Yubico Forum
https://forum.yubico.com/

ykksm-gen-keys.pl and windows personalize
https://forum.yubico.com/viewtopic.php?f=16&t=498
Page 1 of 1

Author:  mgb [ Thu Mar 11, 2010 4:18 am ]
Post subject:  ykksm-gen-keys.pl and windows personalize

Hi guys,

I generated a key with ykksm-gen-keys.pl for insertion into the ykksm database, I also exported that key with ykksm-export.pl into an unencrypted file. I took that file and the first 3 fields are publicName, internalName,aesKey

I tried to provision my yubikey with those parameters but it always generates a key with a publicName that doesn't match so I can't valiadate against my ykksm database.

Has anyone hit this problem or have a work around? I figured it must have to do with the import on Windows (right now all my fields are in Modhex as supplied by ykksm-export.pl

Any suggestions of things I might try? Its tantalisingly close to working outside of the yubico infrastructure but not quite there....


Thanks.. any help appreciated.

Author:  mgb [ Thu Mar 11, 2010 9:31 pm ]
Post subject:  Re: ykksm-gen-keys.pl and windows personalize

Replying to my own post.

The ykksm-export-keys.pl adds some extraneous information the windows utility doesn't understand, including the header and incrementing serial number at the beginning. I also converted the public id from modhex to hex so that the format looked like public_id(hex),private_id(modhex),aes_key

Also by default the ykksm-gen-keys.pl script uses 6 bytes for the modhex encode of the public_id key, be sure to set it to such when writing a new key from the windows utility.

Page 1 of 1 All times are UTC + 1 hour
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/