<updated>2016-05-14T23:20:34+01:00</updated>
<published>2016-05-14T23:20:34+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2193&amp;p=8629#p8629</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2193&amp;p=8629#p8629"/>
<title type="html"><![CDATA[Re: [RESOLVED] Locked Admin PIN]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2193&amp;p=8629#p8629"><![CDATA[
Now I get it, I'm an idiot! Thanks!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4324">axel</a> — Sat May 14, 2016 11:20 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[ChrisHalos]]></name></author>
<updated>2016-05-13T20:16:07+01:00</updated>
<published>2016-05-13T20:16:07+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2193&amp;p=8626#p8626</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2193&amp;p=8626#p8626"/>
<title type="html"><![CDATA[Re: [RESOLVED] Locked Admin PIN]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2193&amp;p=8626#p8626"><![CDATA[
Hello Axel - <br /><br />I'm confused, your key IS reset. With a YubiKey 4 you should see <strong>3  0  3</strong> for the <em>PIN retry counter</em>.<br /><br />1st number - PIN retries remaining<br />2nd number - Reset Code retries remaining (there is no reset code by default, you have to set one if you want one, so you should see <strong>0</strong> here)<br />3rd number - Admin PIN retries remaining<br /><br />Also, you will see <strong>2048R   2048R   2048R</strong> for the <em>Key attributes</em> on a new key, because that's the default. When you load 4096 subkeys there you will see <strong>4096R   4096R   4096R</strong> instead.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3140">ChrisHalos</a> — Fri May 13, 2016 8:16 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[axel]]></name></author>
<updated>2016-05-13T16:35:17+01:00</updated>
<published>2016-05-13T16:35:17+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2193&amp;p=8625#p8625</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2193&amp;p=8625#p8625"/>
<title type="html"><![CDATA[Re: [RESOLVED] Locked Admin PIN]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2193&amp;p=8625#p8625"><![CDATA[
Hello!<br /><br />I have a similar problem, but this solution does not work. I managed to exhaust admin pin retries during botched key migration. Then I ran the gpg-agent script, and it did not reset the admin pin counter as seen.<br /><br />Also the max key lengths were reset to 2048 and as this is yubikey 4 it should support 4096 (and i believe it did when I started the procedure).<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4324">axel</a> — Fri May 13, 2016 4:35 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[enculturation]]></name></author>
<updated>2016-02-02T21:08:39+01:00</updated>
<published>2016-02-02T21:08:39+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2193&amp;p=8246#p8246</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2193&amp;p=8246#p8246"/>
<title type="html"><![CDATA[Re: [RESOLVED] Locked Admin PIN]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2193&amp;p=8246#p8246"><![CDATA[
I appreciate it. I ran into an error message even after running the script. However, it was fixed by rebooting restarting the daemons.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4173">enculturation</a> — Tue Feb 02, 2016 9:08 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[ChrisHalos]]></name></author>
<updated>2016-02-02T20:07:33+01:00</updated>
<published>2016-02-02T20:07:33+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2193&amp;p=8245#p8245</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2193&amp;p=8245#p8245"/>
<title type="html"><![CDATA[Re: Locked Admin PIN]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2193&amp;p=8245#p8245"><![CDATA[
Assuming you're referring to OpenPGP, the NEO instructions work for the YubiKey 4 as well:<br /><br /><!-- m --><a class="postlink" href="https://developers.yubico.com/ykneo-openpgp/ResetApplet.html">https://developers.yubico.com/ykneo-ope ... pplet.html</a><!-- m --><br /><br />You can skip the Prerequisites section when you're using the YubiKey 4. If you receive any errors running the commands manually, try the script option listed at the bottom of the instructions. You can start by checking what is locked (you may need to terminate the gpg-agent and scdaemon processes first):<br /><br />gpg2 --card-status<br />Application ID ...: D2760001240102010006042126520000<br />Version ..........: 2.1<br />Manufacturer .....: Yubico<br />Serial number ....: 04212652<br />Name of cardholder: [not set]<br />Language prefs ...: [not set]<br />Sex ..............: unspecified<br />URL of public key : [not set]<br />Login data .......: [not set]<br />Signature PIN ....: not forced<br />Key attributes ...: 2048R 2048R 2048R<br />Max. PIN lengths .: 127 127 127<br />PIN retry counter : 3 0 3<br />Signature counter : 0<br />Signature key ....: [none]<br />Encryption key....: [none]<br />Authentication key: [none]<br />General key info..: [none]<br /><br />When you check the &quot;PIN retry counter&quot;, the first number is the remaining PIN entries, the second number is irrelevant, and the third number is the remaining Admin PIN entries. In my case, I haven't locked out the PIN or the Admin PIN (both counters are still showing &quot;3&quot;), so I need to lock both out before I can reset the applet&#058;<br /><br />gpg-connect-agent --hex<br />&gt; scd apdu 00 20 00 81 08 40 40 40 40 40 40 40 40<br />D[0000]  69 82                                              i.<br />OK<br />&gt; scd apdu 00 20 00 81 08 40 40 40 40 40 40 40 40<br />D[0000]  69 82                                              i.<br />OK<br />&gt; scd apdu 00 20 00 81 08 40 40 40 40 40 40 40 40<br />D[0000]  69 82                                              i.<br />OK<br />&gt; scd apdu 00 20 00 81 08 40 40 40 40 40 40 40 40<br />D[0000]  69 83                                              i.<br />OK<br />&gt; scd apdu 00 20 00 83 08 40 40 40 40 40 40 40 40<br />D[0000]  69 82                                              i.<br />OK<br />&gt; scd apdu 00 20 00 83 08 40 40 40 40 40 40 40 40<br />D[0000]  69 82                                              i.<br />OK<br />&gt; scd apdu 00 20 00 83 08 40 40 40 40 40 40 40 40<br />D[0000]  69 82                                              i.<br />OK<br />&gt; scd apdu 00 20 00 83 08 40 40 40 40 40 40 40 40<br />D[0000]  69 83                                              i.<br />OK<br />&gt; scd apdu 00 e6 00 00<br />D[0000]  90 00                                              ..<br />OK<br />&gt; scd apdu 00 44 00 00<br />D[0000]  90 00                                              ..<br />OK<br />&gt;<br /><br />At this point, you should be able to remove and re-insert the YubiKey 4, terminate the gpg-agent and scdaemon processes, and run &quot;gpg2 --card-status&quot; again to confirm the PIN retry counter is now at &quot;3  0  3&quot; again as expected. To better understand what the reset commands are:<br /><br />scd apdu 00 20 00 81 08 40 40 40 40 40 40 40 40 (Guess the PIN wrong one time - use this until the response is &quot;D[0000]  69 83&quot;)<br />scd apdu 00 20 00 83 08 40 40 40 40 40 40 40 40 (Guess the Admin PIN wrong one time - use this until the response is &quot;D[0000]  69 83&quot;)<br />scd apdu 00 e6 00 00 (terminate the card, correct response is &quot;D[0000]  90 00&quot;)<br />scd apdu 00 44 00 00 (reactivate the card, correct response is &quot;D[0000]  90 00&quot;)<br /><br />Again, if you receive any errors, try following the script option located at the bottom of <!-- m --><a class="postlink" href="https://developers.yubico.com/ykneo-openpgp/ResetApplet.html">https://developers.yubico.com/ykneo-ope ... pplet.html</a><!-- m --><br /><br />Example: On Windows 10, I create a text document (.txt) in my Documents folder called &quot;ResetApplet.txt&quot; (C:\Users\Chris\Documents\ResetApplet.txt), and paste the contents for the script (you will have to remove any leading spaces if you copy directly from the instructions):<br /><br />/hex<br />scd serialno<br />scd apdu 00 20 00 81 08 40 40 40 40 40 40 40 40<br />scd apdu 00 20 00 81 08 40 40 40 40 40 40 40 40<br />scd apdu 00 20 00 81 08 40 40 40 40 40 40 40 40<br />scd apdu 00 20 00 81 08 40 40 40 40 40 40 40 40<br />scd apdu 00 20 00 83 08 40 40 40 40 40 40 40 40<br />scd apdu 00 20 00 83 08 40 40 40 40 40 40 40 40<br />scd apdu 00 20 00 83 08 40 40 40 40 40 40 40 40<br />scd apdu 00 20 00 83 08 40 40 40 40 40 40 40 40<br />scd apdu 00 e6 00 00<br />scd apdu 00 44 00 00<br />/echo Card has been successfully reset.<br /><br />I then open Command Prompt, change directory to my Documents folder (&quot;cd C:\Users\Chris\Documents&quot;) and run the command:<br /><br />C:\Users\Chris\Documents&gt;gpg-connect-agent -r ResetApplet.txt<br />S SERIALNO D2760001240102010006042126520000 0<br />OK<br />D[0000]  69 82                                              i.<br />OK<br />D[0000]  69 82                                              i.<br />OK<br />D[0000]  69 82                                              i.<br />OK<br />D[0000]  69 83                                              i.<br />OK<br />D[0000]  69 82                                              i.<br />OK<br />D[0000]  69 82                                              i.<br />OK<br />D[0000]  69 82                                              i.<br />OK<br />D[0000]  69 83                                              i.<br />OK<br />D[0000]  90 00                                              ..<br />OK<br />D[0000]  90 00                                              ..<br />OK<br />Card has been successfully reset.<br />&gt;<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3140">ChrisHalos</a> — Tue Feb 02, 2016 8:07 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[enculturation]]></name></author>
<updated>2016-02-02T21:06:37+01:00</updated>
<published>2016-02-02T17:00:19+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2193&amp;p=8244#p8244</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2193&amp;p=8244#p8244"/>
<title type="html"><![CDATA[[RESOLVED] Locked Admin PIN]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2193&amp;p=8244#p8244"><![CDATA[
I hate to admit this on a public forum, but I have managed to lock my admin pin. I can’t change or reset, when I do I get a card error. All of the information I’ve found online is written for the NEO. <br /><br />Can someone help, or is this key a goner? Thanks!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4173">enculturation</a> — Tue Feb 02, 2016 5:00 pm</p><hr />
]]></content>
</entry>
</feed>