<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=5&amp;t=1177" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2013-09-27T08:54:02+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=5&amp;t=1177</id>
<entry>
<author><name><![CDATA[Tom]]></name></author>
<updated>2013-09-27T08:54:02+01:00</updated>
<published>2013-09-27T08:54:02+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1177&amp;p=4412#p4412</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1177&amp;p=4412#p4412"/>
<title type="html"><![CDATA[Re: Self installed KSM Is working, but VAL says BAD_OTP]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1177&amp;p=4412#p4412"><![CDATA[
This is very common in PHP, however you are right we should make it less sensitive to this kind of stuff.<br /><br />We will look into it and fix it.<br /><br />Regards,<br />Tom<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2195">Tom</a> — Fri Sep 27, 2013 8:54 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[andy]]></name></author>
<updated>2013-09-26T10:55:51+01:00</updated>
<published>2013-09-26T10:55:51+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1177&amp;p=4407#p4407</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1177&amp;p=4407#p4407"/>
<title type="html"><![CDATA[Re: Self installed KSM Is working, but VAL says BAD_OTP]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1177&amp;p=4407#p4407"><![CDATA[
the KSM is outputting empty lines before OK<br /><br />found the problem right now..<br /><br />and empty line and the end of config-db.php of the ksm<br /><br />maybe the validation server should trim all empty lines from the ksm output. then this cant happen anymore.<br /><br />regards<br />-andy<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2603">andy</a> — Thu Sep 26, 2013 10:55 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[andy]]></name></author>
<updated>2013-09-26T10:21:25+01:00</updated>
<published>2013-09-26T10:21:25+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1177&amp;p=4406#p4406</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1177&amp;p=4406#p4406"/>
<title type="html"><![CDATA[Re: Self installed KSM Is working, but VAL says BAD_OTP]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1177&amp;p=4406#p4406"><![CDATA[
Here is the debug output frmo yk log. Maybe i found the error. <br /><br />Sep 26 11:14:42 radiusa ykval[13672]: LOG_INFO:ykval-verify:[10.20.30.17] Request: <div class="codetitle"><b>Code:</b></div><div class="codecontent">id=1&amp;nonce=7sdmalkasmdlakmsdaasklmdlak&amp;otp=cccccccccccbbuitiicgkkdjfdilgcrueteffbhbcukf (at 2013-09-26T11:14:42+02:00 0.27085300 1380186882) HTTP<br />Sep 26 11:14:42 radiusa ykval&#91;13672&#93;: LOG_DEBUG:ykval-verify:&#91;10.20.30.17&#93; found protocol version 2<br />Sep 26 11:14:42 radiusa ykval&#91;13672&#93;: LOG_DEBUG:ykval-verify:synclib:db:&#91;10.20.30.17&#93; &#91;cccccccccccbbuitiicgkkdjfdilgcrueteffbhbcukf&#93; DB query is: SELECT id, secret FROM clients WHERE active='1' AND id='1'<br />Sep 26 11:14:42 radiusa ykval&#91;13672&#93;: LOG_DEBUG:ykval-verify:&#91;10.20.30.17&#93; &#91;cccccccccccbbuitiicgkkdjfdilgcrueteffbhbcukf&#93; Client data: id=1  secret=s+RKv23R5l0oyyW81GSHP34ENzM= <br />Sep 26 11:14:42 radiusa ykval&#91;13672&#93;: LOG_DEBUG:ykval-verify:&#91;10.20.30.17&#93; &#91;cccccccccccbbuitiicgkkdjfdilgcrueteffbhbcukf&#93; YK-KSM adding URL : http://localhost/wsapi/decrypt?otp=cccccccccccbbuitiicgkkdjfdilgcrueteffbhbcukf<br />Sep 26 11:14:42 radiusa ykval&#91;13672&#93;: LOG_DEBUG:ykval-verify:&#91;10.20.30.17&#93; &#91;cccccccccccbbuitiicgkkdjfdilgcrueteffbhbcukf&#93; YK-KSM curl multi info :  msg=1  result=0  handle=Resource id #10 <br />Sep 26 11:14:42 radiusa ykval&#91;13672&#93;: LOG_DEBUG:ykval-verify:&#91;10.20.30.17&#93; &#91;cccccccccccbbuitiicgkkdjfdilgcrueteffbhbcukf&#93; YK-KSM curl multi content : #012#012OK counter=0001 low=888a high=1c use=02<br />Sep 26 11:14:42 radiusa ykval&#91;13672&#93;: LOG_DEBUG:ykval-verify:&#91;10.20.30.17&#93; &#91;cccccccccccbbuitiicgkkdjfdilgcrueteffbhbcukf&#93; YK-KSM curl multi info :  msg=1  result=0  handle=Resource id #11 <br />Sep 26 11:14:42 radiusa ykval&#91;13672&#93;: LOG_DEBUG:ykval-verify:&#91;10.20.30.17&#93; &#91;cccccccccccbbuitiicgkkdjfdilgcrueteffbhbcukf&#93; YK-KSM curl multi content : #012#012OK counter=0001 low=888a high=1c use=02<br />Sep 26 11:14:43 radiusa ykval&#91;13672&#93;: LOG_DEBUG:ykval-verify:&#91;10.20.30.17&#93; &#91;cccccccccccbbuitiicgkkdjfdilgcrueteffbhbcukf&#93; YK-KSM response:  #012#012OK counter=0001 low=888a high=1c use=02#012 <br />Sep 26 11:14:43 radiusa ykval&#91;13672&#93;: LOG_DEBUG:ykval-verify:&#91;10.20.30.17&#93; &#91;cccccccccccbbuitiicgkkdjfdilgcrueteffbhbcukf&#93; SIGN: status=BAD_OTP&amp;t=2013-09-26T09:14:43Z0286 H=E+rCN0K3asRbXyPVvae2lHxK+hk=<br />Sep 26 11:14:43 radiusa ykval&#91;13672&#93;: LOG_INFO:ykval-verify:&#91;10.20.30.17&#93; &#91;cccccccccccbbuitiicgkkdjfdilgcrueteffbhbcukf&#93; Response: h=E+rCN0K3asRbXyPVvae2lHxK+hk=#015#012t=2013-09-26T09:14:43Z0286#015#012status=BAD_OTP#015#012#015#012 (at 2013-09-26T09:14:43+00:00 0.28631400 1380186883)<br /></div><br /><br />on the line YK-KSM response there is the String <strong>#012#012OK</strong> which should be just <strong>OK</strong><br /><br />no idea where this is coming from. any ideas?<br /><br />regards<br />-andy<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2603">andy</a> — Thu Sep 26, 2013 10:21 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[andy]]></name></author>
<updated>2013-09-26T10:53:46+01:00</updated>
<published>2013-09-26T09:17:29+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1177&amp;p=4405#p4405</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1177&amp;p=4405#p4405"/>
<title type="html"><![CDATA[Self installed KSM Is working, but VAL says BAD_OTP]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1177&amp;p=4405#p4405"><![CDATA[
Hello all,<br /><br />I have build my own rpms, installed and configured my KSM and VAL Server. The KSM Works<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">curl 'http://localhost/wsapi/decrypt?otp=cccccccccccbrrhldidnubirljgdfrhbkffdtuuduebu'<br /><br /><br />OK counter=0001 low=dbcc high=9d use=00<br /></div><br /><br />when using the validation server<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">wget -q -O - 'http://localhost/wsapi/2.0/verify?id=1&amp;nonce=asdmalkasmdlakmsdaasklmdlak&amp;otp=cccccccccccbghugkrcvnnefhtbvuhtttcdkneklvcdt'</div><br />i am getting the following syslog messages<br /><br />Successful KSM operation<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Sep 26 10:15:21 radiusa ykval&#91;13673&#93;: LOG_INFO:ykval-verify:&#91;::1&#93; Request: id=1&amp;nonce=asdmalkasmdlakmsdaasklmdlak&amp;otp=cccccccccccbghugkrcvnnefhtbvuhtttcdkneklvcdt (at 2013-09-26T10:15:21+02:00 0.75502000 1380183321) HTTP<br />Sep 26 10:15:21 radiusa ykksm&#91;13674&#93;: SUCCESS OTP cccccccccccbghugkrcvnnefhtbvuhtttcdkneklvcdt PT bedf73fb07b70100727bf0021d3f60c6 OK counter=0001 low=7b72 high=f0 use=02<br /></div><br /><br />Error on VAL<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Sep 26 10:15:22 radiusa ykval&#91;13673&#93;: LOG_INFO:ykval-verify:&#91;::1&#93; &#91;cccccccccccbghugkrcvnnefhtbvuhtttcdkneklvcdt&#93; Response: h=PWxygAr5h+W/ogQEQT2b2vZqZF0=#015#012t=2013-09-26T08:15:22Z0771#015#012status=BAD_OTP#015#012#015#012 (at 2013-09-26T08:15:22+00:00 0.77224500 1380183322)</div><br /><br />I have tried alot already and i have no idea what is going wrong. The only thing what should be true is, that he status=BAD_OTP is not true..<br /><br />any idea how to troubleshoot this?<br /><br />thanks<br />-andy<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2603">andy</a> — Thu Sep 26, 2013 9:17 am</p><hr />
]]></content>
</entry>
</feed>