Yubico Forum
https://forum.yubico.com/

YubiKey PIV Manager 1.4.2 can't detect YubiKey 4 in Win10 CU
https://forum.yubico.com/viewtopic.php?f=35&t=2642
Page 1 of 1

Author:  petrsnd [ Thu Jun 01, 2017 6:51 pm ]
Post subject:  YubiKey PIV Manager 1.4.2 can't detect YubiKey 4 in Win10 CU

I have a YubiKey 4 that it would like to configure for PIV (9a) and signing (9c). If I open YubiKey Piv Manager (1.4.2) then insert my YubiKey 4, everything works great the first time. It recognizes the key and allows me to initialize it. However, if I remove the key and try to do it again, YubiKey PIV Manager (1.4.2) fails to recognize the key.

YubiKey 4 -- PIV applet firmware 4.3.4
YubiKey PIV Manager version 1.4.2
Windows 10 Pro, Creators Update (Version: 1703)
Code:
> systeminfo | findstr /B /C:"OS Name" /C:"OS Version"
OS Name:                   Microsoft Windows 10 Pro
OS Version:                10.0.15063 N/A Build 15063


I get the following message in the YubiKey PIV Manager UI:
Image

yubico-piv-tool.exe returns the following:
Code:
> .\yubico-piv-tool.exe -astatus
Failed to connect to reader.


I can get YubiKey PIV Manager to recognize the key again if I follow these steps:
  1. Leave the YubiKey 4 inserted
  2. Leave YubiKey PIV Manager (1.4.2) open
  3. Open up Windows Device Manager
  4. Navigate to "Smart card readers"
  5. Find the "Microsoft Usbccid Smartcard Reader (WUDF)" device that was added by Windows, and right click to "Uninstall device"
  6. Remove the YubiKey 4
  7. Reinsert the YubiKey 4
  8. VoilĂ ! YubiKey 4 is recognized and I can work with it.

Another interesting thing is that after following the process described above, when you reinsert the YubiKey 4, ever so briefly you see a device appear under "Smart card readers" called "YubiKey 4 OTP+U2F+CCID". This eventually disappears only to be replaced by "Microsoft Usbccid Smartcard Reader (WUDF)" again. It is seemingly present long enough for YubiKey PIV Manager (1.4.2) to get started interacting with the key.

yubico-piv-tool.exe also works after following the process above.

After I remove the key, it won't work again unless I repeat the steps above to uninstall the device before plugging it back in.

Author:  petrsnd [ Thu Jun 01, 2017 8:36 pm ]
Post subject:  Re: YubiKey PIV Manager 1.4.2 can't detect YubiKey 4 in Win1

More information. If you enable viewing hidden devices, you can see additional information about what might be wrong.

From the Windows Device Manager Menu:
"View" => "Show hidden devices"

This is what you see when you have inserted the card and it was not recognized (notice the light grey).
Image

If you follow the steps I posted to delete the smart card reader to try again, you'll see this:
Image

The PIV smart card is not being found by the operating system. This means I might have trouble trying to use the YubiKey 4 as a smart card to authenticate to an web application or for a domain login. So, I'm not this is only a YubiKey PIV Manager problem...

When I remove the YubiKey 4, the "Smart card filter driver", the "Microsoft Usbccid Smartcard Reader (WUDF)", and the "Identity Device (NIST SP 800-73 [PIV])" devices all turn grey. When I plug it back in, only the first two come back as show in the first image above.

Author:  petrsnd [ Mon Jun 05, 2017 6:30 pm ]
Post subject:  Re: YubiKey PIV Manager 1.4.2 can't detect YubiKey 4 in Win1

Filed this bug today: https://github.com/Yubico/yubikey-piv-manager/issues/24

Author:  petrsnd [ Thu Jun 15, 2017 7:15 pm ]
Post subject:  Re: YubiKey PIV Manager 1.4.2 can't detect YubiKey 4 in Win1

This was determined to be a Microsoft bug. More details can be found in the GitHub issue I filed:
https://github.com/Yubico/yubikey-piv-manager/issues/24

This is the summary from @dagheyman:
Quote:
Workaround seems to be:
  • Add SeLoadDriverPrivilege to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ ScDeviceEnum\RequiredPrivileges
  • Reboot

Page 1 of 1 All times are UTC + 1 hour
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/