<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=1788" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2015-03-16T11:56:07+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=1788</id>
<entry>
<author><name><![CDATA[dharrigan]]></name></author>
<updated>2015-03-16T11:56:07+01:00</updated>
<published>2015-03-16T11:56:07+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1788&amp;p=7039#p7039</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1788&amp;p=7039#p7039"/>
<title type="html"><![CDATA[Re: OTOH and Challenge Response Clarification]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1788&amp;p=7039#p7039"><![CDATA[
Hi,<br /><br />Thank you for the clarification <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":-)" title="Smile" /> <br /><br />-=david=-<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3220">dharrigan</a> — Mon Mar 16, 2015 11:56 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Tom2]]></name></author>
<updated>2015-03-16T11:05:35+01:00</updated>
<published>2015-03-16T11:05:35+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1788&amp;p=7038#p7038</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1788&amp;p=7038#p7038"/>
<title type="html"><![CDATA[Re: OTOH and Challenge Response Clarification]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1788&amp;p=7038#p7038"><![CDATA[
Hi,<br /><br />If you are using the Yubico Authenticator you are not using that TOTP helper app, rather the OATH applet on the Yubikey NEO<br /><br />You are right that the webpage is misleading we will fix it.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3364">Tom2</a> — Mon Mar 16, 2015 11:05 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[dharrigan]]></name></author>
<updated>2015-03-16T10:47:32+01:00</updated>
<published>2015-03-16T10:47:32+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1788&amp;p=7037#p7037</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1788&amp;p=7037#p7037"/>
<title type="html"><![CDATA[Re: OTOH and Challenge Response Clarification]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1788&amp;p=7037#p7037"><![CDATA[
Hi,<br /><br />Thank you for your reply. I got the information directly from the website, referenced here:<br /><br /><!-- m --><a class="postlink" href="https://www.yubico.com/applications/internet-services/gmail/">https://www.yubico.com/applications/int ... ces/gmail/</a><!-- m --><br /><br />and to quote:<br /><br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />Therefore, to create a TOTP response using the YubiKey, Yubico has developed a small application which sends the current time to the YubiKey set-up for HMAC-SHA1 challenge/response. The application sends the current time in the OATH-TOTP format and receives back the 160 bit HMAC-SHA1 hash.  This is then processed as per the OATH-TOTP spec to produce either a 6 or 8 digit number.<br /></div><br /><br />It alludes that CR is used (specifically HMAC-SHA1).<br /><br />I've probably misunderstood the information presented, but that's how it reads.<br /><br />-=david=-<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3220">dharrigan</a> — Mon Mar 16, 2015 10:47 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Tom2]]></name></author>
<updated>2015-03-16T09:59:16+01:00</updated>
<published>2015-03-16T09:59:16+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1788&amp;p=7035#p7035</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1788&amp;p=7035#p7035"/>
<title type="html"><![CDATA[Re: OTOH and Challenge Response Clarification]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1788&amp;p=7035#p7035"><![CDATA[
I am not sure I understand your question.<br /><br /><br />OATH (TOTP HOTP) they have nothing to do with the HMAC-SHA1.<br /><br />The OATH applet on your NEO will be fed with time from your OS and spit out TOTP codes.<br /><br />The Challenge Response works in a different way over HID not CCID. An example of CR is KeeChallenge for KeePass where the Yubikey secret is used as part of the key derivation function.<br />Another application using CR is the Windows logon tool<br /><br />The Yubico Authenticator does not use CR in any way.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3364">Tom2</a> — Mon Mar 16, 2015 9:59 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[dharrigan]]></name></author>
<updated>2015-03-15T16:10:40+01:00</updated>
<published>2015-03-15T16:10:40+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1788&amp;p=7033#p7033</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1788&amp;p=7033#p7033"/>
<title type="html"><![CDATA[OTOH and Challenge Response Clarification]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1788&amp;p=7033#p7033"><![CDATA[
Hi,<br /><br />If I understand it correctly, the Yubico Authenticator sends the current time to the Yubikey Neo (I have fw version 3.3.0) as a challenge response and gets back a response which is then used to generate the digits.<br /><br />My question is this, when I plug my Yubikey into the Personalization Tool, and click on Tools/Challenge-Response Tester, and choose either slot 1 or slot 2, I get this error:<br /><br />&quot;Challenge response could not be performed. Perhaps they YubiKey is not configured for challenge-response?&quot;<br /><br />So, how does the Yubico Authenticator get my YubiKey to honour a challenge-response request? I'm obviously missing something in my understanding! <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":-)" title="Smile" /><br /><br />btw, I'm successfully using the Yubico Authenticator and is working as expected.<br /><br />Thank you.<br /><br />-=david=-<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3220">dharrigan</a> — Sun Mar 15, 2015 4:10 pm</p><hr />
]]></content>
</entry>
</feed>