Nitrokey 3A mini not working with pamu2cfg

Hey,

I have the following problem with my new NK 3A Mini. I`m getting an error while trying to create keys for using with PAM via pamu2fcfg:

pamu2fcfg 
Enter PIN for /dev/hidraw0: 
error: fido_cred_verify (-6) FIDO_ERR_INVALID_SIG

I`m also using a NK 3A NFC and it’s working fine. Things I already tried:

  • reset and reconfigure udev rules
  • reset NK and firmware update
  • with and without fido2-PIN set
  • reinstalled and restarted the underlying services and libs (libfido2, pam-u2f, pcscd, etc.)

I have absolutely no idea why it is not working. Do you have any further suggestions?

Thanks in advance

EDIT: I tried another machine with a different OS (Fedora instead of Arch) but still the same. NK 3A NFC is recognized and it’s possible to generate keys via pamu2fcfg - NK 3A Mini there is no chance. Same Error as mentioned above. Maybe the key is broken?

There was a similar bug report for the 3AM, not sure if it was fixed or a new one.
You updated the key to the latest firmware version?

Thanks for the hint @ion Both devices are on firmware 1.8.1 (latest as reported by nitropy). The 3AM interacts well with gpg (i.e. “gpg --card-edit”) and is recognized by KeepassXC. The bug is only in combination with pamu2fcfg. Any other suggestions?

Hello, please write to support@nitrokey.com