From: NdK <ndk...@gm...> - 2018-01-12 18:46:13
|
Il 12/01/2018 15:04, Jakub Jelen ha scritto: > I am not using web authentication using PKCS#11, but (for the sake of > correct outcomes here) I got to test it today and it works as expected > without any concurrent issues (until you let the GnuPG's scdaemon into > the round) with all the cards I have around, but mostly with PIV on > yubikey. That's good. I'll test again as soon as I find my reader... Were you able to authenticato to a site from FF and then sign a mail from TB w/o closing FF? That's great! > I believe you should give it a try again. You might be pleasantly > surprised (unless the MyEID cards have some different issues than my > cards). I doubt. Mine are quite old, some contact-only and some dual interface, IIRC. But all single applet. > The scdaemon could be replaced with a tool that does not require > exclusive access and talks PKCS#11, such as gnupg-pkcs11-scd [1] and > then we should be over these problems. I remember trying it but IIRC it was quite underdocumented. Hope that changed too :) > Yes, some of the configuration steps should be more explicit > (disconnect = leave), and we should support both applets on the smart > card (PIV, OpenPGP) on yubikey [2] to make it working setup for general > users. But I would not say it is impossible nor that we are far. Well, multi-applet cards are a very different beast... Tks for trying! BYtE, Diego |