<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=1657" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2015-03-13T15:33:21+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=1657</id>
<entry>
<author><name><![CDATA[zviratko]]></name></author>
<updated>2015-03-13T15:33:21+01:00</updated>
<published>2015-03-13T15:33:21+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1657&amp;p=7026#p7026</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1657&amp;p=7026#p7026"/>
<title type="html"><![CDATA[Re: yubico-piv-tool, ECCP256 and ssh]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1657&amp;p=7026#p7026"><![CDATA[
Hi,<br />have you found out a solution to this?<br /><br />I'd love to use ECC keys, but without PKCS11 support it will not work. I looked around for possibility of adding the support but couldn't find anything (and I'm not a developer).<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3463">zviratko</a> — Fri Mar 13, 2015 3:33 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[evansguy]]></name></author>
<updated>2014-12-14T21:43:10+01:00</updated>
<published>2014-12-14T21:43:10+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1657&amp;p=6508#p6508</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1657&amp;p=6508#p6508"/>
<title type="html"><![CDATA[Re: yubico-piv-tool, ECCP256 and ssh]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1657&amp;p=6508#p6508"><![CDATA[
Ok, I've done some more experimenting.  It seems that things are ok at the PKCS11 level as the following works :-<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">pkcs11-tool --module /lib64/opensc-pkcs11.so  --sign --slot 1 --id 02 -m ECDSA --input-file wombat --output-file wombat-signed<br /></div><br /><br />The problem looks like it's with openssh.  The man page for ssh_config mentions that the PKCS11Provider reads RSA keys (no mention of ECC) and a quick scan of the source code at  <!-- m --><a class="postlink" href="https://github.com/openssh/openssh-portable/blob/master/ssh-pkcs11.c">https://github.com/openssh/openssh-port ... h-pkcs11.c</a><!-- m --> seems to confirm this.<br /><br />Cheers<br />Guy<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3373">evansguy</a> — Sun Dec 14, 2014 9:43 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[evansguy]]></name></author>
<updated>2014-12-12T19:17:21+01:00</updated>
<published>2014-12-12T19:17:21+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1657&amp;p=6498#p6498</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1657&amp;p=6498#p6498"/>
<title type="html"><![CDATA[Re: yubico-piv-tool, ECCP256 and ssh]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1657&amp;p=6498#p6498"><![CDATA[
How do I do that?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3373">evansguy</a> — Fri Dec 12, 2014 7:17 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Tom2]]></name></author>
<updated>2014-12-12T16:08:20+01:00</updated>
<published>2014-12-12T16:08:20+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1657&amp;p=6497#p6497</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1657&amp;p=6497#p6497"/>
<title type="html"><![CDATA[Re: yubico-piv-tool, ECCP256 and ssh]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1657&amp;p=6497#p6497"><![CDATA[
Hello,<br /><br />This may not be a complete answer, but the pkcs11 module doesn't support ECC.<br /><br />Could you double check?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3364">Tom2</a> — Fri Dec 12, 2014 4:08 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[evansguy]]></name></author>
<updated>2014-12-12T10:58:20+01:00</updated>
<published>2014-12-12T10:58:20+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1657&amp;p=6494#p6494</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1657&amp;p=6494#p6494"/>
<title type="html"><![CDATA[yubico-piv-tool, ECCP256 and ssh]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1657&amp;p=6494#p6494"><![CDATA[
Hello,<br /><br />I've got my yubikey neo working with a RSA public/private key and ssh.  However, I can't get it to work with the elliptic curve algorithm ECCP256.<br /><br />The steps that I've done :-<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">yubico-piv-tool -s 9a -a generate /usr/lib/x86_64-linux-gnu/opensc-pkcs11.sote -A ECCP256 -o public-ecc.pem<br />yubico-piv-tool -a verify-pin -P 123456 -a selfsign-certificate -s 9a -S &quot;/CN=Guy Evans ECC key/&quot; -i public-ecc.pem -o ecc-cert.pem<br />yubico-piv-tool -a import-certificate -s 9a -i ecc-cert.pem</div><br /><br />Which all seem to run ok, however, when I run <br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">ssh-keygen -D /usr/lib/x86_64-linux-gnu/opensc-pkcs11.so</div><br /><br />I get the error C_GetAttributeValue failed: 18.<br /><br />I can use ssh-keygen to convert the public-ecc.pem file directly and copy that to authorized_keys.  However, when I attempt to login with ssh -I /usr/lib/x86_64-linux-gnu/opensc-pkcs11.so I get the same error.<br /><br />pkcs15-tool --list-public-keys shows the key.  pkcs15-tool --read-public-key comes back with a &quot;not implemented&quot; error (but also does the same for a RSA key).  pkcs15-tool --read-certificate correctly outputs the certificate that was imported.<br /><br />Cheers<br />Guy<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3373">evansguy</a> — Fri Dec 12, 2014 10:58 am</p><hr />
]]></content>
</entry>
</feed>