You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hello!
As I understand yubico can only import private keys and certificates. May I ask why public keys are deprived in this case? I don't even speak about CKO_DATA, it would be cool if these tokens have an ability to store some data securely.
Thank you!
The text was updated successfully, but these errors were encountered:
The PIV standard specifies that data slots shall contain certificates. One way to represent 'just a public key' is to create a self-signed certificate, something that you can do in YubiKey Authenticator or yubico-piv-tool. That said, the YubiKey doesn't care what data you store in data slots so you could store just a public key if you wanted to, but other PIV applications would expect to find certificates. Regarding secure storage the YubiKey PIV application is designed to work with clients that follow the PIV specification, which specifies how the data slots are to be accessed.
Hello!
As I understand yubico can only import private keys and certificates. May I ask why public keys are deprived in this case? I don't even speak about CKO_DATA, it would be cool if these tokens have an ability to store some data securely.
Thank you!
The text was updated successfully, but these errors were encountered: