Yubico Forum
https://forum.yubico.com/

[QUESTION] Congfigure new Yubikey 4 for Open PGP
https://forum.yubico.com/viewtopic.php?f=35&t=2270
Page 1 of 1

Author:  susanemcg [ Fri Apr 01, 2016 5:07 pm ]
Post subject:  [QUESTION] Congfigure new Yubikey 4 for Open PGP

Due to problems with my Yubikey NEO, I just ordered a new Yubikey 4. I would like to configure it with Open PGP, and per the documentation here(https://developers.yubico.com/PGP/Importing_keys.html), started with the following:

>gpg-connect-agent --hex "scd apdu 00 f1 00 00" /bye

But I get the error:

ERR 100663406 Card removed <SCD>

I realize this may be because I have not configured the Open PGP Applet, but am unsure whether best practice is now to do this from the Yubikey Personalization Tool GUI, or using ykpersonalize as indicated on the following page (last updated in 2012): https://www.yubico.com/2012/12/yubikey-neo-openpgp/ which is only for the NEO (I couldn't find Yubikey 4-specific documentation) and seems to suggest using the command-line ykpersonalize package, which does not seem to be preferred at this point.

In the Yubikey Personalization Tool GUI, however, it is not obvious how and/or where to configure the Open PGP Applet so that I can move a key onto the device.

Suggestions would be most welcome. I am running GPG 2.0.27.

Author:  ChrisHalos [ Fri Apr 01, 2016 6:00 pm ]
Post subject:  Re: [QUESTION] Congfigure new Yubikey 4 for Open PGP

Mode switching should be done with the YubiKey NEO Manager (https://developers.yubico.com/yubikey-n ... /Releases/ - yes it works for the 4 and Edge as well). ykpersonalize is the alternative, but if you happen to disable OTP, the NEO Manager is the only app that will be able to fix it. The YubiKey 4 already comes with CCID mode enabled, so you shouldn't have to use either application anyway. It's ready to use with OpenPGP as soon as you receive it.

"gpg-connect-agent --hex "scd apdu 00 f1 00 00" /bye" also should never have to be run on a YubiKey 4, as the purpose of the command is to confirm you have a NEO OpenPGP applet 1.0.6 or newer. If you've purchased a NEO or YubiKey 4 since around summer of 2014, you don't have to worry about this.

Getting that error from attempting to check the applet version most likely means you locked out your PIN and / or Admin PIN. Please reset the OpenPGP applet by running the script at the bottom of this page:

https://developers.yubico.com/ykneo-ope ... pplet.html

Author:  susanemcg [ Fri Apr 01, 2016 6:07 pm ]
Post subject:  Re: [QUESTION] Congfigure new Yubikey 4 for Open PGP

Thanks! I already tried to reset the applet, but keep getting the same error. I know the documentation said to continue with the process regardless, but since I'm not seeing any results I can't tell when the applet has gotten to C0 to know that it's been reset.

In the meantime, I tried it on another OS (Mac) and it was recognized. But when I try to move the key onto it, it requests an Admin PIN, which I have never configured. I have not found a default mentioned in the related documentation. Is there somewhere I can find this?

Thanks again.

Author:  mouse008 [ Fri Apr 22, 2016 11:43 pm ]
Post subject:  Re: [QUESTION] Congfigure new Yubikey 4 for Open PGP

If memory serves, the default Admin PIN is "12345678" (without quotes).

Make sure to change it. ;)

Author:  ChrisHalos [ Mon Apr 25, 2016 6:36 pm ]
Post subject:  Re: [QUESTION] Congfigure new Yubikey 4 for Open PGP

That is correct.

Default PIN = 123456 (must be 6 characters minimum)
Default Admin PIN = 12345678 (must be 8 characters minimum)

Author:  Patterner [ Thu Sep 15, 2016 3:06 am ]
Post subject:  Re: [QUESTION] Congfigure new Yubikey 4 for Open PGP

I tried to get mine working, but so far nothing helped. only "card error"s, "access denied"s and messages like that.

Author:  hubert [ Mon Sep 19, 2016 1:06 pm ]
Post subject:  Re: [QUESTION] Congfigure new Yubikey 4 for Open PGP

Hello!

Have you installed scdaemon? I had the same problem till I install it.

Good luck

Page 1 of 1 All times are UTC + 1 hour
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/