-
Notifications
You must be signed in to change notification settings - Fork 26
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
When will PIV functionality be stable? #389
Comments
Currently there is no clear roadmap for stabilizing PIV. This is mainly due to the fact that we do not see many requests/users which are interested in this. Another reason is that to fully utilize PIV inside a Windows AD environment we would also need a "MiniDriver" to make best use of it. Currently there is a way to achieve at least PIV based logins on AD clients and we are also improving it currently, but as mentioned before: due to limited demand (at least from what we know) this is not a high priority currently. Please 👍 this comment to increase priority on this functionality... |
Just a vote for the importance to me of PIV. We need this for system login for Linux, macOS, and Windows as well as for VPN. |
Me too ! I vote for the importance to me of PIV. We need this for system login for Linux, macOS, and Windows as well as for VPN. |
If you haven't, please 👍 my comment above so we can collect people who are interested in this feature. Additionally, if possible, could you maybe share some details about your intended use-cases, any of the following questions would be interesting for us:
thanks |
At a company level we have three use cases, list in priority:
No.
Yes.
The only one at the moment is curve 25519 key support. This is something we are exploring.
FOSS tooling based on Linux would be the preferred solution. |
Our use case is basically identical, just with slightly different priorities:
No.
Yes.
ECC, curve 25519 if possible.
As far as I understand, provisioning is already possible with FOSS tooling (just neither easy nor comfortable) if you have the needed master key for the card - this would be enough. |
I would also like to vote for this feature as we want to rollout tokens in our enterprise and would rather not buy yubikeys.
Cert based Authentication and Authorization on different Systems and services and S/MIME.
Not now.
Yes
Support Keys as stated in the FAQ
using nitropy, piv-tool or default cli tools like pkcs11/15 |
I would be interested if you already have an estimate on when the PIV functionality will be considered as stable?
Thanks a lot in advance!
The text was updated successfully, but these errors were encountered: