Skip to content

Make the firmware version reported by GET VERSION configurable - #48

Open
FlorianFranzen wants to merge 1 commit into
trussed-dev:mainfrom
FlorianFranzen:feat/version-option
Open

FlorianFranzen wants to merge 1 commit into
trussed-dev:mainfrom
FlorianFranzen:feat/version-option

Conversation

@FlorianFranzen

@FlorianFranzen FlorianFranzen commented Oct 6, 2026 •

Copy link
Copy Markdown

Clients gate features on the version reported by the Yubico GET VERSION extension: ykman and yubico-piv-tool assume a 3DES default management key below 5.7 and AES-192 from 5.7 on, GET METADATA is only used from 5.3 on, and yubikey.rs refuses serial retrieval for any major version other than 4 and 5. The hardcoded 6.6.6 therefore locks those clients out entirely; neither an honest 0.x nor a made-up 6.x works.

This exposes the reported version as an Options field so a runner can choose one whose feature set matches what the app implements (with this crate's current feature set, 5.4.0 is a good choice for Yubico-ecosystem deployments). The default stays 6.6.6, so nothing changes without opting in.

Tested in command_response.ron for both a configured version and the default.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant