II. YubiKey Smartcard Setup via Self-Signed Certificate (YubiKey Manager)
Enrollment
The PIN and Management Key will be needed to configure each certificate.
- Go back to Applications and then PIV
- Click on Configure Certificates
Click on Authentication (Slot 9a) and then Generate
Authentication (Slot 9a) and Key Management (Slot 9d) can be used if more than 1 cert is needed (ala -admin)
- Check the radio for Self-signed Certificate and then click Next
- Select RSA2048 and then click on Next
- Input a decent subject text (ala username) and then click on Next
Input a reasonable expiration time
Current implementation does not care about expiration, so have fun with the date.
For example, I chose my expected retirement date (not reflected in the picture below).
- The next page gives you a summary of what you've done. Click Generate whenever you are ready.
- You should then see the certificate in the slot you specified
- Click on Configure Certificates
- Once complete, remove and re-insert the YubiKey for the certificate to be seen (specifically in Windows).