<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=4&amp;t=1027" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2013-04-08T09:02:22+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=4&amp;t=1027</id>
<entry>
<author><name><![CDATA[Tom]]></name></author>
<updated>2013-04-08T09:02:22+01:00</updated>
<published>2013-04-08T09:02:22+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1027&amp;p=3870#p3870</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1027&amp;p=3870#p3870"/>
<title type="html"><![CDATA[Re: [QUESTION] Establishing shared secret for Password Safe]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1027&amp;p=3870#p3870"><![CDATA[
The first one use HMAC-SHA1 algorithm. <!-- m --><a class="postlink" href="http://tools.ietf.org/html/rfc2104">http://tools.ietf.org/html/rfc2104</a><!-- m --><br /><br />Read carefully steps 4-7 and you will see how this works in combination with password safe.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2195">Tom</a> — Mon Apr 08, 2013 9:02 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[beckettsmusic]]></name></author>
<updated>2013-04-06T20:27:46+01:00</updated>
<published>2013-04-06T20:27:46+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1027&amp;p=3866#p3866</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1027&amp;p=3866#p3866"/>
<title type="html"><![CDATA[[QUESTION] Establishing shared secret for Password Safe]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1027&amp;p=3866#p3866"><![CDATA[
I'm not sure I understand how the Yubikey works with Password Safe.  There appear to be two different descriptions of how to set up a Yubikey to work with Password Safe:  one at<br /><br /><a href="http://www.yubico.com/applications/password-management/consumer/password-safe/" class="postlink">http://www.yubico.com/applications/password-management/consumer/password-safe/</a><br /><br />which describes using the personalization tool to establish a challenge response configuration and create a 20 byte secret key, and another in Yubico's video, at<br /><br /><a href="https://www.youtube.com/watch?v=m6bza2bXnz4" class="postlink">https://www.youtube.com/watch?v=m6bza2bXnz4</a><br /><br />where Password Safe is used to generate a secret key and write it back to the Yubikey.<br /><br />I can see how the second method works:  both Password Safe and the Yubikey share the secret when the configuration procedure is complete.  However, in the case of the first method, I don't see how the secret key becomes known to Password Safe.  If the key isn't shared, how can Password Safe verify the Yubikey response when a password database is to be opened?<br /><br />BM<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2396">beckettsmusic</a> — Sat Apr 06, 2013 8:27 pm</p><hr />
]]></content>
</entry>
</feed>