3 ms·
You'd also need some way to revoke keys signed by the root if a valid hardware key were lost, stolen, or confiscated. I think Yubico will actually do something
by giaour 4y ago
You'd also need some way to revoke keys signed by the root if a valid hardware key were lost, stolen, or confiscated.
I think Yubico will actually do something like this for large enough customers, though revocation is left as an exercise for the customer. When I worked for AWS, I was issued a couple company YubiKeys, and there was a web portal where I could revoke a token's association with my account.