Yubikey PIV and PIN Policy

NIIBE Yutaka gniibe at fsij.org
Wed Sep 16 08:00:00 CEST 2026


Hello,

I'm currently creating a patch for: 

    https://dev.gnupg.org/T8442

The problem is Yubikey PIV support.  Currently, for the PIV.9C signing
key, PIN verification is always required and this restriction is forced
by scdaemon side (as well as the device itself).  It is the default
behavior of the device and it conforms to the NIST SP 800-73-5.

On the other hand, Yubikey supports PIV policy setting per key slot, and
a user can change the behavior, not requiring the PIN verification
always, but once.

Currently, scdaemon doesn't care about the device setting, which should
be fixed.

I don't have any experience with PIV.  Could someone help to evaluate
the patch?


* The tool, yubico-piv-tool, has --pin-policy=once option to
  generate/import a key.  IIUC, we can use this to configure a key with
  PIN Policy.

* With the configuration of PIV.9C signing with PIN Policy = once,
  please test if the patch works as expected.  That is, it does not
  ask you PIN at the second time.


Attached is the patch candidate.
-- 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0001-scd-piv-Check-PIN-Policy-to-decide-about-the-verific.patch
Type: text/x-diff
Size: 4922 bytes
Desc: not available
URL: <https://lists.gnupg.org/pipermail/gnupg-devel/attachments/20260916/db4f2d62/attachment.patch>


More information about the Gnupg-devel mailing list