Nitrokey Support - Latest posts https://support.nitrokey.com Latest posts NK 3 fails after factory reset Yes, thanks you for that classification

]]>
https://support.nitrokey.com/t/nk-3-fails-after-factory-reset/7520#post_11 Tue, 17 Mar 2026 13:17:12 +0000 support.nitrokey.com-post-21992
Nextbox nicht erreichbar, Server läuft Der Beitrag klingt sehr ähnlich: NextBox nicht mehr von außen erreichbar

Schau da auch mal vorbei.

]]>
https://support.nitrokey.com/t/nextbox-nicht-erreichbar-server-lauft/7512#post_4 Tue, 17 Mar 2026 12:41:55 +0000 support.nitrokey.com-post-21991
Nextbox nicht erreichbar, Server läuft Hi,

Hast du ipv6?

Ich habe einen Full DualStack, dh . Ipv6 und Ipv4 internetzugang und hatte das Problem auch gelegentlich. Habe festgestellt, dass ipv4 teilweise ausgefallen war und dann ipv6 benutzt wurde. Da ipv6 derzeit anscheinend nicht funktioniert führte dies bei mir auch zu ausfällen von bis zu 24h.Dann wurde die IPv4 Adresse erneuert. Habe dann meine dynDNS Konfiguration überarbeitet (verwende eine custom ddclient config)

Vielleicht hilft es erstmal nur ipv4 einzustellen.

Grüße,

Thamos

]]>
https://support.nitrokey.com/t/nextbox-nicht-erreichbar-server-lauft/7512#post_3 Tue, 17 Mar 2026 12:36:28 +0000 support.nitrokey.com-post-21990
NK 3 fails after factory reset my bad yes you are right.

]]>
https://support.nitrokey.com/t/nk-3-fails-after-factory-reset/7520#post_10 Tue, 17 Mar 2026 12:15:39 +0000 support.nitrokey.com-post-21989
NK 3 fails after factory reset Please note that I was referring to “nitropy fido2 status” not working on the NK3.

It’s clear that “nitropy fido2 reset” works on the NK3. MRafael even confirmed that “nitropy fido2 reset” worked after I explained that touching the Nitrokey is required.

]]>
https://support.nitrokey.com/t/nk-3-fails-after-factory-reset/7520#post_9 Tue, 17 Mar 2026 11:58:09 +0000 support.nitrokey.com-post-21988
NK 3 fails after factory reset No this is also working with the NK3.

I just tried on my side and it worked.

Even without sudo it worked.

What you need to make sure is to unplug and replug the Nitrokey just before entering "y” when it ask:

Warning: Your credentials will be lost!!! continue? [(y)es/(n)o]: y

Then you need to touch your Nitrokey and then the reset is done.

]]>
https://support.nitrokey.com/t/nk-3-fails-after-factory-reset/7520#post_8 Tue, 17 Mar 2026 09:46:48 +0000 support.nitrokey.com-post-21986
Nextbox interner Serverfehler, client offline Hi,

Ich hatte den Fehler bei mir auch. Ich konnte den Fehler über ssh beheben.

Ich würde mal den softreset versuchen Soft Reset - Nitrokey Documentation

Aber aufpassen: nicht zu lange drücken.

2-5 Stunden Zeit haben auch schon wunder gewirkt (auch nach dem Softreset nochmal)

Ansonsten kann ich dir nochmal detaillierter erklären, wie ich es hier gelöst habe. Geht aber nur, wenn du bereits einen SSH Zugang eingerichtet hattest.

Grüße,

Thamos

]]>
https://support.nitrokey.com/t/nextbox-interner-serverfehler-client-offline/7530#post_2 Mon, 16 Mar 2026 21:03:54 +0000 support.nitrokey.com-post-21985
Nk3 update v1.8.2 -> v1.8.3 unhandled exception nitropy nk3 update /home/XXXXX/Hämtningar/firmware-nk3am-nrf52-v1.8.3.zip

You have to use the Zip file to do this, i did it 2 days ago….

]]>
https://support.nitrokey.com/t/nk3-update-v1-8-2-v1-8-3-unhandled-exception/7483#post_3 Mon, 16 Mar 2026 15:46:57 +0000 support.nitrokey.com-post-21984
Error returned by C_GetOperationState Hi, I want to create a signing request and sign it with Nitrokey USB-HSM with openssl3. Creating, signing and verification works fine, but during the process I get an error. Is this important? How to fix it?

Sign the certificate? [y/n]:y
2030F391FFFF0000:error:40800054:pkcs11:p11prov_GetOperationState:reason(84):/usr/src/debug/pkcs11-provider/0.5/src/interface.gen.c:335:Error returned by C_GetOperationState

]]>
https://support.nitrokey.com/t/error-returned-by-c-getoperationstate/7531#post_1 Mon, 16 Mar 2026 10:52:38 +0000 support.nitrokey.com-post-21983
NitroPad T430: No Xorg since Debian 13 with Kernel 6.12, intel_iommu, grub-coreboot, heads If your Heads version is 1.4.2 and is maximized then you should be able to update it internally to v2.5.0.

You can follow this guide:

]]>
https://support.nitrokey.com/t/nitropad-t430-no-xorg-since-debian-13-with-kernel-6-12-intel-iommu-grub-coreboot-heads/7505#post_4 Mon, 16 Mar 2026 10:03:18 +0000 support.nitrokey.com-post-21982
Nextbox interner Serverfehler, client offline Guten Morgen,

weiß jemand, was hier zu tun ist?

Ich nutze die nextbox selten über den Browser, wollte das mal wieder ausprobieren und bekomme folgende Fehlermeldung:

Außerdem ist der client offline und ich kann mich auch nicht anmelden (es passiert nichts, wenn ich auf anmelden klicke).

Die LED ist lila und daher ist die nextbox im Wartungsmodus - heißt es also nur abwarten und ich habe zufällig einen doofen Zeitpunkt erwischt?

Was muss ich tun? Weiß das jemand? Da ich vorher nichts aktiv verändert habe, sehe ich hier keinen Ansatzpunkt für mich.

Vielen Dank im Voraus…

Sazz

]]>
https://support.nitrokey.com/t/nextbox-interner-serverfehler-client-offline/7530#post_1 Mon, 16 Mar 2026 07:56:39 +0000 support.nitrokey.com-post-21981
Nitrokey 3C NFC fails generating key or unlocking when used on a different VM than sys-usb It’s working now. I’m not sure why it didn’t work earlier.

Thank you!

]]>
https://support.nitrokey.com/t/nitrokey-3c-nfc-fails-generating-key-or-unlocking-when-used-on-a-different-vm-than-sys-usb/7521#post_3 Mon, 16 Mar 2026 03:53:32 +0000 support.nitrokey.com-post-21980
Obtain serial number on the command line for unlocking keepassxc Try this command, it prints Nitrokey 3 serials in some kinds of representation:

nitropy list 2>&1 | grep “/dev/hidraw.\*: Nitrokey 3” | awk -Wnon-decimal-data ’ { printf “%s\\n%d\\n%s\\n%d\\n”,$4,“0x” $4,substr($4,1,8),“0x” substr($4,1,8) } ’

]]>
https://support.nitrokey.com/t/obtain-serial-number-on-the-command-line-for-unlocking-keepassxc/7510#post_3 Sun, 15 Mar 2026 23:39:24 +0000 support.nitrokey.com-post-21979
Cannot install any OS Hello, i would suggest boot from Live system and install Gparted then do an erase of everything on the disk soo it becomes clean.

You have to install gparted in the live system for it work.

Start there…

]]>
https://support.nitrokey.com/t/cannot-install-any-os/7487#post_9 Sun, 15 Mar 2026 22:34:23 +0000 support.nitrokey.com-post-21978
Nitrokey 3C NFC bent Thank you! You have shown me how I was thinking in a way that introduced complications that simply do not exist. Your reminder that there is no need to sync PINs got me thinking more clearly about how I am using this hardware.

]]>
https://support.nitrokey.com/t/nitrokey-3c-nfc-bent/7522#post_3 Sun, 15 Mar 2026 20:49:12 +0000 support.nitrokey.com-post-21976
NK 3 fails after factory reset
MRafael:

nitropy fido2 status
Command line tool to interact with Nitrokey devices 0.11.3
Warning: This command only works with the Nitrokey FIDO2, not with other FIDO2
devices!
Critical error:
An unhandled exception occurred
Exception encountered: NoSoloFoundError(‘no Nitrokey FIDO2 found’)

That’s the same for me with a Nitrokey 3. I guess – as the command already says – it “only works with the Nitrokey FIDO2”, and thus not with the NK3. Try setting up your PIN and credentials using your web browser now.

Or try nitropy fido2 list-credentials or nitropy fido2 get-info.

]]>
https://support.nitrokey.com/t/nk-3-fails-after-factory-reset/7520#post_7 Sun, 15 Mar 2026 09:09:49 +0000 support.nitrokey.com-post-21971
NK 3 fails after factory reset Thanks you. This was helpful - but not quite right
nitropy fido2 reset has worked successfully
mr@fedora:~$ nitropy fido2 reset
Command line tool to interact with Nitrokey devices 0.11.3
Reset is only possible within 10secs after plugging in the device.
Please (re-)plug in your Nitrokey FIDO2 now!
Warning: Your credentials will be lost!!! continue? [(y)es/(n)o]: y
choosing: yes
Press key to confirm – again, your credentials will be lost!!!
…aaaand they’re gone

But ymr@fedora:~$ nitropy fido2 status
Command line tool to interact with Nitrokey devices 0.11.3
Warning: This command only works with the Nitrokey FIDO2, not with other FIDO2
devices!
Critical error:
An unhandled exception occurred
Exception encountered: NoSoloFoundError(‘no Nitrokey FIDO2 found’)

(Attachment nitropy-20260315T075827-xde8bosf.log is missing)

]]>
https://support.nitrokey.com/t/nk-3-fails-after-factory-reset/7520#post_6 Sat, 14 Mar 2026 22:25:02 +0000 support.nitrokey.com-post-21970
Nitrokey 3C NFC bent You may still be able to salvage it carefully, but that does look bad indeed.

Regarding your question, I’m not aware of a documentation covering it. The concept of using and setting up a backup token depends on what features you use on it. In general you can say that for

  • anything regarding FIDO2/passkeys: You create/register credentials for the backup the same way as you did for the primary. So, for the broken token you can simply create additional new credentials on a replacement token, while using your backup token to login.
    • An exception is if you use the FIDO2 HMAC-SECRET extension, which can be setup on multiple tokens with a shared secret. This is a type of secret an application like KeepassXC uses, for example. If you use it but don’t have the secret used for setup anymore, the feasible way-out is to use your backup token and export the respective application data safely (keypassxc example). Then re-create with a new (again safely setup secret).
    • A similar exception are older FIDO U2F secrets, e.g. often used to use a token to login on Linux. You would simply add a new U2F secret for the new token where used.
  • HOTP/TOTP: you create new ones with the services, or device used. If you use HOTP with a Heads Nitropad, you need to reset it with the new (backup) token and rely on the TOTP secret meanwhile.
  • Password safe: you need to manually duplicate the credentials for/from the/a backup. There is no functionality to import a list of password secrets to a new token, or export a list from a token.
  • GPG: If you imported the secrets to the two tokens initially, you can simply redo that with a new token. If you did not import (but generated them on-device), you won’t have a backup since you cannot export secrets. In this case you create new ones and revoke the old ones (to keep it simple).

Depending on what you use and what you re-setup, the final step is to purge secrets linked to the broken token. So, for the FIDO2 secrets you need to identify the ones from the broken token and delete them where they are registered. Theoretically, you could just physically destroy the token, but you might not want to lose overview which credentials are active and obsolete over time. Some services allow you to name secrets (e.g. nitrokey 1, nitrokey 2) or add a comment (e.g. ssh -C “nitrokey 1”), that makes it easier.

Also good to keep in mind: the different PINs you use are token specific, i.e. there is no need to sync any PIN between primary and backup. It is perfectly feasible to have different (e.g. more complex) PIN on the backup token (since you usually store that out of sight). Once you need to use it, you can change PINs to what you consider feasible and secure enough for every day use.

]]>
https://support.nitrokey.com/t/nitrokey-3c-nfc-bent/7522#post_2 Sat, 14 Mar 2026 21:09:08 +0000 support.nitrokey.com-post-21969
Nextcloud-Warnung Falsches Zeilenformat Hallo,
In der Administrator Übersicht bekomme ich folgende Einrichtungswarnung:

falsches Zeilenformat in Ihrer Datenbank gefunden. ROW_FORMAT=Dynamic bietet die beste Datenbankleistung für Nextcloud. Bitte aktualisieren Sie das Zeilenformat in der folgenden Liste: oc_talk_bridges, oc_notes_meta, oc_circles_event,…. lange Liste

Ist geplant, dass sich die Nextbox-(App/Deamon) irgendwann darum kümmert? Oder kann das mit occ irgendwie automatisch gelöst werden?
Der Dokumentationslink, der an der Fehlermeldung angebracht ist führt direkt zur Datenbankdokumentation (InnoDB). So richtig hilft die nicht weiter.
Ich habe den Eindruck, das ist nicht so einfach zu lösen. Die Dokumentation liest sich, als hätte das eigentlich sowieso bereits als “dynamic” angelegt werden müssen, und ich frage mich ob es absichtlich anders ist.

Weiß hier jemand etwas zu?

Grüße,

Thamos

]]>
https://support.nitrokey.com/t/nextcloud-warnung-falsches-zeilenformat/7527#post_1 Sat, 14 Mar 2026 14:25:33 +0000 support.nitrokey.com-post-21968
Browser-Aktualisierung deaktiviert Habt ihr ssh zugang? Falls ja, würde ich für den Anfang dort mal neu starten: sudo shutdown -r now

Ansonsten wäre interessant, welche Version ihr von der Nextcloud jetzt drauf habt. Bei mir ging gestern auch das Update von Version 31.0.12 auf 31.0.14 schief. Die installierten Versionen kann man in ssh mit sudo docker image ls sehen.

]]>
https://support.nitrokey.com/t/browser-aktualisierung-deaktiviert/7525#post_3 Sat, 14 Mar 2026 14:07:14 +0000 support.nitrokey.com-post-21967
NK 3 fails after factory reset Thank you for your response
I didnot touch the key.
I will try again

]]>
https://support.nitrokey.com/t/nk-3-fails-after-factory-reset/7520#post_5 Sat, 14 Mar 2026 13:43:38 +0000 support.nitrokey.com-post-21966
NK 3 fails after factory reset USER_ACTION_TIMEOUT makes me wonder whether the Nitrokey wants your confirmation via touch to perform the reset. Did you try touching the touch “button” of your NK3?

]]>
https://support.nitrokey.com/t/nk-3-fails-after-factory-reset/7520#post_4 Sat, 14 Mar 2026 13:30:26 +0000 support.nitrokey.com-post-21965
'Interner Serverfehler' since Update i think i made a little progress: Even occ got me an exception. the message said something about custom_apps/spreed/… . So i moved the spreed folder to spreed.broken. Now php occ apps:list is working again. It lists me the spreed.broken app as disabled (as i would expect.) Somehow spreed got installed by itself again, it is now listed as active again with working occ.

Now the Nextcloud was in maintenance mode. After an hour time, looking into the logs, the problem solved itself :slight_smile: now.

(PS, i used the ssh access and worked inside the docker image.)

]]>
https://support.nitrokey.com/t/interner-serverfehler-since-update/7523#post_2 Sat, 14 Mar 2026 13:25:39 +0000 support.nitrokey.com-post-21964
Browser-Aktualisierung deaktiviert Ich habe dieses Problem ebenfalls.

Die offizielle Nextcloud-App auf meinem Telefon sagt: “ Server befindet sich im Wartungsmodus”

Die LED ist aber grün und nicht Lila. Entsprechend hat das einmalige betätigen des Reset-Buttons auch nichts bewirkt.

]]>
https://support.nitrokey.com/t/browser-aktualisierung-deaktiviert/7525#post_2 Sat, 14 Mar 2026 10:51:42 +0000 support.nitrokey.com-post-21963
NK 3 fails after factory reset Hello and thank you for your email

First suggestion to rub with sudo does not work as below

mr@fedora:~$ sudo ~/.local/bin/nitropy fido2 reset
Command line tool to interact with Nitrokey devices 0.11.3
THIS COMMAND SHOULD NOT BE RUN AS ROOT!

Please install udev rules and run nitropy as regular user (without sudo).
We suggest using: https://raw.githubusercontent.com/Nitrokey/libnitrokey/master/data/41-nitrokey.rules
For more information, see: https://docs.nitrokey.com/software/nitropy/linux/udev.html

Set ALLOW_ROOT=1 environment variable to disable this warning.

Reset is only possible within 10secs after plugging in the device.
Please (re-)plug in your Nitrokey FIDO2 now!
Warning: Your credentials will be lost!!! continue? [(y)es/(n)o]: y
choosing: yes
Press key to confirm – again, your credentials will be lost!!!

y
Critical error:
Reset failed (CTAP error: 0x2F - USER_ACTION_TIMEOUT)
Did you confirm with a key-press 10secs after plugging in?
Please re-try…

]]>
https://support.nitrokey.com/t/nk-3-fails-after-factory-reset/7520#post_3 Sat, 14 Mar 2026 10:41:02 +0000 support.nitrokey.com-post-21962
NitroPad T430: No Xorg since Debian 13 with Kernel 6.12, intel_iommu, grub-coreboot, heads

Do you have the update feature in your Heads menu?

Yes.

If your current version is maximized then you should be able to internally update it.

In Heads the “System Info” shows that the NitroPad has the “maximized” Firmware v1.4:
Nitropad T430 (maximized)".
FW_VER: CBET4000 Heads-v1.4-2-g9…

Do I need an external flasher to update to the newest “maximized” Heads firmware v2.5?
If this would be the case: Can I update internally from a maximized firmware (without an external flasher) to the newest legacy Heads firmware V2.1?

The NitroPad T430 is my every day Notebook for work - so I have to be sure to not brick it.

]]>
https://support.nitrokey.com/t/nitropad-t430-no-xorg-since-debian-13-with-kernel-6-12-intel-iommu-grub-coreboot-heads/7505#post_3 Sat, 14 Mar 2026 07:37:38 +0000 support.nitrokey.com-post-21961
Browser-Aktualisierung deaktiviert “Aktualisierung erforderlich

Bitte den Kommandozeilen-Updater verwenden, die Browser-Aktualisierung ist in der config.php deaktiviert.”

Das bekomme ich jetzt angezeigt, wenn ich über Firefox auf die NextBox zugreifen will.

Ich arbeite seit ein paar Monaten auf einem Linux-Rechner von Tuxedo und bin noch nicht so sicher in der Kommandozeile - will da nichts falsch machen. Und die Dokumentation von Nextcloud hat da jetzt auch keinen erhellenden Eintrag geliefert. Gibt es dazu hier einen hilfreichen Ratschlag?

]]>
https://support.nitrokey.com/t/browser-aktualisierung-deaktiviert/7525#post_1 Fri, 13 Mar 2026 20:26:59 +0000 support.nitrokey.com-post-21959
'Interner Serverfehler' since Update Hi,

Today at 12:35 my Nextbox started to upgrade Nextcloud.

Since then I get the error, when I try to open the nextbox website. All connecting apps give me an http 500 error, too.

What I tried already:

Reboot of the nextbox

I have ssh access. But i did nothing special there. I noticed the admin page was complaining about some column format, but think this has nothing to do with the problem.

Is this update error already known, is nitrokey working on this?

I may send some logs, if you say which ones you need.

Regards, Thamos

]]>
https://support.nitrokey.com/t/interner-serverfehler-since-update/7523#post_1 Fri, 13 Mar 2026 14:53:20 +0000 support.nitrokey.com-post-21957
Nitrokey 3C NFC bent My laptop fell from table height on to my primary Nitrokey 3C NFC in the USB-C port. It got pretty badly bent and will no longer fit back into the port because the shape is wrong.

I still have my secondary. But I don’t understand the concept of buying a new one and making that my new primary. (Or using my secondary as my primary and making the new one my secondary once it arrives.) Is there documentation on this procedure? I’ve gotten very confused.

]]>
https://support.nitrokey.com/t/nitrokey-3c-nfc-bent/7522#post_1 Fri, 13 Mar 2026 14:09:22 +0000 support.nitrokey.com-post-21956
Nitrokey 3C NFC fails generating key or unlocking when used on a different VM than sys-usb Hello, I just tried on QubesOS and it works when my NK3 is attached to the qube.

On your same qube are you able to make your Nitrokey work with https://webauthn.io/ ?

Additionally what is your Nitrokey firmware version?

]]>
https://support.nitrokey.com/t/nitrokey-3c-nfc-fails-generating-key-or-unlocking-when-used-on-a-different-vm-than-sys-usb/7521#post_2 Fri, 13 Mar 2026 12:03:54 +0000 support.nitrokey.com-post-21955
NK 3 fails after factory reset Hello, as explained here:

it requires admin rights if you did not do the cmd with sudo could you then try.

And also you could try the reset with chromium based browser.

]]>
https://support.nitrokey.com/t/nk-3-fails-after-factory-reset/7520#post_2 Fri, 13 Mar 2026 11:58:47 +0000 support.nitrokey.com-post-21954
Nitrokey 3C NFC fails generating key or unlocking when used on a different VM than sys-usb Please help me debug this.

I’m trying to use https://confer.to in an AppVM in Qubes OS with Brave Browser.

I can only make it work on sys-usb.

When I try to use it in another VM, I connect to Confer.to with Brave Browser, Nitrokey 3C starts bliking blue, and after I touch it, I get this message:

```
Your device can’t be used with this site
confer.to might require a newer or different kind of device
```

]]>
https://support.nitrokey.com/t/nitrokey-3c-nfc-fails-generating-key-or-unlocking-when-used-on-a-different-vm-than-sys-usb/7521#post_1 Fri, 13 Mar 2026 07:09:51 +0000 support.nitrokey.com-post-21953
NK 3 fails after factory reset I am running Fedora KDE 43 and attempting to install Nitrokey 3. I have installed rules to /etc/udev/rules.d/, (sudo ls /etc/udev/rules.d/.
41-nitrokey.rules

)

and successfully restarted services.

But I can’t use GUI app or Nitropy CLI to either set or change PINs.

nitropy fido2 reset gives error as cut and pasted fron log file

ymr@fedora:~$ ls /tmp/nitropy-20260313T163416-c1h9d2ul.log

/tmp/nitropy-20260313T163416-c1h9d2ul.log
ymr@fedora:~$ cat /tmp/nitropy-20260313T163416-c1h9d2ul.log
164 INFO pynitrokey.cli Timestamp: 2026-03-13 16:34:16.486146
165 INFO pynitrokey.cli OS: uname_result(system=‘Linux’, node=‘fedora’, release=‘6.19.6-200.fc43.x86_64
‘, version=’#1 SMP PREEMPT_DYNAMIC Thu Mar 5 00:10:35 UTC 2026’, machine=‘x86_64’)
165 INFO pynitrokey.cli Python version: 3.14.3
165 INFO pynitrokey.cli Cli arguments: [‘fido2’, ‘reset’]
165 INFO pynitrokey.cli pynitrokey version: 0.11.3
166 INFO pynitrokey.cli cryptography version: 46.0.5
166 INFO pynitrokey.cli fido2 version: 2.1.1
166 INFO pynitrokey.cli nethsm version: 2.0.1
167 INFO pynitrokey.cli nitrokey version: 0.4.2
167 INFO pynitrokey.cli pyusb version: 1.3.1
167 DEBUG root print: Reset is only possible within 10secs after plugging in the device.
167 DEBUG root print: Please (re-)plug in your Nitrokey FIDO2 now!
34507 DEBUG root print: choosing: yes
34507 DEBUG root print: Press key to confirm – again, your credentials will be lost!!!
34559 DEBUG fido2.hid.linux Failed opening device /dev/hidraw1
Traceback (most recent call last):
File “/home/ymr/.local/share/pipx/venvs/pynitrokey/lib64/python3.14/site-packages/fido2/hid/linux.py”, line
96, in list_descriptors
devices.append(get_descriptor(hidraw))
~~~~~~~~~~~~~~^^^^^^^^
File “/home/ymr/.local/share/pipx/venvs/pynitrokey/lib64/python3.14/site-packages/fido2/hid/linux.py”, line
53, in get_descriptor
with open(path, “rb”) as f:
~~~~^^^^^^^^^^^^
PermissionError: [Errno 13] Permission denied: ‘/dev/hidraw1’
34560 DEBUG fido2.hid.linux Failed opening device /dev/hidraw0
Traceback (most recent call last):
File “/home/ymr/.local/share/pipx/venvs/pynitrokey/lib64/python3.14/site-packages/fido2/hid/linux.py”, line
96, in list_descriptors
devices.append(get_descriptor(hidraw))
~~~~~~~~~~~~~~^^^^^^^^
File “/home/ymr/.local/share/pipx/venvs/pynitrokey/lib64/python3.14/site-packages/fido2/hid/linux.py”, line
53, in get_descriptor
with open(path, “rb”) as f:
~~~~^^^^^^^^^^^^
PermissionError: [Errno 13] Permission denied: ‘/dev/hidraw0’
34867 DEBUG fido2.hid Got keepalive status: 02
35119 DEBUG fido2.hid Got keepalive status: 02
35366 DEBUG fido2.hid Got keepalive status: 02
35614 DEBUG fido2.hid Got keepalive status: 02
35866 DEBUG fido2.hid Got keepalive status: 02
36114 DEBUG fido2.hid Got keepalive status: 02
36366 DEBUG fido2.hid Got keepalive status: 02
36614 DEBUG fido2.hid Got keepalive status: 02
36862 DEBUG fido2.hid Got keepalive status: 02
37115 DEBUG fido2.hid Got keepalive status: 02
37363 DEBUG fido2.hid Got keepalive status: 02
37615 DEBUG fido2.hid Got keepalive status: 02
37862 DEBUG fido2.hid Got keepalive status: 02
38111 DEBUG fido2.hid Got keepalive status: 02
38363 DEBUG fido2.hid Got keepalive status: 02
38611 DEBUG fido2.hid Got keepalive status: 02
38858 DEBUG fido2.hid Got keepalive status: 02
39111 DEBUG fido2.hid Got keepalive status: 02
39358 DEBUG fido2.hid Got keepalive status: 02
39611 DEBUG fido2.hid Got keepalive status: 02
39858 DEBUG fido2.hid Got keepalive status: 02
40106 DEBUG fido2.hid Got keepalive status: 02
40359 DEBUG fido2.hid Got keepalive status: 02
40607 DEBUG fido2.hid Got keepalive status: 02
40858 DEBUG fido2.hid Got keepalive status: 02
41107 DEBUG fido2.hid Got keepalive status: 01
41355 DEBUG fido2.hid Got keepalive status: 02
41607 DEBUG fido2.hid Got keepalive status: 02
41855 DEBUG fido2.hid Got keepalive status: 02
42103 DEBUG fido2.hid Got keepalive status: 02
42355 DEBUG fido2.hid Got keepalive status: 02
42603 DEBUG fido2.hid Got keepalive status: 02
42855 DEBUG fido2.hid Got keepalive status: 02
43103 DEBUG fido2.hid Got keepalive status: 02
43351 DEBUG fido2.hid Got keepalive status: 02
43603 DEBUG fido2.hid Got keepalive status: 02
43850 DEBUG fido2.hid Got keepalive status: 02
44103 DEBUG fido2.hid Got keepalive status: 02
44351 DEBUG fido2.hid Got keepalive status: 02
44599 DEBUG fido2.hid Got keepalive status: 02
44850 DEBUG fido2.hid Got keepalive status: 02
45099 DEBUG fido2.hid Got keepalive status: 02
45347 DEBUG fido2.hid Got keepalive status: 02
45599 DEBUG fido2.hid Got keepalive status: 02
45846 DEBUG fido2.hid Got keepalive status: 02
46098 DEBUG fido2.hid Got keepalive status: 02
46347 DEBUG fido2.hid Got keepalive status: 02
46595 DEBUG fido2.hid Got keepalive status: 02
46846 DEBUG fido2.hid Got keepalive status: 02
47095 DEBUG fido2.hid Got keepalive status: 02
47347 DEBUG fido2.hid Got keepalive status: 02
47594 DEBUG fido2.hid Got keepalive status: 02
47842 DEBUG fido2.hid Got keepalive status: 02
48095 DEBUG fido2.hid Got keepalive status: 02
48343 DEBUG fido2.hid Got keepalive status: 02
48591 DEBUG fido2.hid Got keepalive status: 02
48842 DEBUG fido2.hid Got keepalive status: 02
49091 DEBUG fido2.hid Got keepalive status: 02
49343 DEBUG fido2.hid Got keepalive status: 02
49591 DEBUG fido2.hid Got keepalive status: 02
49838 DEBUG fido2.hid Got keepalive status: 02
50091 DEBUG fido2.hid Got keepalive status: 02
50339 DEBUG fido2.hid Got keepalive status: 02
50586 DEBUG fido2.hid Got keepalive status: 02
50839 DEBUG fido2.hid Got keepalive status: 02
51087 DEBUG fido2.hid Got keepalive status: 02
51338 DEBUG fido2.hid Got keepalive status: 02
51587 DEBUG fido2.hid Got keepalive status: 02
51834 DEBUG fido2.hid Got keepalive status: 02
52086 DEBUG fido2.hid Got keepalive status: 02
52335 DEBUG fido2.hid Got keepalive status: 02
52583 DEBUG fido2.hid Got keepalive status: 02
52834 DEBUG fido2.hid Got keepalive status: 02
53082 DEBUG fido2.hid Got keepalive status: 02
53335 DEBUG fido2.hid Got keepalive status: 02
53583 DEBUG fido2.hid Got keepalive status: 02
53831 DEBUG fido2.hid Got keepalive status: 02
54082 DEBUG fido2.hid Got keepalive status: 02
54330 DEBUG fido2.hid Got keepalive status: 02
54583 DEBUG fido2.hid Got keepalive status: 02
54831 DEBUG fido2.hid Got keepalive status: 02
55079 DEBUG fido2.hid Got keepalive status: 02
55330 DEBUG fido2.hid Got keepalive status: 02
55578 DEBUG fido2.hid Got keepalive status: 02
55826 DEBUG fido2.hid Got keepalive status: 02
56078 DEBUG fido2.hid Got keepalive status: 02
56326 DEBUG fido2.hid Got keepalive status: 02
56578 DEBUG fido2.hid Got keepalive status: 02
56826 DEBUG fido2.hid Got keepalive status: 02
57075 DEBUG fido2.hid Got keepalive status: 02
57326 DEBUG fido2.hid Got keepalive status: 02
57574 DEBUG fido2.hid Got keepalive status: 02
57827 DEBUG fido2.hid Got keepalive status: 02
58074 DEBUG fido2.hid Got keepalive status: 02
58322 DEBUG fido2.hid Got keepalive status: 02
58575 DEBUG fido2.hid Got keepalive status: 02
58823 DEBUG fido2.hid Got keepalive status: 02
59071 DEBUG fido2.hid Got keepalive status: 02
59322 DEBUG fido2.hid Got keepalive status: 02
59571 DEBUG fido2.hid Got keepalive status: 02
59823 DEBUG fido2.hid Got keepalive status: 02
60071 DEBUG fido2.hid Got keepalive status: 01
60319 DEBUG fido2.hid Got keepalive status: 02
60570 DEBUG fido2.hid Got keepalive status: 02
60819 DEBUG fido2.hid Got keepalive status: 02
61067 DEBUG fido2.hid Got keepalive status: 02
61319 DEBUG fido2.hid Got keepalive status: 02
61567 DEBUG fido2.hid Got keepalive status: 02
61818 DEBUG fido2.hid Got keepalive status: 02
62067 DEBUG fido2.hid Got keepalive status: 02
62315 DEBUG fido2.hid Got keepalive status: 02
62566 DEBUG fido2.hid Got keepalive status: 02
62814 DEBUG fido2.hid Got keepalive status: 02
63062 DEBUG fido2.hid Got keepalive status: 02
63314 DEBUG fido2.hid Got keepalive status: 02
63562 DEBUG fido2.hid Got keepalive status: 02
63815 DEBUG fido2.hid Got keepalive status: 02
64062 DEBUG fido2.hid Got keepalive status: 02
64310 DEBUG fido2.hid Got keepalive status: 02
64562 DEBUG fido2.hid Got keepalive status: 02
64810 DEBUG fido2.hid Got keepalive status: 02
64898 DEBUG root print: Critical error:
64899 DEBUG root print: Reset failed (CTAP error: 0x2F - USER_ACTION_TIMEOUT)
64899 DEBUG root print: Did you confirm with a key-press 10secs after plugging in?
64899 DEBUG root print: Please re-try…
64899 DEBUG root listing all connected devices:
64906 DEBUG root :: ‘Nitrokey FIDO2’ keys
64906 DEBUG root :: ‘Nitrokey Start’ keys:
64935 DEBUG root :: ‘Nitrokey 3’ keys
64970 DEBUG root /dev/hidraw2: Nitrokey 3 2FBBC03B466539589D5F7025C246E0D4
64970 DEBUG root :: ‘Nitrokey Passkey’ keys
64979 DEBUG root print: ----------------------------------------------------------------------------

64979 DEBUG root print: Critical error occurred, exiting now
64979 DEBUG root print: Unexpected? Is this a bug? Would you like to get support/help?
64979 DEBUG root print: - You can report issues at: https://support.nitrokey.com/
64979 DEBUG root print: - Writing an e-mail to [email protected] is also possible
64979 DEBUG root print: - Please attach the log: ‘/tmp/nitropy-20260313T163416-c1h9d2ul.log’ with an
y support/help request!
64979 DEBUG root print: - Please check if you have udev rules installed:

]]>
https://support.nitrokey.com/t/nk-3-fails-after-factory-reset/7520#post_1 Fri, 13 Mar 2026 05:41:09 +0000 support.nitrokey.com-post-21952
Please update the forum software (so one can login with nitrokey) Well, the passkeys are offered in the forum UI here and is broken the same way as meta was broken. Not sure of course if it will work or not once the forum gets updated.

]]>
https://support.nitrokey.com/t/please-update-the-forum-software-so-one-can-login-with-nitrokey/7518#post_3 Wed, 11 Mar 2026 16:58:10 +0000 support.nitrokey.com-post-21951
Please update the forum software (so one can login with nitrokey) Hi, thanks for your message! The Pricing page of Discourse shows no support for the Passkey Support for the “Free” plan. This unfortunately means we won’t be able to offer this right now. Sorry for the inconvenience!

]]>
https://support.nitrokey.com/t/please-update-the-forum-software-so-one-can-login-with-nitrokey/7518#post_2 Wed, 11 Mar 2026 13:32:39 +0000 support.nitrokey.com-post-21950
Nitrokey 3A Mini Touch FAKES the touch action problem solved.

The key was defective indeed. Sh.. happens. Got a replacement which works as expected.

Excellent support :smiley: :smiling_face:

]]>
https://support.nitrokey.com/t/nitrokey-3a-mini-touch-fakes-the-touch-action/7492#post_2 Mon, 09 Mar 2026 21:53:17 +0000 support.nitrokey.com-post-21949
Creating csr on am62x It was no bug, but my fault. If you want to verify the whole chain with openssl3 you have to set the flag “untrusted” on top, otherwise only the last certificate will be checked:
openssl verify -CAfile <path> -untrusted <csr>.pem <csr>.pem

]]>
https://support.nitrokey.com/t/creating-csr-on-am62x/7516#post_10 Mon, 09 Mar 2026 16:34:10 +0000 support.nitrokey.com-post-21948
The passkey registration process either timed out, was cancelled or is not allowed Thanks this will be added in the next update.

]]>
https://support.nitrokey.com/t/the-passkey-registration-process-either-timed-out-was-cancelled-or-is-not-allowed/7091#post_5 Mon, 09 Mar 2026 09:24:04 +0000 support.nitrokey.com-post-21947
Creating csr on am62x Did you already report the XCA bug ?

If not, can you provide me with the details to reproduce the bug ?

Then I will try and report it.

]]>
https://support.nitrokey.com/t/creating-csr-on-am62x/7516#post_9 Sun, 08 Mar 2026 16:04:36 +0000 support.nitrokey.com-post-21946
I sent a security notice For issues related to the SmartCard-HSM / Nitrokey-HSM please send me a private message here or at [email protected].

]]>
https://support.nitrokey.com/t/i-sent-a-security-notice/7519#post_2 Sun, 08 Mar 2026 13:48:47 +0000 support.nitrokey.com-post-21945
I sent a security notice Do you support hackerone bounties?

]]>
https://support.nitrokey.com/t/i-sent-a-security-notice/7519#post_1 Sun, 08 Mar 2026 09:58:34 +0000 support.nitrokey.com-post-21944
Factory Reset: Data Recoverable? That’s unfortunate. My approach is to disassemble the Nextbox and connect the hard drive to a notebook. But I need Linux on the notebook to gain access to the hard drive. So I want a Linux Live USB stick for the notebook, not for the Nextbox, because I don’t have Linux running yet.

]]>
https://support.nitrokey.com/t/factory-reset-data-recoverable/7495#post_4 Sat, 07 Mar 2026 16:51:15 +0000 support.nitrokey.com-post-21943
Malfunctioning factory reset trigger? please confirm someone Yeah, but you don’t know the meaning of the different LED colors without rereading the documentation. But the fact that there is a long press is something you remember. So some less‑experienced user will simply try a long press, without remembering that it may trigger a dangerous full reset. I would say that this is not a good user interface.

In my current case, I don’t know what happened, because my friend didn’t know what was important. So he can’t say how the led was blinking.
I would test the reset trigger myself, but my own Nextbox is in productive use for my family, so I can’t conduct such experiments on it. The Nextbox belonging to my friend has been taken apart for file recovery. In a few weeks, when I’m finished with that, I may test the soft reset.

]]>
https://support.nitrokey.com/t/malfunctioning-factory-reset-trigger-please-confirm-someone/7494#post_3 Sat, 07 Mar 2026 16:45:24 +0000 support.nitrokey.com-post-21942
Please update the forum software (so one can login with nitrokey)
Ok, i got it fixed upstreams. The fixed registration and authentication and took it only on meta.discourse.com is there any way to tag somebody who can update the forum?

just trying to get attention to the forum updated; Couldnt find a better category

]]>
https://support.nitrokey.com/t/please-update-the-forum-software-so-one-can-login-with-nitrokey/7518#post_1 Sat, 07 Mar 2026 11:57:28 +0000 support.nitrokey.com-post-21941
The passkey registration process either timed out, was cancelled or is not allowed Ok, i got it fixed upstreams. The fixed registration and authentication and took it only on meta.discourse.com

is there any way to tag somebody who can update the forum?

]]>
https://support.nitrokey.com/t/the-passkey-registration-process-either-timed-out-was-cancelled-or-is-not-allowed/7091#post_4 Sat, 07 Mar 2026 11:51:49 +0000 support.nitrokey.com-post-21940
How to encrypt second nvme with the same ID? RAID 0 is simple to setup but effectively doubles the risk of data loss if either NVMe drive fails. By using LVM instead, you can add both drives as physical volumes in a pool. you could limit each logical volume so that it is located only on a single NVMe, which reduces the risk if one NVMe would die (only the affected volumes are gone). But as backups should be done anyhow, one could also go with RAID 0 that can double the performance.

]]>
https://support.nitrokey.com/t/how-to-encrypt-second-nvme-with-the-same-id/7497#post_3 Fri, 06 Mar 2026 18:56:42 +0000 support.nitrokey.com-post-21939
Factory Reset: Data Recoverable? Just to say that I tried and failed to get my nextbox to boot from an external usb-stick. It always wanted to boot from the internal card. An AI advised how to fix this but its advice didn’t work.

]]>
https://support.nitrokey.com/t/factory-reset-data-recoverable/7495#post_3 Fri, 06 Mar 2026 16:54:10 +0000 support.nitrokey.com-post-21938
How to encrypt second nvme with the same ID? Hello, the way I would do that is to set a RAID0 with your both drives so it’s seen as one and then it can be encrypted entirely with one passphrase.

]]>
https://support.nitrokey.com/t/how-to-encrypt-second-nvme-with-the-same-id/7497#post_2 Fri, 06 Mar 2026 11:51:39 +0000 support.nitrokey.com-post-21937
Malfunctioning factory reset trigger? please confirm someone Hello, if a factory reset has been perform you should had noticed a red blinking led and a blue blinking for a soft reset.

Also when the button is pressed you can notice it because the led will become solid blue.

]]>
https://support.nitrokey.com/t/malfunctioning-factory-reset-trigger-please-confirm-someone/7494#post_2 Fri, 06 Mar 2026 11:36:55 +0000 support.nitrokey.com-post-21936
Charger Nitropad NV41 Hello, you can also use a USB-C plug to charge your NitroPad NV41.

For the size if I’m not mistaking it should be DC Jack 5.5mm * 2.1-2.5mm.

]]>
https://support.nitrokey.com/t/charger-nitropad-nv41/7489#post_2 Fri, 06 Mar 2026 11:27:55 +0000 support.nitrokey.com-post-21935