<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=5&amp;t=579" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2010-10-13T10:36:52+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=5&amp;t=579</id>
<entry>
<author><name><![CDATA[romain]]></name></author>
<updated>2010-10-13T10:36:52+01:00</updated>
<published>2010-10-13T10:36:52+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=579&amp;p=2383#p2383</id>
<link href="https://forum.yubico.com/viewtopic.php?t=579&amp;p=2383#p2383"/>
<title type="html"><![CDATA[Yubikeys as a 2nd factor for SSH auth with a different KSM]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=579&amp;p=2383#p2383"><![CDATA[
We have spent some time setting up a pilot infrastructure to incorporate Yubikeys in our RHEL environment, in particular:<br />- We wanted our own validation and KSM services<br />- The first objective was to improve SSH authentication<br />- We wanted to use PAM<br />- We use Kerberos 5 (and AFS)<br />- Our SSH servers run a RHEL5 variant<br />- Our own root CA should be able to issue x509 certificates for the validation and KSM servers<br />- We need to plan a smooth transition from our users to gradually introduce Yubikeys<br />- Users should be able to import to create/import their AES key to the system<br /><br />We had to make some modifications to the code, mainly pam_yubico and ykclient, which has been submitted to Yubico.<br /><br />Our pilot is finally working, and we are in the process of documenting our experience:<br /><!-- m --><a class="postlink" href="https://twiki.cern.ch/twiki/bin/view/Main/Yubikeys">https://twiki.cern.ch/twiki/bin/view/Main/Yubikeys</a><!-- m --><br /><br />We thought it may be of some help for others.<br /><br />Romain.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1368">romain</a> — Wed Oct 13, 2010 10:36 am</p><hr />
]]></content>
</entry>
</feed>