github framefilter/keyroost v0.11.0

3 hours ago

Changed

  • Reset commands no longer guess which key to wipe. With several matching
    keys connected and no selector, molto reset, oath reset,
    openpgp reset and piv reset now stop with an error that names
    --device and lists the candidates, instead of acting on the first one
    found (molto reset) or asking for --reader. Passing both --reader and
    --device to these commands, or to fido reset, is now an error instead of
    --reader silently winning. A single connected key still works without
    flags. Scripts that passed both flags, or relied on the first-found key,
    need to pass one selector.
  • fido set-min-pin and fido enterprise-attestation require --yes.
    Both changes can only be undone by resetting the key, which wipes its
    credentials. Without --yes they refuse and send nothing to the key,
    matching the typed confirmation the app already asks for. Scripts that
    run them need to add --yes.

Fixed

  • PIV reads now handle gzip-compressed certificates. A PIV certificate
    object may hold its certificate gzip-compressed (the CertInfo byte
    71 01 01, part of the PIV standard); the tool that writes the certificate
    chooses this, and tools such as ykman do so on request. keyroost was
    handing the compressed bytes straight to the X.509 parser, which rejected
    them with "DER length field is implausibly large." piv test failed on
    such a slot before it even reached the PIN, and export-cert and the
    status pane's Subject-DN read had the same latent gap. keyroost now honours
    the CertInfo flag and inflates the certificate on read (size-capped), so
    piv test, export-cert, and the status pane read such a certificate
    correctly. The gzip checksum and length are verified on read, so a
    corrupted compressed certificate is reported as damaged rather than passed
    on. A compressed certificate whose data is damaged, or that would
    decompress past a 64 KiB cap, is reported as present but unreadable, with
    the reason: export-cert and piv test fail with that message rather than
    writing or parsing the raw bytes, and piv status (text, and --json via
    a new cert_unreadable field) and the GUI show the slot as holding an
    unreadable certificate, not as empty.
    Reported by @n0xena. (#147)
  • PIV certificate imports that are too large now say so. Importing a
    certificate of about 3 KB or more could fail with a raw PC/SC error
    ("An attempt was made to end a non-existent transaction") before the card
    answered, so the command-chaining fallback never ran. keyroost now retries
    such an import with command chaining. A certificate that fits (for
    example 3048 bytes on a YubiKey 5.7) imports. One the card refuses gets
    "the certificate (N bytes) is too large for ", or "the card has no
    room left" when its storage is full. A refused import leaves the slot's
    existing certificate unchanged. (#151)
  • molto probe no longer sends the keyless seed-delete instruction. The
    hidden research command keyroostctl molto probe --yes sweeps the Molto2's
    instructions while skipping the ones that change the token, but its skip
    list missed 0xE6 (delete seed), which the token accepts without the
    customer key, so a probe could erase the seed in profile 0. It is now
    skipped like the other write instructions.
  • The AppImage starts on systems without the PC/SC library. It used to
    refuse to launch when libpcsclite.so.1 wasn't installed. It now still
    prefers the system's own library (needed to match the system's pcscd),
    and otherwise falls back to a bundled copy: keyroost starts, FIDO works,
    and the smart-card features report unavailable until pcscd is
    installed. (#157)

Full changelog: https://github.com/framefilter/keyroost/blob/v0.11.0/CHANGELOG.md

Don't miss a new keyroost release

NewReleases is sending notifications on new releases.