<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=2427" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2018-01-17T10:48:01+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=2427</id>
<entry>
<author><name><![CDATA[maggis]]></name></author>
<updated>2018-01-17T10:48:01+01:00</updated>
<published>2018-01-17T10:48:01+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2427&amp;p=10111#p10111</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2427&amp;p=10111#p10111"/>
<title type="html"><![CDATA[Re: Smart card removed when press YubiKey button]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2427&amp;p=10111#p10111"><![CDATA[
For the record, I am linking to <!-- l --><a class="postlink-local" href="https://forum.yubico.com/viewtopic.php?f=25&amp;t=2764">viewtopic.php?f=25&amp;t=2764</a><!-- l --> that implements the aforementioned minidriver, with support for multiple certificates.<br /><br />With <strong>important</strong> drawbacks, see for example <!-- l --><a class="postlink-local" href="https://forum.yubico.com/viewtopic.php?f=26&amp;t=2739">viewtopic.php?f=26&amp;t=2739</a><!-- l --> , by the way!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4467">maggis</a> — Wed Jan 17, 2018 10:48 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[maggis]]></name></author>
<updated>2016-09-18T13:45:17+01:00</updated>
<published>2016-09-18T13:45:17+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2427&amp;p=9024#p9024</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2427&amp;p=9024#p9024"/>
<title type="html"><![CDATA[Re: Smart card removed when press YubiKey button]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2427&amp;p=9024#p9024"><![CDATA[
Thanks, useful information.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4467">maggis</a> — Sun Sep 18, 2016 1:45 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[ChrisHalos]]></name></author>
<updated>2016-09-16T16:20:29+01:00</updated>
<published>2016-09-16T16:20:29+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2427&amp;p=9018#p9018</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2427&amp;p=9018#p9018"/>
<title type="html"><![CDATA[Re: Smart card removed when press YubiKey button]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2427&amp;p=9018#p9018"><![CDATA[
Just as an FYI, the YubiKey 4 doesn't disconnect/reconnect like the NEO (it was designed as a monolithic firmware, so if you send an OTP it doesn't eject the smart card). It also allows certificates up to 3049 bytes (compared to 2025 bytes with the NEO, although generally not an issue unless you're using a larger private key for the CA, or your environment is very complex).<br /><br />9a is for authentication, so no, you can't use other slots for domain authentication. It's possible on some other smart card manufacturers' offerings, but there is currently no vendor-specific minidriver for the YubiKey. making this impossible. You would essentially need middleware to map multiple certificates to 9a.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3140">ChrisHalos</a> — Fri Sep 16, 2016 4:20 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[maggis]]></name></author>
<updated>2016-09-16T13:36:21+01:00</updated>
<published>2016-09-16T13:36:21+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2427&amp;p=9016#p9016</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2427&amp;p=9016#p9016"/>
<title type="html"><![CDATA[Re: Smart card removed when press YubiKey button]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2427&amp;p=9016#p9016"><![CDATA[
Disappointing. Thanks for the link, will definitely check it out, I hope it is a feasible workaround.<br /><br />Do you happen to know if there is any way to use other certificate slots than 9a for things like logon on Windows? I would like to use more than the slot 9a for logon to different AD realms. Where are the slots defined? Probably in the standard but it sounds painful to find &amp; read it all so looking for some pointers here. Will do a separate thread if no reply.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4467">maggis</a> — Fri Sep 16, 2016 1:36 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Tom2]]></name></author>
<updated>2016-09-16T12:39:45+01:00</updated>
<published>2016-09-16T12:39:45+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2427&amp;p=9015#p9015</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2427&amp;p=9015#p9015"/>
<title type="html"><![CDATA[Re: Smart card removed when press YubiKey button]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2427&amp;p=9015#p9015"><![CDATA[
Hello,<br /><br />You are correct. No, there is no workaround if you want to use HID interface.<br /><br />If you use TOTP or HOTP you can use the Yubico Authenticator that shouldn't eject the card<br /><!-- m --><a class="postlink" href="https://developers.yubico.com/yubioath-desktop/">https://developers.yubico.com/yubioath-desktop/</a><!-- m --><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3364">Tom2</a> — Fri Sep 16, 2016 12:39 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[maggis]]></name></author>
<updated>2016-09-16T13:23:59+01:00</updated>
<published>2016-09-16T12:25:45+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2427&amp;p=9014#p9014</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2427&amp;p=9014#p9014"/>
<title type="html"><![CDATA[Smart card removed when press YubiKey button]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2427&amp;p=9014#p9014"><![CDATA[
Does pressing the YubiKey button on YubiKey NEO cause the smart card to be removed momentarily?<br /><br />If the policy on Windows is set to &quot;lock workstation on smart card removal&quot;, pressing the YubiKey button causes workstation to lock. This is a huge caveat and practically makes all OTP functionality unusable. Tested on Windows 10 and Windows 7.<br /><br />Letting the user remove smart card without locking the workstation is not possible due to policy reasons and I believe most smart card deployments use this policy.<br /><br />Is there any workaround to use the OTP functionality on YubiKey NEO with smart card removal policy set?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4467">maggis</a> — Fri Sep 16, 2016 12:25 pm</p><hr />
]]></content>
</entry>
</feed>