<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=16&amp;t=2143" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2016-01-01T21:47:04+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=16&amp;t=2143</id>
<entry>
<author><name><![CDATA[ojiwankenobi]]></name></author>
<updated>2016-01-01T21:47:04+01:00</updated>
<published>2016-01-01T21:47:04+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2143&amp;p=8105#p8105</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2143&amp;p=8105#p8105"/>
<title type="html"><![CDATA[Tips: KeePass, Windows 10 Logon, Yubikey 4]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2143&amp;p=8105#p8105"><![CDATA[
Re: Yubikey 4 standard; Windows 10; KeePass; Using both slots.<br /><br />All,  It took me several days to figure this out, so I thought I'd share what worked and what did not:<br /><br />1.  <span style="text-decoration: underline">The Yubikey Personalization Tool</span>:  Every time you <em>update settings</em> on a Slot or <em>write configuration</em>, use the <strong>same</strong> configuration log file.  I mistakenly thought each feature used its own config file, but only one is needed.  It is a .csv file with a row added each time <em>Settings</em> are updated or a <em>Write Configuration</em> is done.  So, in this example, in the end you will find one row each for OATH-HOTP and Challenge-Response (see attached snapshot).<br /><br />2. <span style="text-decoration: underline"> KeePass v. 2.30</span>:<br />         Use instructions at <a href="https://www.yubico.com/applications/password-management/consumer/keepass/" class="postlink">https://www.yubico.com/applications/password-management/consumer/keepass/</a>.<br />I use Slot 1, Look-ahead count = 6.  Why Slot 1?  I use the same Yubikey 4 stick for Windows logon.  Windows logon would work for me only in Slot 2, so KeePass' OATH-HOTP is configured in Slot 1.<br />         My .kbdx file is in a locally-shared folder along with the YubiKey configuration file so I can get to it from any of the other accounts on the PC without confusing the &quot;count.&quot;<br />         A portable copy of the .kbdx kept on a thumbdrive still uses a Master Password.<br /><br />3.  <span style="text-decoration: underline">Windows 10 Logon</span><br />         I did not enable the built-in administrator account.  Instead, I created a new, local account; promoted it to administrator; configured Yubikey 4's slot 2 according to <a href="https://www.yubico.com/wp-content/uploads/2013/02/Windows-Login-YubiKey-Configuration.pdf" class="postlink">https://www.yubico.com/wp-content/uploads/2013/02/Windows-Login-YubiKey-Configuration.pdf</a>.<br />After convincing myself that the NewAdmin logon worked fine with YubiKey enabled, I demoted my own account to standard user.  Now the PC behaves more like LINUX: if I want to do admin work from my own account, Windows asks me for the NewAdmin's logon info - which is managed by YubiKey.<br /><br />-- Oji --<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4074">ojiwankenobi</a> — Fri Jan 01, 2016 9:47 pm</p><hr />
]]></content>
</entry>
</feed>