<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=3&amp;t=193" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2008-10-20T12:27:20+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=3&amp;t=193</id>
<entry>
<author><name><![CDATA[Simon]]></name></author>
<updated>2008-10-20T12:27:20+01:00</updated>
<published>2008-10-20T12:27:20+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=193&amp;p=765#p765</id>
<link href="https://forum.yubico.com/viewtopic.php?t=193&amp;p=765#p765"/>
<title type="html"><![CDATA[Re: troubles verifying response]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=193&amp;p=765#p765"><![CDATA[
We have some clients that perform signing/validation of signatures, check the yubico.com web pages.  Maybe you can debug some of them to find out what is going on with your implementation?  I think they are supposed to work with our current server.<br /><br />/Simon<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2">Simon</a> — Mon Oct 20, 2008 12:27 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[paul]]></name></author>
<updated>2008-10-08T07:35:12+01:00</updated>
<published>2008-10-08T07:35:12+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=193&amp;p=753#p753</id>
<link href="https://forum.yubico.com/viewtopic.php?t=193&amp;p=753#p753"/>
<title type="html"><![CDATA[Re: troubles verifying response]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=193&amp;p=753#p753"><![CDATA[
<div class="quotetitle">Philippe wrote:</div><div class="quotecontent"><br />Yes, now requests that previously returned OK now return BAD_SIGNATURE. I tried to use it without the h parameter but then I get MISSING_PARAMETER info=h.<br /></div><br /><br />Philippe, you can turn on/off of signature &amp; id checking at our new validation server in beta:<br /><br /> <!-- m --><a class="postlink" href="http://63.146.69.105/yms/">http://63.146.69.105/yms/</a><!-- m --><br /><br />And, you can use this to test the generated signature:<br /><br /> <!-- m --><a class="postlink" href="http://63.146.69.105/wsapi/sign_demo.php">http://63.146.69.105/wsapi/sign_demo.php</a><!-- m --><br /><br />To validate an OTP:<br /><br />Debug mode: <!-- m --><a class="postlink" href="http://63.146.69.105/wsapi/verify_debug?id=...&amp;otp=....&amp;h=...">http://63.146.69.105/wsapi/verify_debug ... ....&amp;h=...</a><!-- m -->.<br /><br />Production mode: <!-- m --><a class="postlink" href="http://63.146.69.105/wsapi/verify?id=...&amp;otp=....&amp;h=...">http://63.146.69.105/wsapi/verify?id=...&amp;otp=....&amp;h=...</a><!-- m -->.<br /><br />This beta server's database is used only for testing purpose, NOT the same as the production database behind the server at <!-- m --><a class="postlink" href="http://api.yubico.com">http://api.yubico.com</a><!-- m -->.<br /><br />Thanks for comments<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=55">paul</a> — Wed Oct 08, 2008 7:35 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Philippe]]></name></author>
<updated>2008-10-07T19:26:25+01:00</updated>
<published>2008-10-07T19:26:25+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=193&amp;p=752#p752</id>
<link href="https://forum.yubico.com/viewtopic.php?t=193&amp;p=752#p752"/>
<title type="html"><![CDATA[Re: troubles verifying response]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=193&amp;p=752#p752"><![CDATA[
Yes, now requests that previously returned OK now return BAD_SIGNATURE. I tried to use it without the h parameter but then I get MISSING_PARAMETER info=h.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=282">Philippe</a> — Tue Oct 07, 2008 7:26 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[paul]]></name></author>
<updated>2008-10-06T20:38:34+01:00</updated>
<published>2008-10-06T20:38:34+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=193&amp;p=742#p742</id>
<link href="https://forum.yubico.com/viewtopic.php?t=193&amp;p=742#p742"/>
<title type="html"><![CDATA[Re: troubles verifying response]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=193&amp;p=742#p742"><![CDATA[
The hmac calc has not been working well for awhile in the validation response.<br /><br />So I'm migrating it to the new server at:<br /><br /><!-- m --><a class="postlink" href="http://63.146.69.105/wsapi/verify.php?id=1&amp;otp=..">http://63.146.69.105/wsapi/verify.php?id=1&amp;otp=..</a><!-- m -->.<br /><br />Let me know if you have problems with the new server?<br /><br />Thanks<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=55">paul</a> — Mon Oct 06, 2008 8:38 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Philippe]]></name></author>
<updated>2008-10-05T10:54:14+01:00</updated>
<published>2008-10-05T10:54:14+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=193&amp;p=738#p738</id>
<link href="https://forum.yubico.com/viewtopic.php?t=193&amp;p=738#p738"/>
<title type="html"><![CDATA[troubles verifying response]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=193&amp;p=738#p738"><![CDATA[
I have some troubles verifying the response from the Yubico server.<br /><br />The response I get is something like this (REPLAYED_OTP is ok, I'm fooling around)<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">h=yPsLotcX+VOIP/OSlViLqsMLl4c=<br />t=2008-10-05T09:17:26Z0459<br />status=REPLAYED_OTP</div><br />What I do is the following:<br /><ol style="list-style-type: decimal"><li>base 64 decode the hash which gives me (200 251 11 162 215 23 249 83 136 63 243 146 149 88 139 170 195 11 151 135)</li><li>compute the verification line which is in this case &quot;s=REPLAYED_OTP&amp;t=2008-10-05T09:17:26Z0459&quot;. It's all ASCII so it's the same in UTF-8.</li><li>compute the HMAC-SHA1 hash over the verification line using my shared secret and compare it with hash from the first step. They don't match.</li></ol>I also sign my requests and the server does verify them. If I attach a wrong signature the server complains with BAD_SIGNATURE. So I think my HMAC-SHA1 library is ok. My first guess would be that my verification line is bad.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=282">Philippe</a> — Sun Oct 05, 2008 10:54 am</p><hr />
]]></content>
</entry>
</feed>