Below you will find pages that utilize the taxonomy term “PKI”
PKI Is Hard - How Yubico Trusted OpenSSL And Got It Wrong
This is the story on how I discovered that Yubico used an invalid certificate chain in their Personal Identity Verification (PIV) attestation feature on YubiKey 4.3 and YubiKey NEO, which could only be solved by a new hardware release. The impact for users and organizations is that the certificate chain will be deemed invalid by tools that verifies the chain properly, such as OpenSSL version 1.1.0 and later. Yubico has published a custom Python script that can be used to verify their attestation certificate chains.