<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=12&amp;t=80" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2008-11-20T16:10:28+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=12&amp;t=80</id>
<entry>
<author><name><![CDATA[Rohos]]></name></author>
<updated>2008-11-20T16:10:28+01:00</updated>
<published>2008-11-20T16:10:28+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=80&amp;p=796#p796</id>
<link href="https://forum.yubico.com/viewtopic.php?t=80&amp;p=796#p796"/>
<title type="html"><![CDATA[Re: YubiKey for Windows login?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=80&amp;p=796#p796"><![CDATA[
New <a href="http://www.rohos.com/free-encryption/2008/11/20/using-yubikey-token-to-login-into-remote-desktop/" class="postlink">Rohos Logon Key release</a> with OTP validation.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=225">Rohos</a> — Thu Nov 20, 2008 4:10 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[deekdeek]]></name></author>
<updated>2008-08-21T02:13:47+01:00</updated>
<published>2008-08-21T02:13:47+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=80&amp;p=579#p579</id>
<link href="https://forum.yubico.com/viewtopic.php?t=80&amp;p=579#p579"/>
<title type="html"><![CDATA[Re: YubiKey for Windows login?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=80&amp;p=579#p579"><![CDATA[
agreed/<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=246">deekdeek</a> — Thu Aug 21, 2008 2:13 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Simon]]></name></author>
<updated>2008-08-19T14:37:58+01:00</updated>
<published>2008-08-19T14:37:58+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=80&amp;p=561#p561</id>
<link href="https://forum.yubico.com/viewtopic.php?t=80&amp;p=561#p561"/>
<title type="html"><![CDATA[Re: YubiKey for Windows login?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=80&amp;p=561#p561"><![CDATA[
However right now it doesn't appear to validate the OTPs though, and uses the Yubikey OTP as a password by looking at the static prefix.  Still better than simple passwords, but not quite the security you would expect.  The product is quite polished in other regards, so I hope the security can be improved.<br /><br />/Simon<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2">Simon</a> — Tue Aug 19, 2008 2:37 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[paul]]></name></author>
<updated>2008-08-08T23:09:30+01:00</updated>
<published>2008-08-08T23:09:30+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=80&amp;p=537#p537</id>
<link href="https://forum.yubico.com/viewtopic.php?t=80&amp;p=537#p537"/>
<title type="html"><![CDATA[Re: YubiKey for Windows login?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=80&amp;p=537#p537"><![CDATA[
Cool! It works nicely on my Windows XP box!<br /><br /> <img src="https://forum.yubico.com/images/smilies/icon_e_biggrin.gif" alt=":D" title="Very Happy" /><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=55">paul</a> — Fri Aug 08, 2008 11:09 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Rohos]]></name></author>
<updated>2008-08-06T14:30:28+01:00</updated>
<published>2008-08-06T14:30:28+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=80&amp;p=530#p530</id>
<link href="https://forum.yubico.com/viewtopic.php?t=80&amp;p=530#p530"/>
<title type="html"><![CDATA[Re: YubiKey for Windows login?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=80&amp;p=530#p530"><![CDATA[
Update: <br /><br />We have published next release with Windows Vista support (x64/x86).<br />This is a final release.<br /><br />Rohos Logon Key can be intalled into Windows 2000/XP/Vista standalone workstations or AD workstations.<br />Local login/AD login are possible.<br /><br />Some answers:<br /><ul>* During Yubikey setup the program bounds to YubiKey IDs (first 12 chars).<br />* In current release Rohos doesn’t check generated OTP on the server, or OTP validity. It only checks the key’s ID.<br />* Rohos checks that OTP string was entered from YubiKey device, but not manually.<br />* For login rohos uses actual username/password that is stored in Windows registry (encrypted). <br /></ul><br />Download: <a href="http://www.rohos.com/free-encryption/2008/07/28/yubikey/" class="postlink">http://www.rohos.com/free-encryption/2008/07/28/yubikey/</a><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=225">Rohos</a> — Wed Aug 06, 2008 2:30 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Rohos]]></name></author>
<updated>2008-08-01T08:54:03+01:00</updated>
<published>2008-08-01T08:54:03+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=80&amp;p=510#p510</id>
<link href="https://forum.yubico.com/viewtopic.php?t=80&amp;p=510#p510"/>
<title type="html"><![CDATA[Rohos Logon. Windows Login with YubiKey]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=80&amp;p=510#p510"><![CDATA[
Hi All,<br /><br />Thanks Paul for the device sample!<br />Here is how to try Yubikey for Windows Logon:<br /><a href="http://www.rohos.com/yubikey.htm" class="postlink">http://www.rohos.com/yubikey.htm</a><br /><br />* At the moment Windows XP (x64/x86) are supported. <br />* Windows Vista in progress. <br />* MAC OS X login in development plan.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=225">Rohos</a> — Fri Aug 01, 2008 8:54 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[jdetar]]></name></author>
<updated>2008-07-22T14:09:16+01:00</updated>
<published>2008-07-22T14:09:16+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=80&amp;p=458#p458</id>
<link href="https://forum.yubico.com/viewtopic.php?t=80&amp;p=458#p458"/>
<title type="html"><![CDATA[Re: YubiKey for Windows login?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=80&amp;p=458#p458"><![CDATA[
I'll be interested, as well as other clients I have. We're looking for an RSA SecurID alternative, and I think someday Yubikey has the potential to really compete with it. This will be just another step in the right direction.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=54">jdetar</a> — Tue Jul 22, 2008 2:09 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[ferrix]]></name></author>
<updated>2008-07-18T04:36:54+01:00</updated>
<published>2008-07-18T04:36:54+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=80&amp;p=440#p440</id>
<link href="https://forum.yubico.com/viewtopic.php?t=80&amp;p=440#p440"/>
<title type="html"><![CDATA[Re: YubiKey for Windows login?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=80&amp;p=440#p440"><![CDATA[
What kind of login is it?  To a standalone machine?  To AD?  Using OTP mode I assume? <br /><br />We need details <img src="https://forum.yubico.com/images/smilies/icon_e_biggrin.gif" alt=":D" title="Very Happy" /><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=162">ferrix</a> — Fri Jul 18, 2008 4:36 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[paul]]></name></author>
<updated>2008-07-18T04:34:29+01:00</updated>
<published>2008-07-18T04:34:29+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=80&amp;p=439#p439</id>
<link href="https://forum.yubico.com/viewtopic.php?t=80&amp;p=439#p439"/>
<title type="html"><![CDATA[Rohos did a beta release of using YubiKey for Windows login]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=80&amp;p=439#p439"><![CDATA[
Just for your information - <br /><br />I'm excited to try out a great piece of work done by Rohos to use Yubikey for Windows login. They are polishing it and testing it more before making the official release.<br /><br />Cheers<br /> <img src="https://forum.yubico.com/images/smilies/icon_cool.gif" alt="8-)" title="Cool" /><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=55">paul</a> — Fri Jul 18, 2008 4:34 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[ferrix]]></name></author>
<updated>2008-06-30T15:28:49+01:00</updated>
<published>2008-06-30T15:28:49+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=80&amp;p=381#p381</id>
<link href="https://forum.yubico.com/viewtopic.php?t=80&amp;p=381#p381"/>
<title type="html"><![CDATA[Re: YubiKey for Windows login?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=80&amp;p=381#p381"><![CDATA[
<div class="quotetitle">Simon wrote:</div><div class="quotecontent"><br />Right.  I suspect that our &quot;static OTP&quot; yubikey will be a simpler solution for this camp.<br /></div><br /><br />That is certainly an easy solution.  I'm interested to see if the AES key can be pushed into the TPM chip and that way use the key in OTP mode.  <br /><br /><div class="quotetitle">Simon wrote:</div><div class="quotecontent"><br />Some are using Active Directory, which if I understand correctly, would mean that it is the server that needs to become yubikey-aware and not the client (or possibly both).<br /></div><br /><br />For logon to AD workstations, it's definitely both.  The interface needs to change on the client, and there needs to be quite a lot of infrastructure code on the domain side.<br /><br />But there are other scenarios.  The first simple one we are supporting is to use the yubikey as a second factor to log in to the extranet, preventing remote password attacks and access.  This solution would not change the way authentication to the workstations happens, only remote web authentication and VPN.<br /><br />I'm just trying to get a feel for what the priorities are of the community (potential customers)<br /><br />Simon if you don't want to field questions about Windows directly feel free to forward them to me at <!-- e --><a href="mailto:greg@collectivesoftware.com">greg@collectivesoftware.com</a><!-- e --><br /><br />Cheers!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=162">ferrix</a> — Mon Jun 30, 2008 3:28 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Simon]]></name></author>
<updated>2008-06-30T15:12:22+01:00</updated>
<published>2008-06-30T15:12:22+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=80&amp;p=378#p378</id>
<link href="https://forum.yubico.com/viewtopic.php?t=80&amp;p=378#p378"/>
<title type="html"><![CDATA[Re: YubiKey for Windows login?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=80&amp;p=378#p378"><![CDATA[
<div class="quotetitle">paul wrote:</div><div class="quotecontent"><br />* Secure a personal PC:<br /><br /> Convenience is the driver. People do not want to leave the PC w/o a password<br /> but do not like the hassle of remmebering &amp; typing the password.<br /></div><br /><br />Right.  I suspect that our &quot;static OTP&quot; yubikey will be a simpler solution for this camp.<br /><br />I've asked the people who want &quot;windows login&quot; what they mean, but it seems there are soo many things they can mean that I lose track.  I'm not a windows expert.  Some are using Active Directory, which if I understand correctly, would mean that it is the server that needs to become yubikey-aware and not the client (or possibly both).<br /><br />Doesn't windows support radius for login authentication?  If so, getting it to work should be relatively easy, at least for demonstration purposes, via our Pam module and FreeRadius.<br /><br />/Simon<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2">Simon</a> — Mon Jun 30, 2008 3:12 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[ferrix]]></name></author>
<updated>2008-06-28T01:20:43+01:00</updated>
<published>2008-06-28T01:20:43+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=80&amp;p=371#p371</id>
<link href="https://forum.yubico.com/viewtopic.php?t=80&amp;p=371#p371"/>
<title type="html"><![CDATA[Re: YubiKey for Windows login?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=80&amp;p=371#p371"><![CDATA[
<div class="quotetitle">paul wrote:</div><div class="quotecontent"><br />* Secure an enterprise PC:<br /><br /> 2nd-factor strong auth is the selling point. The PC can be online connected to a corp AD as well as off-line when you are travelling.<br /></div><br /><br />The only ways I can think of to allow offline access would be:<br /><br />1) Have the AES key in the machine's TPM store, and log on with local validation.  Neat but it's hard to administer because it requires a secure authority to visit each laptop and commit the AES key to storage.<br /><br />2) Just look at the public ID of the yubikey since we can't decrypt it without access to the AD server.  <br /><br />3) The default-- don't require yubikey to log in locally, but when we get back to the domain and try to access net resources, do the OTP then.<br />----<br /><br />This is the reason I want to have these discussions here.  Using symmetric encryption can be tricky because storage of the secret becomes important, and because it's impossible to evaluate the identity without knowledge of the secret or connection to (in this case) the domain.<br /><br />Or, were you talking about having the OTP validation connect out to a publically available server such as the Yubico one?  But I bet enterprises will not want to trust their identity security to an external company.<br /><br />I look forward to responses; trying to generate some good ideas and discussion so the product is as good as possible.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=162">ferrix</a> — Sat Jun 28, 2008 1:20 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[paul]]></name></author>
<updated>2008-06-28T01:10:22+01:00</updated>
<published>2008-06-28T01:10:22+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=80&amp;p=370#p370</id>
<link href="https://forum.yubico.com/viewtopic.php?t=80&amp;p=370#p370"/>
<title type="html"><![CDATA[Re: YubiKey for Windows login?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=80&amp;p=370#p370"><![CDATA[
In general it is like using a PC similar to using an ATM machine. Plug in the token, enter a simple/short PIN then you are in.<br /><br />The requests on Windows login go into 2 camps as you may already knew:<br /><br />* Secure an enterprise PC:<br /><br /> 2nd-factor strong auth is the selling point. The PC can be online connected to a corp AD as well as off-line when you are travelling.<br /><br />* Secure a personal PC:<br /><br /> Convenience is the driver. People do not want to leave the PC w/o a password<br /> but do not like the hassle of remmebering &amp; typing the password.<br /><br /> <img src="https://forum.yubico.com/images/smilies/icon_e_ugeek.gif" alt=":ugeek:" title="Uber Geek" /><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=55">paul</a> — Sat Jun 28, 2008 1:10 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[ferrix]]></name></author>
<updated>2008-06-25T14:04:30+01:00</updated>
<published>2008-06-25T14:04:30+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=80&amp;p=351#p351</id>
<link href="https://forum.yubico.com/viewtopic.php?t=80&amp;p=351#p351"/>
<title type="html"><![CDATA[Re: YubiKey for Windows login?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=80&amp;p=351#p351"><![CDATA[
Yeah well we are also happy to let the customers get keys directly from Yubico, and just license the software.  A better value for end users since they don't have to pay a percentage to us for the hardware.<br /><br />Simon (et al) could you post any details about requests you've received?   &quot;log in to windows&quot; is a very broad thing.  I'm assuming most people want to do this in an organization and log in to active directory.  But also some people may want to do this on their home (standalone) machines... I'm sure my fellow &quot;Security Now&quot; listeners probably fall into this &quot;enthusiast&quot; category..<br /><br />So any details will be very helpful as we do development.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=162">ferrix</a> — Wed Jun 25, 2008 2:04 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Simon]]></name></author>
<updated>2008-06-25T08:13:45+01:00</updated>
<published>2008-06-25T08:13:45+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=80&amp;p=339#p339</id>
<link href="https://forum.yubico.com/viewtopic.php?t=80&amp;p=339#p339"/>
<title type="html"><![CDATA[Re: YubiKey for Windows login?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=80&amp;p=339#p339"><![CDATA[
<div class="quotetitle">ferrix wrote:</div><div class="quotecontent"><br />My company is interested in building and selling a custom windows interactive authentication module (they are a lot of work).  But don't worry, it will be affordable, like the keys <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":)" title="Smile" /><br /></div><br /><br />Thanks!  This is exactly the kind of efforts that we from Yubico wants to encourage, companies should be able to develop applications or integration components and bundle them with yubikeys as a value-added service.  Yubico isn't a integration company, so this co-operation is excellent for us.  We have many potential customers asking for Windows login, and if you or someone else develops a solution for it, we'll send these customers your way.<br /><br />/Simon<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2">Simon</a> — Wed Jun 25, 2008 8:13 am</p><hr />
]]></content>
</entry>
</feed>