Skip to content

v0.2.0: Cloning Support

Latest

Choose a tag to compare

@zeroSteiner zeroSteiner released this 08 Nov 17:27
· 2 commits to master since this release

This release adds support for cloning a previously initialized YubiKey to a new one.

Cloning

Given an existing YubiKey that was already initialized and the age-encrypted CA private key data, a new YubiKey can be initialized using the clone command. This new YubiKey can be used in the future to initialize new ones as well. A new age-encrypted CA private key will be generated for all of the YubiKey recipients, both old and new.

Database Schema

In order to support cloning YubiKeys and maintaining backwards compatibility with all previously cloned YubiKeys, the database was updated to track recipient information for previously initialized CA files. This is necessary to include the old recipients for newly encrypted CA files. The database now also includes schema tracking. A new database command with schema and upgrade subcommands is now available for seeing the current schema, and for upgrading to the latest schema.