This document summarizes troubleshooting findings regarding repeated PIN prompts, smartcard session resets, and FIDO2 vs OpenPGP key workflows when using a YubiKey on Linux (NixOS).
When using a YubiKey for GnuPG (pass, GPG commit signing, or SSH via gpg-agent):
scdaemon and pcscd Conflicting Driversdisable-ccid / pcsc-shared AND shared-access in ~/.gnupg/scdaemon.conf breaks scdaemon with No SmartCard daemon.disable-ccid and pcsc-shared in scdaemon.conf so scdaemon routes card access through the system pcscd service without breaking parser options.card-timeout 1 in scdaemon.conf closes the smartcard hardware connection 1 second after every GPG operation.gpg-agent. Do not set short card-timeout values if PIN caching is desired.forcesig SettingSignature PIN is set to forced on the OpenPGP card (visible via gpg --card-status), the YubiKey hardware enforces fresh PIN entry for every signature operation (git commit / git push) regardless of gpg-agent cache configuration.forcesig off via gpg --card-edit -> admin -> forcesig.UIF) Hardware RequirementOn (fixed) (visible via ykman openpgp info), the OpenPGP card standard v2.1 chip specification ties PIN verification 1:1 to every hardware touch/signature request.gpg-agent cannot cache the PIN across operations when OpenPGP Touch is enabled; the card firmware demands fresh PIN authentication before accepting physical touch for each operation.To achieve "Physical Touch per action, but PIN typed only once per session", standard SSH FIDO2 keys (ed25519-sk or ecdsa-sk) are preferred over OpenPGP SSH emulation.
ed25519-sk: Requires YubiKey firmware 5.2.3 or higher. Attempting enrollment on older firmware yields: Key enrollment failed: requested feature not supported.ecdsa-sk (NIST P-256): Supported on all YubiKey 5 series firmware (including version 5.1.2). Provides 128-bit cryptographic security equivalent to Ed25519, backed by hardware side-channel protection.ecdsa-sk SSH key:
ssh-keygen -t ecdsa-sk -C "yubikey-titan"
~/.ssh/config to use the explicit identity:
Host github.com
IdentityFile ~/.ssh/id_ecdsa_sk
IdentitiesOnly yes
id_ecdsa_sk.pub on GitHub. Outgoing Git pushes will trigger a green touch prompt on the YubiKey without demanding GPG PIN re-entry.