Yubico Forum
https://forum.yubico.com/

[Question] Upon too many PIV/Key management failures. Erase?
https://forum.yubico.com/viewtopic.php?f=4&t=2742
Page 1 of 1

Author:  Morthawt [ Wed Oct 04, 2017 6:38 pm ]
Post subject:  [Question] Upon too many PIV/Key management failures. Erase?

If someone tries to use certs I have in my PIV, for, code signing say. They try and try and try, I assume it gets locked right? Are there any conditions where the Yubikey will "maliciously" (desired) destroy the key upon too many failures or anything? Or does it just "choose" to deny the usage of the contained keys and rely on the protection of the secure element to hopefully prevent forced physical access to the key information?

Clarification would be very helpful to know what is what.

Thanks.

Author:  ChrisHalos [ Mon Oct 09, 2017 7:25 pm ]
Post subject:  Re: [Question] Upon too many PIV/Key management failures. Er

Three attempts to verify the PIN and the PIN is blocked. Three attempts to verify the PUK and the PUK is blocked. At this point the only option is to reset the PIV applet. Management Key is the only thing that can hypothetically be brute-forced, but the person with the management key can't use the certificate that's stored on the YubiKey. They would have to generate a new one to use the key. All scenarios are basically covered on our developer website. Recommend you start with https://developers.yubico.com/PIV/Intro ... ccess.html

There is no way to render the PIV applet completely useless (otherwise lots of customers will experiment, lock the PIV applet permanently, and demand a replacement). This isn't like a basic smart card where you lock it and you have to throw it away and buy another one. There are several other manufacturers that offer those.

Author:  Morthawt [ Mon Oct 09, 2017 7:26 pm ]
Post subject:  Re: [Question] Upon too many PIV/Key management failures. Er

Very nice. Thanks for letting me know.

Page 1 of 1 All times are UTC + 1 hour
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/