<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=3&amp;t=484" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2012-03-06T11:06:00+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=3&amp;t=484</id>
<entry>
<author><name><![CDATA[Anonymous]]></name></author>
<updated>2012-03-06T11:06:00+01:00</updated>
<published>2012-03-06T11:06:00+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=484&amp;p=2952#p2952</id>
<link href="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2952#p2952"/>
<title type="html"><![CDATA[Re: c#.net yubicoClient question]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2952#p2952"><![CDATA[
You are basically right, but supporting signing the request even when SSL is used has the advantage of letting the server identify the client.<br /><br />YubiCloud currently does not make use of this, but it could become important in the future to mitigate DoS attacks against the service.<br /><br />Also, using HMAC signatures to validate the servers response could perhaps feel better than trusting your typical list of 100+ trusted SSL CAs. Not that you would necessarily be using such a list for validating the YubiCloud servers SSL certificates, but...<br /><br />/Fredrik<p>Statistics: Posted by Guest — Tue Mar 06, 2012 11:06 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[bwong]]></name></author>
<updated>2012-01-20T19:54:46+01:00</updated>
<published>2012-01-20T19:54:46+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=484&amp;p=2902#p2902</id>
<link href="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2902#p2902"/>
<title type="html"><![CDATA[Re: c#.net yubicoClient question]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2902#p2902"><![CDATA[
I'm confused is the generated Client ID the AuthID?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1941">bwong</a> — Fri Jan 20, 2012 7:54 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[darkfader]]></name></author>
<updated>2010-06-22T00:17:27+01:00</updated>
<published>2010-06-22T00:17:27+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=484&amp;p=2256#p2256</id>
<link href="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2256#p2256"/>
<title type="html"><![CDATA[Re: c#.net yubicoClient question]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2256#p2256"><![CDATA[
https instead of hmac verificiation is secure enough and more easy.<br />But anyway, check <a href="http://code.google.com/p/yubico-dot-net-client/issues/detail?id=1" class="postlink">this attachment</a> for some hmac verification code I wrote quickly if you want to implement it anyway.<br />Just make sure the API key is securely stored on your server! There is no way telling if someone forged an 'OK' status if they aquired this key.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1185">darkfader</a> — Tue Jun 22, 2010 12:17 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[crash893]]></name></author>
<updated>2010-03-02T15:47:39+01:00</updated>
<published>2010-03-02T15:47:39+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=484&amp;p=2090#p2090</id>
<link href="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2090#p2090"/>
<title type="html"><![CDATA[Re: c#.net yubicoClient question]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2090#p2090"><![CDATA[
.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1060">crash893</a> — Tue Mar 02, 2010 3:47 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[crash893]]></name></author>
<updated>2010-03-02T15:48:34+01:00</updated>
<published>2010-02-26T21:13:45+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=484&amp;p=2084#p2084</id>
<link href="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2084#p2084"/>
<title type="html"><![CDATA[Re: c#.net yubicoClient question]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2084#p2084"><![CDATA[
.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1060">crash893</a> — Fri Feb 26, 2010 9:13 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[crash893]]></name></author>
<updated>2010-02-25T19:55:07+01:00</updated>
<published>2010-02-25T19:55:07+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=484&amp;p=2083#p2083</id>
<link href="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2083#p2083"/>
<title type="html"><![CDATA[Re: c#.net yubicoClient question]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2083#p2083"><![CDATA[
bump<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1060">crash893</a> — Thu Feb 25, 2010 7:55 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[network-marvels]]></name></author>
<updated>2010-02-24T06:48:38+01:00</updated>
<published>2010-02-24T06:48:38+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=484&amp;p=2078#p2078</id>
<link href="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2078#p2078"/>
<title type="html"><![CDATA[Re: c#.net yubicoClient question]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2078#p2078"><![CDATA[
Checking the hash is optional. However, Yubico recommend all production deployments use either API key or HTTPS to secure the OTP validation communication.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=280">network-marvels</a> — Wed Feb 24, 2010 6:48 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[crash893]]></name></author>
<updated>2010-02-23T17:15:35+01:00</updated>
<published>2010-02-23T17:15:35+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=484&amp;p=2072#p2072</id>
<link href="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2072#p2072"/>
<title type="html"><![CDATA[Re: c#.net yubicoClient question]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2072#p2072"><![CDATA[
I'm still working on this but am i to understand correctly that checking the hash is not nesscary from a security point of view if the api url is just switched to https?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1060">crash893</a> — Tue Feb 23, 2010 5:15 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[network-marvels]]></name></author>
<updated>2010-02-22T10:45:31+01:00</updated>
<published>2010-02-22T10:45:31+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=484&amp;p=2065#p2065</id>
<link href="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2065#p2065"/>
<title type="html"><![CDATA[Re: c#.net yubicoClient question]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2065#p2065"><![CDATA[
We are assuming that you are asking about how to generate the HMAC HASH i.e h parameter at client side and compare it with the h parameter sent as a response from the OTP validation server.<br /><br />The instructions for generating and comparing the h parameter is available at the following links:<br /><br /><!-- m --><a class="postlink" href="http://www.yubico.com/developers/api/#generate_sig">http://www.yubico.com/developers/api/#generate_sig</a><!-- m --><br /><br /><!-- m --><a class="postlink" href="http://www.yubico.com/developers/api/">http://www.yubico.com/developers/api/</a><!-- m --> (Protocol Specification section)<br /><br />The t parameter present in OTP validation response is the timestamp in UTC at the server side when the OTP is validated. This parameter is not related with HMAC HASH generation/compare functionality. <br /><br />We hope this helps!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=280">network-marvels</a> — Mon Feb 22, 2010 10:45 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[crash893]]></name></author>
<updated>2010-02-19T23:39:31+01:00</updated>
<published>2010-02-19T23:39:31+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=484&amp;p=2059#p2059</id>
<link href="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2059#p2059"/>
<title type="html"><![CDATA[Re: c#.net yubicoClient question]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2059#p2059"><![CDATA[
so basically<br /><br />My api key (the long string) + the returned H value should combine in some fashion to return my auth-id code?<br /><br /><br />what about t= do i need to know anything about that?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1060">crash893</a> — Fri Feb 19, 2010 11:39 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[crash893]]></name></author>
<updated>2010-02-19T22:56:16+01:00</updated>
<published>2010-02-19T22:56:16+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=484&amp;p=2058#p2058</id>
<link href="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2058#p2058"/>
<title type="html"><![CDATA[Re: c#.net yubicoClient question]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2058#p2058"><![CDATA[
cool<br /><br />thanks the c# example does not implement this feature I will look into it and see if i can implement it.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1060">crash893</a> — Fri Feb 19, 2010 10:56 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[network-marvels]]></name></author>
<updated>2010-02-19T10:26:46+01:00</updated>
<published>2010-02-19T10:26:46+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=484&amp;p=2053#p2053</id>
<link href="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2053#p2053"/>
<title type="html"><![CDATA[Re: c#.net yubicoClient question]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2053#p2053"><![CDATA[
Please find answers to your questions as follows:<br /><br />1) what does the auth_id do <br /><br />Answer: <br /><br />There are two ways to secure the OTP validation communication (request and response). The first is to use HTTPS based secure communication channel to exchange the OTP Validation request and response. The other is to authenticate the request and response with (an optional) parameter h which is the HMAC SHA1 hash generated using the shared secret Key to sign the OTP validation request and response message.<br /><br />Using this h parameter, a client (i.e. an application/service making the validation request to the Yubico OTP validation server) can be sure that the response is coming from the Yubico OTP validation and has not been tampered.<br /><br />To generate this h parameter a shared secret Key (referred henceforth as API Key) is used. This API Key is associated with an ID (API ID/auth_id) on the Yubico OTP validation server. <br /><br />If the h parameter is present in the OTP validation request, i.e. the client has signed the request using the API Key, then at the OTP validation server the id parameter is used to extract the corresponding API Key from the database and the HMAC SHA1 hash is computed on the OTP validation request. The server generated hash is compared with the h parameter present in the OTP validation request to validate the authenticity of the OTP validation request. <br /><br />Therefore, if you are using the h parameter in the OTP validation request, you need to use your corresponding API ID in the OTP validation request.<br /><br />The OTP validation server always sends the h parameter in the OTP validation response. This h parameter is generated by signing the OTP validation response using the shared secret Key associated with the id in the validation request. At the client side, HMAC SHA1 hash is computed on the OTP validation response using the API Key configured on the client side (the way of configuring this on the client will be client specific). The client generated h parameter is compared with the h parameter present in the OTP validation response to validate the authenticity of the OTP validation response.<br /><br />2) if i made a program that reqired a yubikey would i need to create a individual auth_ID for each one?<br /><br />Answer:<br /><br />You should always use a same API ID for all of your YubiKeys. There is no need to generate a different API ID for each YubiKey. The API ID concept is designed to use an API ID per site / application / service and not per YubiKey.<br /><br />Let’s take an example. You have developed a web application and integrated YubiKey based strong authentication in to your web application. You are using the online Yubico OTP validation server for OTP validation and you want to use the h parameter in the OTP validation request for authenticating the validation requests and responses. Your users are using YubiKey OTP for authentication along with traditional username and password. <br /><br />Now all user authentication requests will be handled by your web application. Your web application will validate the username and password and will send the OTP to the online Yubico OTP validation server by forming the OTP validation requests for every OTP received from the users. Here, your web application acts as a client to the Yubico OTP validation server. <br /><br />As the web application is sending the OTP to the validation server and not the user, there is no need to create separate API ID and API Key for every YubiKey you own. You should create and use only one API ID and API Key pair for all of your YubiKeys. <br /><br />We hope this helps!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=280">network-marvels</a> — Fri Feb 19, 2010 10:26 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[crash893]]></name></author>
<updated>2010-02-18T17:59:50+01:00</updated>
<published>2010-02-18T17:59:50+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=484&amp;p=2052#p2052</id>
<link href="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2052#p2052"/>
<title type="html"><![CDATA[Re: c#.net yubicoClient question]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2052#p2052"><![CDATA[
thanks I got it<br /><br />so new questions arise from this<br /><br /><br />1) what does the auth_id do <br /><br />2) if i made a program that reqired a yubikey would i need to create a individual auth_ID for each one?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1060">crash893</a> — Thu Feb 18, 2010 5:59 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[network-marvels]]></name></author>
<updated>2010-02-18T07:07:26+01:00</updated>
<published>2010-02-18T07:07:26+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=484&amp;p=2049#p2049</id>
<link href="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2049#p2049"/>
<title type="html"><![CDATA[Re: c#.net yubicoClient question]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2049#p2049"><![CDATA[
You can create your own auth_id using the Yubico API Key generator which is available at the link given below:<br /><br /><!-- m --><a class="postlink" href="https://api.yubico.com/get-api-key/">https://api.yubico.com/get-api-key/</a><!-- m --><br /><br />Please provide your E-mail address and YubiKey OTP and click on the &quot;Generate API Key&quot; button. This will generate a new id parameter (which is auth_id) and API Key for your use.<br /><br />We hope this helps!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=280">network-marvels</a> — Thu Feb 18, 2010 7:07 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[crash893]]></name></author>
<updated>2010-02-17T22:32:44+01:00</updated>
<published>2010-02-17T22:32:44+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=484&amp;p=2048#p2048</id>
<link href="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2048#p2048"/>
<title type="html"><![CDATA[Re: c#.net yubicoClient question]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=484&amp;p=2048#p2048"><![CDATA[
I see that it mentions auth_id in the read me but it doesn't explain where that number came from. I apologize if its right in front of me I'm pretty new to all this.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1060">crash893</a> — Wed Feb 17, 2010 10:32 pm</p><hr />
]]></content>
</entry>
</feed>