Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Same certificate on multiple Yubikey #11

Open
YoNevelt opened this issue Feb 6, 2023 · 2 comments
Open

Same certificate on multiple Yubikey #11

YoNevelt opened this issue Feb 6, 2023 · 2 comments

Comments

@YoNevelt
Copy link

YoNevelt commented Feb 6, 2023

Hi,
I tried to do the best thing and upload the same certificate to more Yubikeys. But opening the database with the backup key is not working, KeePass says:

Selected certificate can't be used!
Reason: At least on the of the given parameters can't be interpreted correctly.

There's no other messages, details, nothing. I have a Yubikey 5C Nano and a Yubikey 5C NFC. I generated the certificate on the Nano, exported it then imported to the NFC model into the same slot. Windows doesn't show any difference between the certificates, when the selector pops up, I can see the same. After typing the PIN, I get access to the certificate but KeePass / the plugin doesn't accept/work with it.

@FrantisekBodnar
Copy link
Member

Hello, I never experienced this issue. Do you use PFX certificate, with private key? The plugin only restricts expiration date of the cert, nothing else, rest is handled by Windows OS.

@YoNevelt
Copy link
Author

YoNevelt commented Feb 6, 2023

I cleaned up the personal certificates in Windows (certmgr.msc) just to be sure I have only 1 Yubikey certificate active.
I generated the certificate with RSA2048. Set the expire date and name. I have Management Key set but basically only the hardware is a different model, the setup is the same. I'll try it on a different Windows machine later and I get back to you with the results. Thank you for your prompt attention.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants