Investigate PIV over the Alcor NFC reader #3

Open
opened 2026-08-20 07:04:11 +00:00 by htayj · 0 comments
htayj commented 2026-08-20 07:04:11 +00:00 (Migrated from github.com)

Idea

PIV is the one YubiKey application that works contactlessly on this
machine's hardware today. Desktop Firefox cannot do NFC WebAuthn (see #2), but
PIV runs over PC/SC, so the Alcor Link AK9567 contactless reader can talk to
the key without plugging it in.

Worth investigating whether that combination is useful for anything concrete,
or whether it stays a curiosity.

Why PIV rather than FIDO2 here

FIDO2 speaks USB HID directly and never touches PC/SC, which is why it works
without pcscd and why NFC WebAuthn is a dead end in Firefox. PIV is the
opposite: smartcard-native, so it reaches the reader over the stack already
running.

PIV FIDO2
Transport PC/SC smartcard USB HID
Works over the Alcor reader yes not for WebAuthn
Credential X.509 cert + private key per-site keypair
Needs a CA yes no

Possible uses to evaluate

  • Client-certificate TLS over NFC (VPN, mTLS APIs, intranet)
  • S/MIME email signing
  • SSH via PKCS#11 as an alternative to ed25519-sk, notably for servers too
    old to support FIDO2
  • Firefox client certs: load
    /home/tay/.guix-home/profile/lib/opensc-pkcs11.so under Settings >
    Privacy & Security > Security Devices. Use the profile path, not a
    /gnu/store path, so it survives a reconfigure.

Realistically none of these are needed right now: there is no CA issuing
certs, and FIDO2 over USB already covers web login. This is speculative.

Current state

PIV applet is empty and entirely on factory defaults:

PIV version:              5.7.4
PIN tries remaining:      3/3
PUK tries remaining:      3/3
Management key algorithm: AES192
WARNING: Using default PIN!
WARNING: Using default PUK!
WARNING: Using default Management key!
CHUID: No data available
CCC:   No data available

Nothing is stored, so the default credentials are not currently an exposure.
They become one the moment a real key or certificate lands in a slot.

If this is ever pursued

  • Change PIN, PUK, and management key first:

    ykman piv access change-pin                                # default 123456
    ykman piv access change-puk                                # default 12345678
    ykman piv access change-management-key --generate --protect
    
    `--generate --protect` stores a random management key on the device
    guarded by the PIN, so there is no third secret to remember.
    
    Retry limits are tight: 3 PIN attempts, then the PUK unblocks it; 3 PUK
    attempts, then the applet is permanently locked and only `ykman piv
    reset` recovers it, wiping keys and certs. Record both in Bitwarden as
    they are set rather than relying on recall.
    
  • Generate a key and self-signed cert in slot 9a and confirm the reader
    sees it contactlessly:

    ykman piv keys generate 9a /tmp/9a.pub
    ykman piv certificates generate 9a /tmp/9a.pub --subject "CN=tay"
    
  • Verify over NFC specifically, not just USB:

    ykman --reader "Alcor Link AK9567 [Contactless" piv info
    
  • Decide whether any real use case justifies keeping it.

Prerequisites already in place

From system generation 14:

  • pcscd running via pcscd-service-type
  • Readers detected: Alcor Link AK9567 00 00, Alcor Link AK9567 [Contactless Card Reader] 01 00, Yubico YubiKey OTP+FIDO+CCID 02 00
  • ykman, opensc, pcsc-tools, yubico-piv-tool in the home profile
  • YubiKey 5C NFC 5.7.4 with PIV enabled over both USB and NFC

Not blocking

Purely exploratory. Nothing depends on it.


Imported from GitHub issue/PR. Originally posted by htayj on 2026-08-20T07:04:11Z.

## Idea PIV is the one YubiKey application that works **contactlessly** on this machine's hardware today. Desktop Firefox cannot do NFC WebAuthn (see #2), but PIV runs over PC/SC, so the Alcor Link AK9567 contactless reader can talk to the key without plugging it in. Worth investigating whether that combination is useful for anything concrete, or whether it stays a curiosity. ## Why PIV rather than FIDO2 here FIDO2 speaks USB HID directly and never touches PC/SC, which is why it works without `pcscd` and why NFC WebAuthn is a dead end in Firefox. PIV is the opposite: smartcard-native, so it reaches the reader over the stack already running. | | PIV | FIDO2 | | --- | --- | --- | | Transport | PC/SC smartcard | USB HID | | Works over the Alcor reader | yes | not for WebAuthn | | Credential | X.509 cert + private key | per-site keypair | | Needs a CA | yes | no | ## Possible uses to evaluate - Client-certificate TLS over NFC (VPN, mTLS APIs, intranet) - S/MIME email signing - SSH via PKCS#11 as an alternative to `ed25519-sk`, notably for servers too old to support FIDO2 - Firefox client certs: load `/home/tay/.guix-home/profile/lib/opensc-pkcs11.so` under Settings > Privacy & Security > Security Devices. Use the profile path, not a `/gnu/store` path, so it survives a reconfigure. Realistically none of these are needed right now: there is no CA issuing certs, and FIDO2 over USB already covers web login. This is speculative. ## Current state PIV applet is empty and entirely on factory defaults: PIV version: 5.7.4 PIN tries remaining: 3/3 PUK tries remaining: 3/3 Management key algorithm: AES192 WARNING: Using default PIN! WARNING: Using default PUK! WARNING: Using default Management key! CHUID: No data available CCC: No data available Nothing is stored, so the default credentials are not currently an exposure. They become one the moment a real key or certificate lands in a slot. ## If this is ever pursued - [ ] Change PIN, PUK, and management key **first**: ykman piv access change-pin # default 123456 ykman piv access change-puk # default 12345678 ykman piv access change-management-key --generate --protect `--generate --protect` stores a random management key on the device guarded by the PIN, so there is no third secret to remember. Retry limits are tight: 3 PIN attempts, then the PUK unblocks it; 3 PUK attempts, then the applet is permanently locked and only `ykman piv reset` recovers it, wiping keys and certs. Record both in Bitwarden as they are set rather than relying on recall. - [ ] Generate a key and self-signed cert in slot 9a and confirm the reader sees it contactlessly: ykman piv keys generate 9a /tmp/9a.pub ykman piv certificates generate 9a /tmp/9a.pub --subject "CN=tay" - [ ] Verify over NFC specifically, not just USB: ykman --reader "Alcor Link AK9567 [Contactless" piv info - [ ] Decide whether any real use case justifies keeping it. ## Prerequisites already in place From system generation 14: - `pcscd` running via `pcscd-service-type` - Readers detected: `Alcor Link AK9567 00 00`, `Alcor Link AK9567 [Contactless Card Reader] 01 00`, `Yubico YubiKey OTP+FIDO+CCID 02 00` - `ykman`, `opensc`, `pcsc-tools`, `yubico-piv-tool` in the home profile - YubiKey 5C NFC 5.7.4 with PIV enabled over both USB and NFC ## Not blocking Purely exploratory. Nothing depends on it. --- Imported from [GitHub issue/PR](https://github.com/htayj/src/issues/3). Originally posted by [htayj](https://github.com/htayj) on 2026-08-20T07:04:11Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/src#3
No description provided.