solokeys / openpgp

OpenPGP functionality for Solo
107 stars 10 forks source link

Non-extractable keys #4

Open paroxp opened 4 years ago

paroxp commented 4 years ago

It would be beneficial if the solokeys were capable of generating non-extractable gpg and ssh keys.

merlokk commented 4 years ago

Attestation was added as a Yubico-specific extension in version 3.4 of the OpenPGP Smart Card Specification

My1 commented 4 years ago

It would be beneficial if the solokeys were capable of generating non-extractable gpg and ssh keys.

I thought this is the default already (except on a hacker device)

merlokk commented 4 years ago

It's part of specification 3.4. This specification now not public, but can be downloaded from their ftp If we talk about openpgp. As for u2f and fido2 - it another story

merlokk commented 4 years ago

https://gnupg.org/ftp/specs/OpenPGP-smart-card-application-3.4.pdf