Added
- PIV applet fingerprinting and per-key feature support. keyroost now
identifies which PIV implementation a card runs (YubiKey, Token2, Nitrokey,
uTrust, HID Crescendo, Authentrend, OpenFIPS201 and others) from its ATR,
SELECT response and a few AID probes, and shows it inpiv statusand the
GUI's status line, with the device firmware next to the applet version
where it differs. A built-in list says which vendor extensions (move and
delete key, reset, key types, PIN and touch policies) each applet supports.
Unknown applets keep every control, with a warning; a feature the list
marks unsupported is greyed with the reason on hover, and the GUI's
Enable Anyway line at the bottom of the PIV pane turns those back on
for that key until the app closes. In the CLI,--forcedoes the same.
Contributed by @episource. (#128) - More PIV key and certificate options. ECC P-521 keys
(--algorithm eccp521) and SHA-512 signatures;--years,--monthsand
--dayscombine for certificate and CHUID validity (default: one calendar
year), with matching GUI fields;--mgmt-key-defaultuses the card's
factory management key. (#128) - PIN-protected management key.
piv change-management-key --allow-pin-unlock(GUI: "Allow PIN unlock") stores the management key so
the PIN alone unlocks management, and the GUI can authenticate with the PIN.
The Change management key dialog can generate a random key and copy it; the
clipboard is cleared after 45 seconds. (#128) - HID Crescendo management. Management-key authentication and rotation,
Delete key, the serial number, and a whole-device factory reset, each
through HID's own commands. (#128) - Serial numbers match the device. Token2 PIV and OpenPGP serials now show
the number printed on the key, a Nitrokey shows its own serial, and serials
too long for decimal display as hex. (#128) - PIV certificates too large for a slot can be stored compressed.
keyroost can now write a certificate in the PIV standard's gzip form
(CertInfo0x01, NIST SP 800-73-4). By default it stores certificates
uncompressed and only compresses one the card refuses as too large (about
3 KB on a YubiKey), saying so when it does.piv import-certand
piv self-signtake--compress/--no-compress, and the GUI's Import
certificate and Self-signed dialogs have a matching Compression choice.
Every compressed write is read back and checked.piv statusand the GUI
show which certificates are stored compressed. ykman, OpenSC and, in a
community test on Windows 11, Windows' built-in smart-card driver read
them; macOS's built-in PIV support has not been verified yet (testers
welcome in #152). (#154) - "Enable Anyway" and
--forcealso cover keyroost's own reads. GET
METADATA and ATTEST, which keyroost skips on an applet listed without them,
are sent too, so key details and attestation still show if the list is out
of date. Every skipped or overridden read leaves a line in the--debug
trace and the GUI activity log. (#161)
Changed
piv resetblocks the PIN and PUK itself where needed. On a key listed
as supporting reset, it now locks the PIN and then the PUK if the card asks
for that before resetting; it used to fail unless both were already
blocked. On a key that isn't listed, or with--forceon one listed
without reset, it sends one reset and locks nothing.
Some cards also need the management key or PIN for reset, and keyroost asks
for it.factory-resetnow runs Token2 OTP before PIV, and on HID Crescendo
uses the device-wide reset. (#128)- PIV safety checks before writing.
piv import-certrefuses a
certificate whose public key doesn't match the key in the slot;
generate-keyrefuses a PIN or touch policy the card doesn't accept (unless
--force) and clears the slot's old certificate;self-signand
request-certrefuse an X25519 slot before asking for the PIN. (#128) piv status --jsonreportsserialas a string. A serial can now be
up to 128 bits, and a bare JSON number past 2^53 loses precision in most
consumers, so it is a decimal string, or0x-hex when too long for
decimal, matching the text output. It was a number through 0.11.0.
New fields:applet_fingerprint,applet_name,version_firmware.
(#128)- PIV pane layout. Every slot action stays visible and is greyed with a
reason when it can't run; Import and Export certificate share a row; the
pane is locked while a card command runs; PIN, PUK and management-key fields
have a show/hide button. (#128)
Fixed
- The AppImage runs on older Linux systems and minimal setups. It is now
built on Ubuntu 22.04, so it needs glibc 2.35 rather than 2.39, and it
bundles the keyboard libraries (libxkbcommon,libxkbcommon-x11) the
windowing layer loads at runtime; without them it crashed at startup on
systems that lacklibxkbcommon-x11. The Linux release tarball is built
on Ubuntu 22.04 as well. (#160)
Full changelog: https://github.com/framefilter/keyroost/blob/v0.12.0/CHANGELOG.md