Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Understanding YubiKey PIN when authenticate #131

Open
luky0007 opened this issue May 9, 2023 · 0 comments
Open

Understanding YubiKey PIN when authenticate #131

luky0007 opened this issue May 9, 2023 · 0 comments

Comments

@luky0007
Copy link

luky0007 commented May 9, 2023

I checked in Yubico Sample and when we want to register FIDO2 YubiKey (NFC), if before YubiKey have PIN, we must pass PIN when we try register new Yubikey. BUT when we authenticate (user its registred) we not must provide PIN for YubiKey, Yubico library success response AssertOnKeyAuthenticationResponse and we can authenticate. So Question is - why? I checkend webauthn on browser and we must ALWAYS provide PIN to YubiKey when authentication is present.

Read that article https://support.yubico.com/hc/en-us/articles/4402836718866-Understanding-YubiKey-PINs but it not help.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

1 participant