Yubico Forum

...visit our web-store at store.yubico.com
It is currently Tue Jan 30, 2018 9:25 pm

All times are UTC + 1 hour




Post new topic Reply to topic  [ 3 posts ] 
Author Message
PostPosted: Mon Nov 17, 2014 6:37 pm 
Offline

Joined: Fri Oct 31, 2014 10:34 pm
Posts: 9
Hello all!

I'd like to request anyone that is successfully using their Yubikey Neo in OSX Yosemite in CCID/PIV mode to provide step by step instructions on client setup. I currently have a certificate installed on the Yubikey already that I provisioned on a PC. I now need to be able to use it in OSX.

There are many forum posts about very specific issues with OSX, but no guide that is start to finish.

Thank you!


Top
 Profile  
Reply with quote  

Share On:

Share on Facebook FacebookShare on Twitter TwitterShare on Tumblr TumblrShare on Google+ Google+

PostPosted: Thu Nov 20, 2014 12:47 am 
Offline

Joined: Thu Nov 06, 2014 5:09 pm
Posts: 20
I haven't really used the PIV bits under OSX, but I did manage to get the device talking to pcsclite. Unfortunately, pcsclite doesn't have a generic USB CCID class driver; it's all matched on specific vendor/device IDs. So I had to edit /usr/libexec/SmartCardServices/drivers/ifd-ccid.bundle/Contents/Info.plist to add the vendor ID / device ID / name to the relevant arrays.

I think maybe I also had to make it run pcscd because it wasn't started by default; I don't remember now.

Once you've done that, the device should be recognised as a card reader and show up when you run 'pcsctest'.

That should be the start of your 'start to finish' guide. As I said, I didn't look at PIV — but it was working well enough for me to test the OATH support in the VPN application I was working on.


Top
 Profile  
Reply with quote  
PostPosted: Fri Nov 21, 2014 1:58 am 
Offline

Joined: Fri Nov 21, 2014 1:50 am
Posts: 5
My primary use case is OS X (10.10) with a yubikey NEO-n in CCID/PIV mode only for use in mutual-auth TLS through Safari. The steps I followed were to download and install OpenSC (Yosemite installer was just posted within the last few days). I then put it into CCID mode only using Yubikey NEO Manager and installed the yubico-piv-tool and installed a .p12 using this tool.

The end result is that a keychain is present with my credential on it, but unlocking it via either Keychain Access or in the certificate prompt in Safari does not work. I have reset my pin and for testing purposes set an incorrect pin lockout of 30. I'm having trouble finding why exactly this cannot be unlocked via any application accessing keychain, but all command prompt tools (opensc-tool, yubico-piv-tool) are able to operate with it, which tells me the PIN is set and working. Additionally, installing the .p12 into keychain directly functions as expected, which eliminates that element.

I'd love to hear if anyone got this far and figured out that last step!


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 3 posts ] 

All times are UTC + 1 hour


Who is online

Users browsing this forum: Heise IT-Markt [Crawler] and 9 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group