<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=35&amp;t=2767" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2017-11-01T02:34:40+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=35&amp;t=2767</id>
<entry>
<author><name><![CDATA[LD2gIlShWrA2J9qFcwS5]]></name></author>
<updated>2017-11-01T02:33:08+01:00</updated>
<published>2017-11-01T02:33:08+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2767&amp;p=9946#p9946</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2767&amp;p=9946#p9946"/>
<title type="html"><![CDATA[Re: Config Protection of EXISTING &quot;Challange-Response&quot;]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2767&amp;p=9946#p9946"><![CDATA[
<div class="quotetitle">ChrisHalos wrote:</div><div class="quotecontent"><br /><em>... I think I figured out what's going on here ...</em><br /></div><br />Chris:<br /><br />A sincere &quot;Thank You&quot; for the extra clarifications re: potentially differing behaviors based on firmware versions.<br /><br />Cheers,<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3583">LD2gIlShWrA2J9qFcwS5</a> — Wed Nov 01, 2017 2:33 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[LD2gIlShWrA2J9qFcwS5]]></name></author>
<updated>2017-11-01T02:27:23+01:00</updated>
<published>2017-11-01T02:27:23+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2767&amp;p=9945#p9945</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2767&amp;p=9945#p9945"/>
<title type="html"><![CDATA[Re: Config Protection of EXISTING &quot;Challange-Response&quot;]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2767&amp;p=9945#p9945"><![CDATA[
<div class="quotetitle">My1 wrote:</div><div class="quotecontent"><br /><em>... you go into settings press update settings and there you can set the protection ...</em><br /></div><br />My1:<br /><br /><strong>Thank you so much!</strong>  <img src="https://forum.yubico.com/images/smilies/icon_e_biggrin.gif" alt=":D" title="Very Happy" /> <br /><br />I'd never investigated that innocuous little button down there at the bottom of the page w/ the grayed-out text.<br /><br />It was EXACTLY what I was looking for.<br /><br />Thanks again,<br /><br />Cheers,<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3583">LD2gIlShWrA2J9qFcwS5</a> — Wed Nov 01, 2017 2:27 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[My1]]></name></author>
<updated>2017-10-31T20:06:36+01:00</updated>
<published>2017-10-31T20:06:36+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2767&amp;p=9933#p9933</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2767&amp;p=9933#p9933"/>
<title type="html"><![CDATA[Re: Config Protection of EXISTING &quot;Challange-Response&quot;]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2767&amp;p=9933#p9933"><![CDATA[
<div class="quotetitle">ChrisHalos wrote:</div><div class="quotecontent"><br />Just remember... forgetting an access code after setting one means there's no way to make changes to that slot anymore (or enable/disable modes - OTP/CCID/U2F).<br /></div><br /><br />how does that last part even make sense? the config protection applies to slot 1 or 2, but the modes the Yubi acts in are neither related to the slots to nor the personalization tool in the first place.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4175">My1</a> — Tue Oct 31, 2017 8:06 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[ChrisHalos]]></name></author>
<updated>2017-10-31T00:21:10+01:00</updated>
<published>2017-10-31T00:21:10+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2767&amp;p=9926#p9926</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2767&amp;p=9926#p9926"/>
<title type="html"><![CDATA[Re: Config Protection of EXISTING &quot;Challange-Response&quot;]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2767&amp;p=9926#p9926"><![CDATA[
I think I figured out what's going on here. Firmware 4.3.4 and 4.3.5 there was a bug that didn't allow updating configuration protection on the slot credentials. 4.2.6-4.3.3 work, as do 4.3.6 and newer. When I responded on the other thread I'm speaking from experience (works). When my colleague responded on the support case that was referred to on the other post, he was testing on 4.3.4 because he wasn't sure (hence the two different answers).<br /><br />So on a 4.3.4 or 4.3.5 firmware YK4, you need to reprogram the credential in order to set an access code. If you have the configuration log (csv file), you can simply choose the same settings in the Personalization Tool and set the access code during programming. Just remember... forgetting an access code after setting one means there's no way to make changes to that slot anymore (or enable/disable modes - OTP/CCID/U2F).<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3140">ChrisHalos</a> — Tue Oct 31, 2017 12:21 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[My1]]></name></author>
<updated>2017-10-29T16:49:48+01:00</updated>
<published>2017-10-29T16:49:48+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2767&amp;p=9924#p9924</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2767&amp;p=9924#p9924"/>
<title type="html"><![CDATA[Re: Config Protection of EXISTING &quot;Challange-Response&quot;]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2767&amp;p=9924#p9924"><![CDATA[
you go into settings press update settings and there you can set the protection.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4175">My1</a> — Sun Oct 29, 2017 4:49 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[LD2gIlShWrA2J9qFcwS5]]></name></author>
<updated>2017-11-01T02:34:40+01:00</updated>
<published>2017-10-28T20:52:57+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2767&amp;p=9921#p9921</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2767&amp;p=9921#p9921"/>
<title type="html"><![CDATA[[SOLVED] Config Protection of EXISTING &quot;Challange-Response&quot;]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2767&amp;p=9921#p9921"><![CDATA[
I had previously posed this question in another thread  -- <!-- l --><a class="postlink-local" href="https://forum.yubico.com/viewtopic.php?f=35&amp;t=2722">viewtopic.php?f=35&amp;t=2722</a><!-- l --> -- but never received a definitive answer.<br /><br />So I'm trying again here w/ a more &quot;descriptive&quot; <em>Subj </em>line<br /><br /><strong>Question</strong>:   Is it possible to config-protect a &quot;Challenge-Reply&quot; configuration in Slot 2 WITHOUT changing / over-writing the previously-entered &quot;Secret Key&quot; ?<br /><br />I've tried several times but have been unsuccessful on each attempt.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3583">LD2gIlShWrA2J9qFcwS5</a> — Sat Oct 28, 2017 8:52 pm</p><hr />
]]></content>
</entry>
</feed>