Open IDevJoe opened 1 month ago
Updated and reproduced on SDK 1.11.0
Hi @IDevJoe,
Thanks for reporting this issue. To help us better understand and resolve the problem, could you please provide the following information:
Environment Details: Any relevant configurations on your machine.
Detailed Reproduction Steps: More detailed steps to reproduce the issue, including any specific configurations of the YubiKey device.
Key Management: Details about the old and new management keys. Are you using a standard key change process? Have you tried using different keys or configurations?
Current Workarounds: Details on the process and state of the YubiKey when you do not modify the management key.
With this information, we will be in a better position to investigate and resolve the issue.
@DennisDyallo
Environment Details: Windows 10 21H2 .NET Framework 4.8
Reproduction steps: (From reset state)
certutil -scinfo
Key management: The management key is changed to a randomized key during the initial provisioning process. It is one of the first steps. I have tried changing where in the process the key is changed, but the key container seems to never be generated no matter where it happens. The key is always changed when from the reset state of the card.
Current workarounds: The only workaround that doesn't add additional overhead is to simply not change the management key. In theory, you could ask the user to unplug the key and plug it back in before the management key is actually changed (triggering the smartcard minidriver to create the containers).
Is there an existing issue for this?
Current Behavior
After importing certificates using the SDK with a modified management key, windows fails to recognize the imported certificates because the containers are never created.
Not modifying the management key fixes the behavior, since the minidriver is able to modify the MSCMAP itself.
Expected Behavior
During the import operation, the MSCMAP should be updated on the card, allowing the certificates to be recognized (or a separate function should be available to do this). The documentation states that this operation already exists:
any necessary operations with the MSCMAP will be handled by the SDK
, but there is no trace of the SDK modifying the MSCMAP.Steps To Reproduce
Run the code (obviously replace necessary components to make it work):
Version
1.8.0
Version
5.4.3
Anything else?
No response