- Will now attempt to open device 3 times before failing
- OpenPGP: Don't say data is removed when not
- OpenPGP: Don't swallow APDU errors
- PIV: Block on-chip RSA key generation for firmware versions 4.2.0 to 4.3.4 (inclusive) since these chips are vulnerable to CVE-2017-15631.