Files
yubikey/pkcs15-tools.md
2024-08-29 01:31:34 +08:00

1.6 KiB

$ pkcs15-tool --list-info
Using reader with a card: Yubico YubiKey OTP+FIDO+CCID
PKCS#15 Card [hatterjiang]:
	Version        : 0
	Serial number  : f8611841ff8055ac3da54acba9975cee
	Manufacturer ID: piv_II 
	Flags          : 
$ pkcs15-tool --list-certificates 
Using reader with a card: Yubico YubiKey OTP+FIDO+CCID
X.509 Certificate [Certificate for Card Authentication]
	Object Flags   : [0x00]
	Authority      : no
	Path           : 
	ID             : 04
	Encoded serial : 02 09 0088891A87487694BA
$ pkcs15-tool --list-public-keys
Using reader with a card: Yubico YubiKey OTP+FIDO+CCID
Public EC Key [PIV AUTH pubkey]
	Object Flags   : [0x00]
	Usage          : [0x40], verify
	Access Flags   : [0x02], extract
	FieldLength    : 384
	Key ref        : 154 (0x9A)
	Native         : yes
	ID             : 01
	DirectValue    : <absent>

Public EC Key [SIGN pubkey]
	Object Flags   : [0x00]
	Usage          : [0x40], verify
	Access Flags   : [0x02], extract
	FieldLength    : 256
	Key ref        : 156 (0x9C)
	Native         : yes
	ID             : 02
	DirectValue    : <absent>
$ pkcs15-tool --read-ssh-key 01
Using reader with a card: Yubico YubiKey OTP+FIDO+CCID
ecdsa-sha2-nistp384 AAAAE2Vj.... PIV AUTH pubkey
$ pkcs15-tool --read-certificate 01
Using reader with a card: Yubico YubiKey OTP+FIDO+CCID
-----BEGIN CERTIFICATE-----
....
-----END CERTIFICATE-----
$ pkcs15-tool --read-public-key 01
Using reader with a card: Yubico YubiKey OTP+FIDO+CCID
-----BEGIN PUBLIC KEY-----
....
-----END PUBLIC KEY-----

Reference

  1. https://ubuntu.com/server/docs/smart-card-authentication