Yubico Forum
https://forum.yubico.com/

[QUESTION] NEO + PIV; Can I disable the PIN?
https://forum.yubico.com/viewtopic.php?f=26&t=2342
Page 1 of 1

Author:  BuildTheRobots [ Mon Jun 13, 2016 12:06 pm ]
Post subject:  [QUESTION] NEO + PIV; Can I disable the PIN?

I am trying to use my YubiKey's PIV applet to hold an SSL key for openVPN.
I have successfully imported the certificate+key onto my YubiKey and have configured openvpn client on CentOS to use pkcs11 to load in the cert/key. This seems to be working great :)

As I want to deploy this to a remote server, is it possible for the PIV applet NOT to prompt for the pin when accessing a cert/key, or is it possible somehow hardcode the pin into the PIV applet/OS?

I wish to protect against the ssl-key being cloned or extracted (rather than used), essentially tying the vpn connection to a specific dongle (yubikey).
I have no wish to protect against it being used (as the pin currently does), just to protect against the key being copied/extracted (which if I understand correctly is impossible anyway).

Any advice would be greatly appreciated.

Edited to add [question] to the subject.

Author:  offset [ Tue Jun 14, 2016 5:56 am ]
Post subject:  Re: [QUESTION] NEO + PIV; Can I disable the PIN?

Looking for similar solution, except for automated build pipeline for code signing, goal is remove ability to extract private key, but allow code signing operations in a build pipeline.

Author:  Tom2 [ Tue Jun 14, 2016 1:14 pm ]
Post subject:  Re: [QUESTION] NEO + PIV; Can I disable the PIN?

9a is for PIV Authentication (once)
9c is for Digital Signature (PIN always checked)
9d is for Key Management (once)
9e is for Card Authentication (PIN never checked)

http://nvlpubs.nist.gov/nistpubs/Specia ... 0-73-4.pdf

Author:  offset [ Tue Jun 14, 2016 4:35 pm ]
Post subject:  Re: [QUESTION] NEO + PIV; Can I disable the PIN?

Tom2 wrote:
9a is for PIV Authentication (once)
9c is for Digital Signature (PIN always checked)
9d is for Key Management (once)
9e is for Card Authentication (PIN never checked)

http://nvlpubs.nist.gov/nistpubs/Specia ... 0-73-4.pdf


Yes, known.

However, even under 9e, because of the Access Control Matrix listed here - https://developers.yubico.com/PIV/Intro ... ccess.html

Any sign operations still require a PIN, is there a way to change this behavior (even custom config) of the Yubikey for this use case?

Page 1 of 1 All times are UTC + 1 hour
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/