Yubico Forum

...visit our web-store at store.yubico.com
It is currently Tue Jan 30, 2018 10:07 am

All times are UTC + 1 hour




Post new topic Reply to topic  [ 3 posts ] 
Author Message
PostPosted: Wed Mar 23, 2016 4:11 pm 
Offline

Joined: Wed Mar 23, 2016 3:59 pm
Posts: 2
I am looking at the possibility of using YubiHSM to encrypt data on a server without having the ability for the same server to decrypt it - however I am having trouble getting past go with the python API.

I can connect to the HSM OK, generate keys and unlock them with no issues through a terminal. However when I attempt to unlock the keys using pyhsm I am told the master key which I use successfully through the terminal is too long.

Attachment:
Screen Shot 2016-03-23 at 15.07.47.png
Screen Shot 2016-03-23 at 15.07.47.png [ 157.18 KiB | Viewed 2227 times ]



I feel like I am missing something obvious....


Dom


Top
 Profile  
Reply with quote  

Share On:

Share on Facebook FacebookShare on Twitter TwitterShare on Tumblr TumblrShare on Google+ Google+

PostPosted: Thu Mar 24, 2016 8:37 am 
Offline
Site Admin
Site Admin

Joined: Thu Apr 19, 2012 1:45 pm
Posts: 148
Hey,

What you're missing is that you need to hex decode the password before you pass it to the unlock function. See https://github.com/Yubico/python-pyhsm/ ... unlock#L76 for an example of how this is done in the yhsm-keystore-unlock utility.

/klas


Top
 Profile  
Reply with quote  
PostPosted: Thu Mar 24, 2016 8:47 am 
Offline

Joined: Wed Mar 23, 2016 3:59 pm
Posts: 2
Thank you for the reply - will try shortly!


Dom


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 3 posts ] 

All times are UTC + 1 hour


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group