<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=12&amp;t=81" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2008-11-26T16:47:46+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=12&amp;t=81</id>
<entry>
<author><name><![CDATA[network-marvels]]></name></author>
<updated>2008-11-26T16:47:46+01:00</updated>
<published>2008-11-26T16:47:46+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=81&amp;p=802#p802</id>
<link href="https://forum.yubico.com/viewtopic.php?t=81&amp;p=802#p802"/>
<title type="html"><![CDATA[Re: YubiKey as a strong authentication device for VPN clients]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=81&amp;p=802#p802"><![CDATA[
Please refer below documentation for configuring OpenVPN with two factor authentication using YubiKey:<br /><br /><ul><li> <span style="text-decoration: underline"><strong>About this document:</strong> </span></li></ul><br />The purpose of this document is to guide readers through the configuration steps to use two factor authentication for OpenVPN using YubiKey. This document assumes that the reader has advanced knowledge and experience in Linux system administration, particularly for how PAM authentication mechanism is configured on a Linux platform.<br /><br /><ul><li> <span style="text-decoration: underline"><strong>Prerequisites:</strong> </span></li></ul><br />Successful configuration of the Yubico PAM module to support two factor authentication for OpenVPN has the following prerequisites:<br /><br /><ul>1) Operating System: Any Unix operating system which supports PAM (Pluggable Authentication Module) (<!-- m --><a class="postlink" href="http://www.kernel.org/pub/linux/libs/pam/">http://www.kernel.org/pub/linux/libs/pam/</a><!-- m -->)<br />2) Complier : GNU GCC complier (<!-- m --><a class="postlink" href="http://gcc.gnu.org/">http://gcc.gnu.org/</a><!-- m -->)<br />3) Yubico PAM Module: Yubico PAM Module Version 1.8. It can be downloaded from: <!-- m --><a class="postlink" href="http://code.google.com/p/yubico-pam">http://code.google.com/p/yubico-pam</a><!-- m --><br />4) OpenVPN: OpenVPN Version 2.0.9. It can be downloaded from : <!-- m --><a class="postlink" href="http://openvpn.net/index.php/downloads.html">http://openvpn.net/index.php/downloads.html</a><!-- m --><br />5) FreeRADIUS: FreeRADIUS Version: 1.1.7. It can be downloaded from : <!-- m --><a class="postlink" href="http://freeradius.org/download.html">http://freeradius.org/download.html</a><!-- m --><br />6) Pam_Radius: pam_radius Version 1.3.17. It can be downloaded from : <!-- m --><a class="postlink" href="ftp://ftp.freeradius.org/pub/radius/pam_radius-1.3.17.tar.gz">ftp://ftp.freeradius.org/pub/radius/pam ... .17.tar.gz</a><!-- m --><br /></ul><br /><ul><li> <span style="text-decoration: underline"><strong>Configuration:</strong> </span></li></ul><br />There are two ways OpenVPN can be configured to support two factor authentication with YubiKey.<br /><br /><ul><strong>1) OpenVPN Configuration without FreeRADIUS support:</strong><br />In this mode of configuration, OpenVPN server will be authenticating users by verifying username and user’s password against system password file “/etc/passwd” and verifying OTP (one time password generated from YubiKey) against Yubico’s OTP validation server.  <br /><br />We assume that OpenVPN server is already installed on the server.<br /><br /><ul><strong>1.1) Configuration of OpenVPN server to support PAM authentication:</strong><br /><br /><ul>a) Edit the OpenVPN server configuration file “/etc/openvpn/server.conf” to add the following three lines to enable PAM modules for username and password authentication:<br /><br />plugin &lt;Absolute path of  “openvpn-auth-pam.so” file&gt; &lt;PAM configuration file name for OpenVPN&gt;<br /><br />(For e.g.: <br />plugin /usr/lib/openvpn/plugin/lib/openvpn-auth-pam.so openvpn)<br /><br />client-cert-not-required<br /><br />username-as-common-name<br /><br />b) Edit the OpenVPN client configuration file “/etc/openvpn/client.conf” to add following line to configure OpenVPN client for prompting username and password:<br /><br />auth-user-pass<br /></ul><br /><strong>1.2) Installation of pam_yubico module:</strong><br /><br />Build instructions for pam_yubico are available in the README: <br /><br /><!-- m --><a class="postlink" href="http://code.google.com/p/yubico-c/source/browse/trunk/README">http://code.google.com/p/yubico-c/sourc ... unk/README</a><!-- m --><br /><br /><strong>1.3) Configuration of pam_yubico module:</strong><br /><br /><ul><strong>a) Configuration for user and YubiKey PublicID mapping:</strong><br /><br />There are two ways of user and YubiKey PublicID (token ID) mapping. It can be either done at administrative level or at individual user level.<br /><br /><ul><strong>i) Administrative Level:</strong><br /><br />In Administrative level, system administrators hold right to configure the user and YubiKey PublicID mapping. Administrators can achieve this by creating a new file that contains information about the username and the corresponding PublicIDs of YubiKey(s) assigned. This file contains user name that is allowed to connect to the system using RADIUS and the PublicID of the YubiKey(s) assigned to that particular user. A user can be assigned multiple YubiKeys and this multi key mapping is supported by this file. However, presently there is no logic coded to detect or prevent use of same YubiKey ID for multiple users.<br /> <br />Each record in the file should begin on a new line. The parameters in each record are separated by “:” character similar to /etc/passwd. <br />The contents of this file are as follows:<br /> <br />&lt;user name&gt;:&lt;YubiKey PublicID&gt;:&lt;YubiKey PublicID&gt;: …. <br />&lt;user name&gt;:&lt;YubiKey PublicID &gt;:&lt;YubiKey PublicID&gt;:….. <br /><br />e.g.:<br /> <br />paul:indvnvlcbdre:ldvglinuddek <br />simon:uturrufnjder:hjturefjtehv <br />kurt:ertbhunjimko <br /><br />The mapping file must be created/updated manually before configuration of Yubico PAM module for OpenVPN authentication.<br /><br /><ul><li><strong>Configuration of modified pam_yubico.so module at administrative level:</strong><br /></ul><br />Append the following line to the beginning of /etc/pam.d/radiusd file: <br />auth required pam_yubico.so id=16 debug authfile=&lt;absolute path of the mapping file&gt; <br /><br />After the above configuration changes, whenever a user connects to the server using any RADIUS client, the PAM authentication interface will pass the control to Yubico PAM module. The Yubico PAM module first checks the presence of authfile argument in PAM configuration. If authfile argument is present, it parses the corresponding mapping file and verifies the username with corresponding YubiKey PublicID as configured in the mapping file. If valid, the Yubico PAM module extracts the OTP string and sends it to the Yubico authentication server or else it reports failure. If authfile argument is present but the mapping file is not present at the provided path PAM module reports failure. After successful verification of OTP Yubico PAM module from the Yubico authentication server, a success code is returned.<br /><br /><strong>ii) User Level: </strong><br /><br />Although, user level configuration of pam_yubico is possible, this might not be a desired configuration option in case of OpenVPN demon in most enterprise.<br /></ul><br /><strong>b) Configuration of PAM modules for OpenVPN::</strong><br /><br />To configure PAM modules for OpenVPN, create a file named “/etc/pam.d/openvpn” (file name must be one which is specified in “/etc/openvpn/server.conf “   along with “plugin” directive) and list all the PAM modules in this files accordingly.<br /></ul><br /><strong>1.4) Test Setup:</strong><br /><br />Our test environment is as follows:<br /><br /><ul>i) Operating System: Fedora release 8 (Werewolf)<br />ii) OpenVPN Server : OpenVPN Version 2.0.9  <br />iii) Yubico PAM: pam_yubico  Version 1.8<br />iv) &quot;/etc/pam.d/openvpn&quot; file:<br /><br />auth       required     pam_yubico.so authfile=/etc/yubikeyid id=16 debug<br />auth        include     system-auth<br />account    required  pam_nologin.so<br />account     include      system-auth<br />password   include     system-auth<br />session     include     system-auth<br /></ul><br /><strong>1.5) Testing the configuration:</strong><br /><br />We have tested the pam_yubico configuration on following Linux sever platforms:<br /><br /><ul>a) Fedora 8:<br /><ul><br />i) Operating system: Fedora release 8 (Werewolf)<br />ii) OpenVPN Server : OpenVPN Version 2.0.9<br />iii) Yubico PAM: pam_yubico  Version 1.8<br /></ul> <br />b) Fedora 6:<br /><ul><br />i) Operating system: Fedora Core release 6 (Zod)<br />ii) OpenVPN Server: OpenVPN Version 2.0.9<br />iii) Yubico PAM: pam_yubico version 1.8<br /></ul></ul><br />To test the configuration, first create a couple of test users on the system where OpenVPN server is running and configure their YubiKey IDs accordingly.  <br /><br />Please use the following command for testing:<br /><br /># openvpn /etc/openvpn/client.conf <br /><br />OpenVPN client will first prompt for username, enter the username. After that OpenVPN client will prompt for password, enter user’s password immediately followed by an OTP generated by a YubiKey.<br /><br />If OpenVPN server is configured for supporting PAM authentication, it will verify user authentication details even at the startup of OpenVPN server demon, when it is started using “init.d” script or it is configured to start at boot time.<br /><br />To avoid prompting of username and password at the startup of OpenVPN server demon, we can start OpenVPN Server demon at command line as follows instead of starting it using “init.d” script&#058;<br /><br /># /usr/sbin/openvpn --config /etc/openvpn/server.conf --daemon openvpn<br /><br />We can configure OpenVPN server demon to start at boot time by copying the above command in /etc/rc.local file.  <br /></ul><br /><strong>2) OpenVPN Configuration with FreeRADIUS support:</strong><br /><br />In this type of configuration, the OpenVPN server will be using FreeRADIUS server for authenticating users. FreeRADIUS server will be verifying the authentication information received from OpenVPN server by verifying the username and user’s password against system password file “/etc/passwd” (or by other means supported by FreeRADIUS) and verifying the OTP (one time password) generated by a YubiKey with the Yubico’s OTP validation server.  <br /><br />To configure OpenVPN with FreeRADIUS support, please follow the steps below:<br /><br /><ul>A) Follow all the steps mentioned in the section “OpenVPN Configuration without FreeRADIUS support” to configure OpenVPN server to support PAM authentication. <br /><br />B) Install and configure FreeRADIUS server for two factor authentication using following wiki link:<br /><br /><!-- m --><a class="postlink" href="http://code.google.com/p/yubico-pam/wiki/YubiKeyAndFreeRADIUSviaPAM">http://code.google.com/p/yubico-pam/wik ... DIUSviaPAM</a><!-- m --><br /><br />C) Install and configure pam_radius_auth.so and copy it to /lib/security directory<br /><br />D) Create a file “/etc/pam.d/openvpn” (file name must be the one which is specified in “/etc/openvpn/server.conf “  along with “plugin” directive) and copy the following contents to the file:<br /><br />account         required        pam_radius_auth.so<br />account         required        pam_radius_auth.so<br />auth            required        pam_radius_auth.so no_warn try_first_pass<br /><br />E) Create a file “/etc/raddb/server” to configure FreeRADIUS server that is used by pam_radius_auth PAM module. The content for the file is as follows:<br /><br />&lt;RADIUS server fully qualified domain name/ IP Address&gt; &lt;Shared Secrete &gt;<br />&lt;RADIUS server fully qualified domain name/ IP Address&gt; &lt;Shared Secrete &gt;<br />.<br />.<br />.<br />.<br /><br /><br />e.g.:<br /><br />freeradius.example.com Admin456<br /><br />We can configure failover support for RADIUS server by creating additional RADIUS server entries per line of “/etc/raddb/server” file.<br /></ul><br /><strong>2.1) Test Setup:</strong><br /><br />Our test environment is as follows:<br /><br /><ul>i) Operating System: Fedora release 8 (Werewolf)<br />ii) FreeRADIUS Server: FreeRADIUS Server Version 1.1.7 <br />iii) pam_radius: pam_radius_auth Version 1.3.17 <br />iv) Yubico PAM: pam_yubico  Version 1.8<br />v) &quot;/etc/pam.d/openvpn&quot; file:<br /><br />account         required        pam_radius_auth.so<br />account         required        pam_radius_auth.so<br />auth            required        pam_radius_auth.so no_warn try_first_pass<br /></ul><br /><strong>2.2) Testing the configuration:</strong><br /><br />We have tested the pam_yubico configuration on following Linux sever platforms:<br /><br /><ul>a) Fedora 8:<br /><br /><ul>i) Operating system: Fedora release 8 (Werewolf)<br />ii) OpenVPN Server : OpenVPN Version 2.0.9<br />iii) Yubico PAM: pam_yubico  Version 1.8<br />iv) FreeRADIUS Server: FreeRADIUS Server Version 1.1.7<br />v) Pam_radius: pam_radius_auth Version 1.3.17 <br /></ul> <br /><br />b) Fedora 6:<br /><br /><ul>i) Operating system: Fedora Core release 6 (Zod)<br />ii) OpenVPN Server: OpenVPN Version 2.0.9<br />iii) Yubico PAM: pam_yubico version 1.8<br />iv) FreeRADIUS Server: FreeRADIUS Server Version 1.1.7<br />v) Pam_radius: pam_radius_auth Version 1.3.17<br /></ul></ul><br />To test the configuration, first create a couple of test users on the system where FreeRADIUS server is running and configure their YubiKey IDs accordingly.<br /><br />Please use the following command for testing:<br /><br /># openvpn /etc/openvpn/client.conf <br /><br />OpenVPN client will first prompt for username, enter the username. After that OpenVPN client will prompt for password, enter user’s password immediately followed by an OTP generated by a YubiKey.</li></ul><br /><br /><em><strong>Note:</strong> Please use OpenVPN server Version 2.0.9 (Latest Stable Version), as older and newer beta versions have problems with PAM libraries. RADIUS authentication will fail if it is configured with older or latest beta versions of OpenVPN Server.</em><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=280">network-marvels</a> — Wed Nov 26, 2008 4:47 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[paul]]></name></author>
<updated>2008-11-07T18:26:56+01:00</updated>
<published>2008-11-07T18:26:56+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=81&amp;p=788#p788</id>
<link href="https://forum.yubico.com/viewtopic.php?t=81&amp;p=788#p788"/>
<title type="html"><![CDATA[Re: YubiKey as a strong authentication device for VPN clients]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=81&amp;p=788#p788"><![CDATA[
<div class="quotetitle">Neal wrote:</div><div class="quotecontent"><br />Has any progress been made on this project recently?  I have managed to get a Netscreen SSG VPN authenticating using the RedHat image and I'm interested in getting local auth done with username + password + OTP for two factor authentication on the vpn (basically the BETA which was sceduled for release Q3 2008).  I'm quite happy to help test anything if it would help.<br /><br />If no progress has been made since the last release I'll probably start from scratch with a RedHat ES5 install and the lateset pam modules etc.  If so any suggestions would be greatly appreciated as I'd expect to loose some hair trying to get it working.  I'll be happy to report on any progress I make.<br /><br />Thanks in advance,<br /></div><br /><br />There has been some deployments of Yubico PAM for SSH, which is similar to deploying it for VPN/FreeRadus.<br /><br /><!-- l --><a class="postlink-local" href="http://forum.yubico.com/search.php?author_id=280&amp;sr=posts">search.php?author_id=280&amp;sr=posts</a><!-- l --><br /><br />Any effort or experience sharing of Yubikey for VPN would be highly appreciated!<br /><br /> <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":)" title="Smile" /> Thanks<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=55">paul</a> — Fri Nov 07, 2008 6:26 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Neal]]></name></author>
<updated>2008-11-07T12:49:39+01:00</updated>
<published>2008-11-07T12:49:39+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=81&amp;p=787#p787</id>
<link href="https://forum.yubico.com/viewtopic.php?t=81&amp;p=787#p787"/>
<title type="html"><![CDATA[Re: YubiKey as a strong authentication device for VPN clients]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=81&amp;p=787#p787"><![CDATA[
Has any progress been made on this project recently?  I have managed to get a Netscreen SSG VPN authenticating using the RedHat image and I'm interested in getting local auth done with username + password + OTP for two factor authentication on the vpn (basically the BETA which was sceduled for release Q3 2008).  I'm quite happy to help test anything if it would help.<br /><br />If no progress has been made since the last release I'll probably start from scratch with a RedHat ES5 install and the lateset pam modules etc.  If so any suggestions would be greatly appreciated as I'd expect to loose some hair trying to get it working.  I'll be happy to report on any progress I make.<br /><br />Thanks in advance,<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=299">Neal</a> — Fri Nov 07, 2008 12:49 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[paul]]></name></author>
<updated>2008-07-25T18:16:30+01:00</updated>
<published>2008-07-25T18:16:30+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=81&amp;p=487#p487</id>
<link href="https://forum.yubico.com/viewtopic.php?t=81&amp;p=487#p487"/>
<title type="html"><![CDATA[Download the pre-configured VPN ready package for RedHat]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=81&amp;p=487#p487"><![CDATA[
* This is the config guide:<br /><br /> yubicoVPNYubicoAuthServerConfigGuide.pdf (103.28 KB)<br /><br /> <!-- m --><a class="postlink" href="http://www.megaupload.com/?d=90WAGP86">http://www.megaupload.com/?d=90WAGP86</a><!-- m --><br /><br />* This is an VMWare image readily deployable on a Redhat:<br /><br /> yubicoVPNYubico Redhat Enterprise 4.zip (372.35 MB)<br /><br /> <!-- m --><a class="postlink" href="http://www.megaupload.com/?d=HCQYA6Y0">http://www.megaupload.com/?d=HCQYA6Y0</a><!-- m --><br /><br />PS. Found many don't use BitTorrent client, so we use this mega upload service<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=55">paul</a> — Fri Jul 25, 2008 6:16 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[paul]]></name></author>
<updated>2008-07-23T17:20:19+01:00</updated>
<published>2008-07-23T17:20:19+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=81&amp;p=466#p466</id>
<link href="https://forum.yubico.com/viewtopic.php?t=81&amp;p=466#p466"/>
<title type="html"><![CDATA[Re: YubiKey as a strong authentication device for VPN clients]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=81&amp;p=466#p466"><![CDATA[
Folks, we are starting a group there:<br /><br /><!-- m --><a class="postlink" href="http://code.google.com/p/yubikeyvpnserver/">http://code.google.com/p/yubikeyvpnserver/</a><!-- m --><br /><br />If you like, we heartily welcome you to participate with a leading role in a Yubico community group depends on your interest, expertise and availability:<br /><br />[1] Technical Lead Group:<br /><br />Collect &amp; review requirements, decide the technology foundation,<br />arbitrate voting on feature preferences, architecture design, code the<br />framework, code &amp; bug &amp; doc review, coordinate the QA, documentation<br />and other developers' efforts, plan the release/patch schedules.<br /><br />As a technical lead, since there are customers demand paid consulting,<br />Yubico will list you as a qualified expert in Yubikey integration on<br />our web site and you make your consulting money from our customers<br />directly. Because Yubikey has a fast-growing grass-root momentum, the<br />early qualified consultants should do pretty well in years to come.<br /><br />[2] Customer/User Group:<br /><br />Write down requirements from your use case, discuss &amp; prioritize<br />suggested features, and sponsor this community project with $3K USD.<br />In return you can cast a Sponsor Vote about Go or No-Go of<br />controversial features. We welcome individuals or your company to<br />sponsor this project that benefit everyone.<br /><br />Let me know.<br /><br />Thanks<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=55">paul</a> — Wed Jul 23, 2008 5:20 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[paul]]></name></author>
<updated>2008-07-23T16:20:54+01:00</updated>
<published>2008-07-23T16:20:54+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=81&amp;p=463#p463</id>
<link href="https://forum.yubico.com/viewtopic.php?t=81&amp;p=463#p463"/>
<title type="html"><![CDATA[Re: YubiKey as a strong authentication device for VPN clients]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=81&amp;p=463#p463"><![CDATA[
Good idea! Sam, will do!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=55">paul</a> — Wed Jul 23, 2008 4:20 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Sam]]></name></author>
<updated>2008-07-18T17:58:23+01:00</updated>
<published>2008-07-18T17:58:23+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=81&amp;p=442#p442</id>
<link href="https://forum.yubico.com/viewtopic.php?t=81&amp;p=442#p442"/>
<title type="html"><![CDATA[Re: YubiKey as a strong authentication device for VPN clients]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=81&amp;p=442#p442"><![CDATA[
You mention the VMWare image fits on a CD-ROM...<br /><br />Perhaps arranging a torrent for the image would alleviate Yubico from paying for the bandwidth of distributing it.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=71">Sam</a> — Fri Jul 18, 2008 5:58 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[paul]]></name></author>
<updated>2008-07-08T23:31:03+01:00</updated>
<published>2008-07-08T23:31:03+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=81&amp;p=422#p422</id>
<link href="https://forum.yubico.com/viewtopic.php?t=81&amp;p=422#p422"/>
<title type="html"><![CDATA[Re: YubiKey as a strong authentication device for VPN clients]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=81&amp;p=422#p422"><![CDATA[
Yubico has made progress to package FreeRadius and Yubikey PAM module to integrate with Cisco VPN. We put the pre-configured software into a VMWare image that you can run it out of the box, if you need the CDROM, let me know. Also I'll publicize that onto Yubico web site so you can order. Since the VMWare image is too big to download.<br /><br />More info:<br /><br /><!-- l --><a class="postlink-local" href="http://forum.yubico.com/vpn">vpn</a><!-- l --><br /><br />Cheers<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=55">paul</a> — Tue Jul 08, 2008 11:31 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[paul]]></name></author>
<updated>2008-06-13T23:59:11+01:00</updated>
<published>2008-06-13T23:59:11+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=81&amp;p=267#p267</id>
<link href="https://forum.yubico.com/viewtopic.php?t=81&amp;p=267#p267"/>
<title type="html"><![CDATA[Re: YubiKey as a strong authentication device for VPN clients]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=81&amp;p=267#p267"><![CDATA[
YubiKey with FreeRadius has been a proven use case with Yubico's open-source PAM module:<br /><br /><!-- m --><a class="postlink" href="http://code.google.com/p/yubico-pam/w/list">http://code.google.com/p/yubico-pam/w/list</a><!-- m --><br /><br />I suppose you are very familiar with FreeRadius configuration etc. We also have a pre-configured VPN Ready package with FreeRadius + Yubico PAM preconfigured in a VMWare image that you can evaluate it out of the box. If you need that, we can arrange to get you a CDROM of it since it is too big to download.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=55">paul</a> — Fri Jun 13, 2008 11:59 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[paul]]></name></author>
<updated>2008-06-10T07:40:21+01:00</updated>
<published>2008-06-10T07:40:21+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=81&amp;p=215#p215</id>
<link href="https://forum.yubico.com/viewtopic.php?t=81&amp;p=215#p215"/>
<title type="html"><![CDATA[Re: YubiKey as a strong authentication device for VPN clients]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=81&amp;p=215#p215"><![CDATA[
I'll find time to share the experience about how we integrated YubiKey with Cisco VPN and FreeRadius.<br /><br />Stay tuned.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=55">paul</a> — Tue Jun 10, 2008 7:40 am</p><hr />
]]></content>
</entry>
</feed>