Yubikey PIV and PIN Policy
NIIBE Yutaka
gniibe at fsij.org
Wed Sep 16 08:00:00 CEST 2026
Hello,
I'm currently creating a patch for:
https://dev.gnupg.org/T8442
The problem is Yubikey PIV support. Currently, for the PIV.9C signing
key, PIN verification is always required and this restriction is forced
by scdaemon side (as well as the device itself). It is the default
behavior of the device and it conforms to the NIST SP 800-73-5.
On the other hand, Yubikey supports PIV policy setting per key slot, and
a user can change the behavior, not requiring the PIN verification
always, but once.
Currently, scdaemon doesn't care about the device setting, which should
be fixed.
I don't have any experience with PIV. Could someone help to evaluate
the patch?
* The tool, yubico-piv-tool, has --pin-policy=once option to
generate/import a key. IIUC, we can use this to configure a key with
PIN Policy.
* With the configuration of PIV.9C signing with PIN Policy = once,
please test if the patch works as expected. That is, it does not
ask you PIN at the second time.
Attached is the patch candidate.
--
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0001-scd-piv-Check-PIN-Policy-to-decide-about-the-verific.patch
Type: text/x-diff
Size: 4922 bytes
Desc: not available
URL: <https://lists.gnupg.org/pipermail/gnupg-devel/attachments/20260916/db4f2d62/attachment.patch>
More information about the Gnupg-devel
mailing list