Yubico Forum
https://forum.yubico.com/

Resetting gpg smartcard on Yubikey NEO
https://forum.yubico.com/viewtopic.php?f=26&t=1763
Page 1 of 1

Author:  baloo [ Fri Feb 27, 2015 8:33 am ]
Post subject:  Resetting gpg smartcard on Yubikey NEO

Hello there,

I have a Yubikey NEO bought in October 2014 (with U2F) and I've locked myself out of my smartcard.

Code:
$ gpg --card-status
Application ID ...: D2760001240102000006030128970000
Version ..........: 2.0
Manufacturer .....: unknown
Serial number ....: 03012897
Name of cardholder: [not set]
Language prefs ...: [not set]
Sex ..............: unspecified
URL of public key : [not set]
Login data .......: [not set]
Signature PIN ....: forced
Key attributes ...: 2048R 2048R 2048R
Max. PIN lengths .: 127 127 127
PIN retry counter : 0 3 0
Signature counter : 0
Signature key ....: [none]
Encryption key....: [none]
Authentication key: [none]
General key info..: [none]


I'm unable to reset the smartcard:
Code:
$ gpshell gpinstall.txt
mode_211
enable_trace
establish_context
card_connect
* reader name Yubico Yubikey NEO OTP+U2F+CCID 00 00
select -AID a000000003000000
Command --> 00A4040008A000000003000000
Wrapped command --> 00A4040008A000000003000000
Response <-- 6F658408A000000003000000A5599F6501FF9F6E06479112103800734A06072A864886FC6B01600C060A2A864886FC6B02020101630906072A864886FC6B03640B06092A864886FC6B040255650B06092B8510864864020103660C060A2B060104012A026E01029000
open_sc -security 1 -keyind 0 -keyver 0 -mac_key 404142434445464748494a4b4c4d4e4f -enc_key 404142434445464748494a4b4c4d4e4f
Command --> 80CA006600
Wrapped command --> 80CA006600
Response <-- 664C734A06072A864886FC6B01600C060A2A864886FC6B02020101630906072A864886FC6B03640B06092A864886FC6B040255650B06092B8510864864020103660C060A2B060104012A026E01029000
Command --> 8050000008C488A323DA720A7F00
Wrapped command --> 8050000008C488A323DA720A7F00
Response <-- 0000331700773397091202020001AD2C6EC86A9C5A1F7A8AEDAA95B09000
mutual_authentication() returns 0x80302000 (The verification of the card cryptogram failed.)


The keys appears to have changed is there something I can do to sort this out ?

Author:  Tom2 [ Fri Feb 27, 2015 11:07 am ]
Post subject:  Re: Resetting gpg smartcard on Yubikey NEO

Show me this please:

gpg-connect-agent --hex "scd apdu 00 f1 00 00" /bye

Author:  baloo [ Sun Mar 01, 2015 6:37 pm ]
Post subject:  Re: Resetting gpg smartcard on Yubikey NEO

Code:
D[0000]  01 00 08 90 00                                     .....           
OK

Author:  Tom2 [ Mon Mar 02, 2015 4:30 pm ]
Post subject:  Re: Resetting gpg smartcard on Yubikey NEO

There is no smartcard to reset. You want to reset the applet. Read the documentation

https://developers.yubico.com/ykneo-ope ... pplet.html

Page 1 of 1 All times are UTC + 1 hour
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/