<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=35&amp;t=2650" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2017-06-17T02:32:32+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=35&amp;t=2650</id>
<entry>
<author><name><![CDATA[laurent]]></name></author>
<updated>2017-06-17T02:32:32+01:00</updated>
<published>2017-06-17T02:32:32+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2650&amp;p=9624#p9624</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2650&amp;p=9624#p9624"/>
<title type="html"><![CDATA[Re: YubiKey4 and signtool]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2650&amp;p=9624#p9624"><![CDATA[
<div class="quotetitle">ChrisHalos wrote:</div><div class="quotecontent"><br />This is unavoidable with signtool and smart cards, as far as I'm aware. I haven't had any feedback on this yet, but you may want to look at this tool - <!-- m --><a class="postlink" href="https://www.mgtek.com/smartcard">https://www.mgtek.com/smartcard</a><!-- m --> (arguably less secure as the current method as it's storing the PIN somewhere in plaintext, but it would certainly be more convenient, and would still be requiring smart card presence).<br /></div><br /><br />I don't mind be asked for the PIN. My issue is about signtool not generating a valid signature, and it seems to be related to the fact that even if I import the whole certificate chain into the yubikey, only the most specific one is stored/used?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4819">laurent</a> — Sat Jun 17, 2017 2:32 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[ChrisHalos]]></name></author>
<updated>2017-06-16T21:09:37+01:00</updated>
<published>2017-06-16T21:09:37+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2650&amp;p=9623#p9623</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2650&amp;p=9623#p9623"/>
<title type="html"><![CDATA[Re: YubiKey4 and signtool]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2650&amp;p=9623#p9623"><![CDATA[
This is unavoidable with signtool and smart cards, as far as I'm aware. I haven't had any feedback on this yet, but you may want to look at this tool - <!-- m --><a class="postlink" href="https://www.mgtek.com/smartcard">https://www.mgtek.com/smartcard</a><!-- m --> (arguably less secure as the current method as it's storing the PIN somewhere in plaintext, but it would certainly be more convenient, and would still be requiring smart card presence).<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3140">ChrisHalos</a> — Fri Jun 16, 2017 9:09 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[laurent]]></name></author>
<updated>2017-06-16T02:37:12+01:00</updated>
<published>2017-06-16T02:37:12+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2650&amp;p=9620#p9620</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2650&amp;p=9620#p9620"/>
<title type="html"><![CDATA[Re: YubiKey4 and signtool]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2650&amp;p=9620#p9620"><![CDATA[
The certificate was provided by the Certificate authority based on the CSR I provided. The pin code was asked during signing and signtool shows that my private key is picked up.<br /><br />I tried jsign (<!-- m --><a class="postlink" href="https://github.com/ebourg/jsign">https://github.com/ebourg/jsign</a><!-- m -->) and had the exact same result when only using the yubikey. If I provide the full cert chain to the software, then the signature added to the file is valid.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4819">laurent</a> — Fri Jun 16, 2017 2:37 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[mattlegitt]]></name></author>
<updated>2017-06-15T05:09:59+01:00</updated>
<published>2017-06-15T05:09:59+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2650&amp;p=9615#p9615</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2650&amp;p=9615#p9615"/>
<title type="html"><![CDATA[Re: YubiKey4 and signtool]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2650&amp;p=9615#p9615"><![CDATA[
Hello laurent,<br /><br />When using the signtool were you prompted for the PIN to unlock the smart card for signing or did it finish the signing operation without a PIN prompt? if you were not prompted for a PIN unlock the most likely cause is windows is not detecting the certificate as valid for code signing, where / how did you generate the certificate for code signing?<br /><br />Best Regards,<br />Matthew<br />Yubico Support<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4123">mattlegitt</a> — Thu Jun 15, 2017 5:09 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[laurent]]></name></author>
<updated>2017-06-14T19:02:48+01:00</updated>
<published>2017-06-14T19:02:48+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2650&amp;p=9614#p9614</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2650&amp;p=9614#p9614"/>
<title type="html"><![CDATA[YubiKey4 and signtool]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2650&amp;p=9614#p9614"><![CDATA[
Hi,<br /><br />I'm trying to use YubiKey4 to sign Windows Executable with the Windows 10 Kit signtool utility.<br /><br />I followed instructions at <!-- m --><a class="postlink" href="https://www.yubico.com/support/knowledge-base/categories/articles/sign-code-yubikey-neo/">https://www.yubico.com/support/knowledg ... bikey-neo/</a><!-- m --> to load the certificate and private key into the yubikey, and signtool successfully signs the file, but when checking the digital signature, Windows shows that the certificate is missing a digital signature (Message is &quot;No Signature present in the subject&quot;).<br /><br />Did anybody successfully manage to sign an executable on Windows? It seems that the yubikey doesn't save the whole certificate chain, and I wonder if this is the reason why the signature is missing.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4819">laurent</a> — Wed Jun 14, 2017 7:02 pm</p><hr />
]]></content>
</entry>
</feed>