I have a question regarding the PBA from Drive Encryption:
We are testing a YubiKey with the autoenrollment process for certificates, for our Drive Encryption.
For the first certificate thats enrolled on the Yubikey it works fine. The first one gets enrolled into slot 9A (authentification) on the YubiKey. When the autoenrollment process is triggerd, the second certificate gets enrolled into another slot on the Yubikey (9D Key Managment) instead of overwriting the old one.
This seems to be a problem, since the PBA seems not be able to read the certificate from the slot 9D.
If i dont delete the first certificate in solt 9A, it just says correctly that its expired. And if i delete the expired one, the remaining in 9D cannot be read from Drive Encryption.
Since we want to automate our process, we need this autoenrollment. Is there an option that i can configure the policy that it also looks in the other slots at Preboot?
Also checked if i can configure the Yubikey that i replaces the certificate in 9a instead of pushing a new one, but unfortunateley i did not find anything.