Nitrokey / nitrokey-start-firmware

A mirror of Gnuk's 1.0.x and 1.2.x branches.
56 stars 15 forks source link

Nitrokey Start - can't change admin PIN #61

Closed sanosis closed 2 years ago

sanosis commented 3 years ago

Nitrokey Start (old one) updated to latest firmware: FSIJ-1.2.15 (RTM.10)

After updating the firmware I can't change the Admin PIN. The standard pin 1-8 works, but after entering the new pin I get: "Error changing the PIN: Conditions of use not satisfied".

Factory reset or uploading keys do not change the situation, tested on 0 and 1 identity.

sanosis commented 3 years ago

Linux Arch, gpg (GnuPG) 2.2.27, libgcrypt 1.9.2-unknown Tested with openpg card in gemalto reader - changing the pin worked.

szszszsz commented 3 years ago

Hi! Since RTM.8 the minimal PIN length without KDF-DO set is 14 characters (both User and Admin). See release note under:

When KDF-DO is set, the PIN can be a regular length. We cannot show this information during setup in GnuPG unfortunately. Sorry for confusion.

Edit: Link to the documentation for the future reference: