<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=35&amp;t=2537" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2017-02-08T16:16:06+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=35&amp;t=2537</id>
<entry>
<author><name><![CDATA[Mathieulh]]></name></author>
<updated>2017-02-08T16:16:06+01:00</updated>
<published>2017-02-08T16:16:06+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2537&amp;p=9366#p9366</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2537&amp;p=9366#p9366"/>
<title type="html"><![CDATA[Re: [QUESTION] Windows AD CS with root CA key on YK4]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2537&amp;p=9366#p9366"><![CDATA[
<div class="quotetitle">Marecki wrote:</div><div class="quotecontent"><br />I wonder, has anyone here ever tried to use a YubiKey 4 in PIV mode to store the root CA key for Windows Active Directory Certificate Services, and if so could I find the procedure documented somewhere? the &quot;Configuring a CA for Smart Card Authentication&quot; section of YubiKey PIV Deployment Guide says nothing about what cryptographic provider to use, all the documentation I have seen so far seems to assume only keys other than the root CA to be generated in YubiKeys, and when I simply tried to choose either the standard Windows SmartCard Store cryptographic provider or the OpenSC CSP Windows informed me the card was read-only.<br /><br />Thank you in advance for any suggestions!<br /></div><br /><br />-----BEGIN PGP SIGNED MESSAGE-----<br />Hash: SHA512<br /><br /><br />Why not import the pem/pfx to the Yubikey using piv-tool or the Yubikey PIV Manager?<br />For some reason the yubikey PIV applet reports as read only, and neither the Microsoft or opensc stacks can write to PIV slots, so certificates have to be imported/generated using Yubikey's own set of tools.<br /><br />It would be good to know why Yubikey won't let applications overwrite its PIV slots when other competitors (such as PIVkey) would, using non standard APIs can be rather cumbersome.<br />-----BEGIN PGP SIGNATURE-----<br /><br />iQEcBAEBCgAGBQJYmzYmAAoJEKa4nBz3AlIIYb8IAJqFIt6NENmOLfg3rkd3zNQZ<br />/NUJDVq0/ChiRXwpt//jkb4F0AVL2nQJFEOu5JFVRXyRE/W7u6SHcmw797fT3/OK<br />zDsuO68fioUKgpoQiL0op2OyeG/5TxcWDpAQYoEFSFOR2NxUMF3aUyIE53BbDcRK<br />oljhmSBl5gEqtdvEwGQYMfDwkXe2e7+q2pFkAjDJqm97kRW5cWQAbaKVCE950N1K<br />BcyHxdzsb8dzNBAujUkc/dTccC+x+gEPe2Ku/iGBoFRB8v2k6ARc1XEAy20HPpNJ<br />Fj8hHbGshAwNUZ1moyKet85JW+nU5TNhxIK+D4aQdFqoAdCyAvpJwiWxI/n1K24=<br />=84bS<br />-----END PGP SIGNATURE-----<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3608">Mathieulh</a> — Wed Feb 08, 2017 4:16 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Marecki]]></name></author>
<updated>2017-01-23T16:23:54+01:00</updated>
<published>2017-01-23T16:23:54+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2537&amp;p=9304#p9304</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2537&amp;p=9304#p9304"/>
<title type="html"><![CDATA[[QUESTION] Windows AD CS with root CA key on YK4]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2537&amp;p=9304#p9304"><![CDATA[
I wonder, has anyone here ever tried to use a YubiKey 4 in PIV mode to store the root CA key for Windows Active Directory Certificate Services, and if so could I find the procedure documented somewhere? the &quot;Configuring a CA for Smart Card Authentication&quot; section of YubiKey PIV Deployment Guide says nothing about what cryptographic provider to use, all the documentation I have seen so far seems to assume only keys other than the root CA to be generated in YubiKeys, and when I simply tried to choose either the standard Windows SmartCard Store cryptographic provider or the OpenSC CSP Windows informed me the card was read-only.<br /><br />Thank you in advance for any suggestions!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4639">Marecki</a> — Mon Jan 23, 2017 4:23 pm</p><hr />
]]></content>
</entry>
</feed>