Yubico Forum

...visit our web-store at store.yubico.com
It is currently Tue Jan 30, 2018 11:10 am

All times are UTC + 1 hour




Post new topic Reply to topic  [ 4 posts ] 
Author Message
PostPosted: Thu Jun 01, 2017 6:51 pm 
Offline

Joined: Thu Jun 01, 2017 6:11 pm
Posts: 4
I have a YubiKey 4 that it would like to configure for PIV (9a) and signing (9c). If I open YubiKey Piv Manager (1.4.2) then insert my YubiKey 4, everything works great the first time. It recognizes the key and allows me to initialize it. However, if I remove the key and try to do it again, YubiKey PIV Manager (1.4.2) fails to recognize the key.

YubiKey 4 -- PIV applet firmware 4.3.4
YubiKey PIV Manager version 1.4.2
Windows 10 Pro, Creators Update (Version: 1703)
Code:
> systeminfo | findstr /B /C:"OS Name" /C:"OS Version"
OS Name:                   Microsoft Windows 10 Pro
OS Version:                10.0.15063 N/A Build 15063


I get the following message in the YubiKey PIV Manager UI:
Image

yubico-piv-tool.exe returns the following:
Code:
> .\yubico-piv-tool.exe -astatus
Failed to connect to reader.


I can get YubiKey PIV Manager to recognize the key again if I follow these steps:
  1. Leave the YubiKey 4 inserted
  2. Leave YubiKey PIV Manager (1.4.2) open
  3. Open up Windows Device Manager
  4. Navigate to "Smart card readers"
  5. Find the "Microsoft Usbccid Smartcard Reader (WUDF)" device that was added by Windows, and right click to "Uninstall device"
  6. Remove the YubiKey 4
  7. Reinsert the YubiKey 4
  8. VoilĂ ! YubiKey 4 is recognized and I can work with it.

Another interesting thing is that after following the process described above, when you reinsert the YubiKey 4, ever so briefly you see a device appear under "Smart card readers" called "YubiKey 4 OTP+U2F+CCID". This eventually disappears only to be replaced by "Microsoft Usbccid Smartcard Reader (WUDF)" again. It is seemingly present long enough for YubiKey PIV Manager (1.4.2) to get started interacting with the key.

yubico-piv-tool.exe also works after following the process above.

After I remove the key, it won't work again unless I repeat the steps above to uninstall the device before plugging it back in.


Top
 Profile  
Reply with quote  

Share On:

Share on Facebook FacebookShare on Twitter TwitterShare on Tumblr TumblrShare on Google+ Google+

PostPosted: Thu Jun 01, 2017 8:36 pm 
Offline

Joined: Thu Jun 01, 2017 6:11 pm
Posts: 4
More information. If you enable viewing hidden devices, you can see additional information about what might be wrong.

From the Windows Device Manager Menu:
"View" => "Show hidden devices"

This is what you see when you have inserted the card and it was not recognized (notice the light grey).
Image

If you follow the steps I posted to delete the smart card reader to try again, you'll see this:
Image

The PIV smart card is not being found by the operating system. This means I might have trouble trying to use the YubiKey 4 as a smart card to authenticate to an web application or for a domain login. So, I'm not this is only a YubiKey PIV Manager problem...

When I remove the YubiKey 4, the "Smart card filter driver", the "Microsoft Usbccid Smartcard Reader (WUDF)", and the "Identity Device (NIST SP 800-73 [PIV])" devices all turn grey. When I plug it back in, only the first two come back as show in the first image above.


Top
 Profile  
Reply with quote  
PostPosted: Mon Jun 05, 2017 6:30 pm 
Offline

Joined: Thu Jun 01, 2017 6:11 pm
Posts: 4
Filed this bug today: https://github.com/Yubico/yubikey-piv-manager/issues/24


Top
 Profile  
Reply with quote  
PostPosted: Thu Jun 15, 2017 7:15 pm 
Offline

Joined: Thu Jun 01, 2017 6:11 pm
Posts: 4
This was determined to be a Microsoft bug. More details can be found in the GitHub issue I filed:
https://github.com/Yubico/yubikey-piv-manager/issues/24

This is the summary from @dagheyman:
Quote:
Workaround seems to be:
  • Add SeLoadDriverPrivilege to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ ScDeviceEnum\RequiredPrivileges
  • Reboot


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

All times are UTC + 1 hour


Who is online

Users browsing this forum: Google [Bot] and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group