<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=8&amp;t=639" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2011-02-24T15:20:36+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=8&amp;t=639</id>
<entry>
<author><name><![CDATA[Anonymous]]></name></author>
<updated>2011-02-24T15:20:36+01:00</updated>
<published>2011-02-24T15:20:36+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=639&amp;p=2586#p2586</id>
<link href="https://forum.yubico.com/viewtopic.php?t=639&amp;p=2586#p2586"/>
<title type="html"><![CDATA[Re: yubico-pam and response verification]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=639&amp;p=2586#p2586"><![CDATA[
Yes, definitely. Validation protocol 2.0 has been available for a long time, but unfortunately updating the c-client was lagging behind.<br /><br />Anyways, I've been working on (and testing) the 2.0-branch today, and it seems to work now (HMAC signing was broken this morning). <br /><br />Please bring any issues to my attention - preferably in the yubico-devel google group. <!-- m --><a class="postlink" href="http://groups.google.com/group/yubico-devel">http://groups.google.com/group/yubico-devel</a><!-- m --><br /><br />/Fredrik<p>Statistics: Posted by Guest — Thu Feb 24, 2011 3:20 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[yaramo]]></name></author>
<updated>2011-02-24T09:32:06+01:00</updated>
<published>2011-02-24T09:32:06+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=639&amp;p=2585#p2585</id>
<link href="https://forum.yubico.com/viewtopic.php?t=639&amp;p=2585#p2585"/>
<title type="html"><![CDATA[Re: yubico-pam and response verification]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=639&amp;p=2585#p2585"><![CDATA[
<div class="quotetitle">Fredrik-at-Yubico wrote:</div><div class="quotecontent"><br />The solution is to use a Validation protocol version 2.0 client.<br /></div><br /><br />Ok, I understand now. I'll give it a go. Bit of a huge gaping hole though!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1549">yaramo</a> — Thu Feb 24, 2011 9:32 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Anonymous]]></name></author>
<updated>2011-02-24T08:09:51+01:00</updated>
<published>2011-02-24T08:09:51+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=639&amp;p=2584#p2584</id>
<link href="https://forum.yubico.com/viewtopic.php?t=639&amp;p=2584#p2584"/>
<title type="html"><![CDATA[Re: yubico-pam and response verification]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=639&amp;p=2584#p2584"><![CDATA[
The solution is to use a Validation protocol version 2.0 client.<br /><br />Version 2.0 uses either either a shared key (HMAC checksums), SSL or both to provide integrity in the requests/responses to the validation servers.<br /><br />  <!-- m --><a class="postlink" href="http://code.google.com/p/yubikey-val-server-php/wiki/ValidationProtocolV20">http://code.google.com/p/yubikey-val-se ... rotocolV20</a><!-- m --><br /><br />I've integrated various patches from contributors updating the yubico-c-client to the v2.0 specification. This is now ready for testing, which I haven't gotten around to yet. The plan is to release yubico-c-client v2.4 (last release was 2.3) _without_ these patches (as a more stable release), and then aim to release 2.5 _with_ these patches fairly quickly.<br /><br />It looks like you've compiled yubico-c-client from source? You are most welcome to help testing this new branch :<br /><br />  $ git clone <!-- m --><a class="postlink" href="git://github.com/Yubico/yubico-c-client.git">git://github.com/Yubico/yubico-c-client.git</a><!-- m --> -b feature/v2.0_validation<br /><br />/Fredrik<p>Statistics: Posted by Guest — Thu Feb 24, 2011 8:09 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[yaramo]]></name></author>
<updated>2011-02-23T20:27:03+01:00</updated>
<published>2011-02-23T20:27:03+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=639&amp;p=2583#p2583</id>
<link href="https://forum.yubico.com/viewtopic.php?t=639&amp;p=2583#p2583"/>
<title type="html"><![CDATA[yubico-pam and response verification]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=639&amp;p=2583#p2583"><![CDATA[
I just installed the yubico-pam module and got it working ok. However looking at the source, it seems very naive:<br /><br />/etc/pam.d/su<br />auth            sufficient      pam_yubico.so id=5180 key=redacted= url=http://127.0.0.1:5000/wsapi/verify?id=%d&amp;otp=%s debug<br /><br />In one window:<br />$ nc -l 5000<br /><br />In another:<br />$ su<br />Yubikey for `root': <br />[press key]<br /><br />In nc window:<br />$ nc -l  5000<br />GET /wsapi/verify?id=5180&amp;otp=redacted&amp;h=redacted=&amp;nonce=ghqhmsiewomlmbetmeptpimowjdnxlcd HTTP/1.1<br />User-Agent: ykclient/2.4<br />Host: 127.0.0.1:5000<br />Accept: */*<br /><br />type:<br />status=OK<br /><br />In su window:<br /># <br /><br />What am I supposed to do to make this secure? i.e. prevent a man in the middle returning status=OK for anything.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1549">yaramo</a> — Wed Feb 23, 2011 8:27 pm</p><hr />
]]></content>
</entry>
</feed>