cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
MKu
Level 7
Report Inappropriate Content
Message 1 of 1

DE: Preboot Authentication: Certificate not found on YubiKey

I have a question regarding the PBA from Drive Encryption:

We are testing a YubiKey with the autoenrollment process for certificates, for our Drive Encryption.

 

For the first certificate thats enrolled on the Yubikey it works fine. The first one gets enrolled into slot 9A (authentification) on the YubiKey. When the autoenrollment process is triggerd, the second certificate gets enrolled into another slot on the Yubikey (9D Key Managment) instead of overwriting the old one.

This seems to be a problem, since the PBA seems not be able to read the certificate from the slot 9D.

If i dont delete the first certificate in solt 9A, it just says correctly that its expired. And if i delete the expired one, the remaining in 9D cannot be read from Drive Encryption.

 

Since we want to automate our process, we need this autoenrollment. Is there an option that i can configure the policy that it also looks in the other slots at Preboot?

Also checked if i can configure the Yubikey that i replaces the certificate in 9a instead of pushing a new one, but unfortunateley i did not find anything.

 

 

 

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community