<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=4&amp;t=903" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2013-08-29T10:14:48+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=4&amp;t=903</id>
<entry>
<author><name><![CDATA[tommy]]></name></author>
<updated>2013-08-29T10:14:48+01:00</updated>
<published>2013-08-29T10:14:48+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=903&amp;p=4314#p4314</id>
<link href="https://forum.yubico.com/viewtopic.php?t=903&amp;p=4314#p4314"/>
<title type="html"><![CDATA[Re: YubiRADIUS 3.6 - assinging new tokens issue]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=903&amp;p=4314#p4314"><![CDATA[
I have the same problem with 3.6.1 <img src="https://forum.yubico.com/images/smilies/icon_cry.gif" alt=":cry:" title="Crying or Very Sad" /> <br /><br /><ul><li>user import from active directory works without a problem.</li></ul><ul><li>&quot;Validate OTP&quot; from the troubleshoot works also.</li></ul><br />But if I try to assign a new yubikey I got this error message:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Error in adding the key mapping : Unknown error</div><br />Auto-provisioning is not working too.<br /><br />I did setup yubiradius last year about 10 times without a problem, but this time with this version I am going crazy.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2561">tommy</a> — Thu Aug 29, 2013 10:14 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[samir]]></name></author>
<updated>2013-04-10T16:05:11+01:00</updated>
<published>2013-04-10T16:05:11+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=903&amp;p=3883#p3883</id>
<link href="https://forum.yubico.com/viewtopic.php?t=903&amp;p=3883#p3883"/>
<title type="html"><![CDATA[Re: YubiRADIUS 3.6 - assinging new tokens issue]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=903&amp;p=3883#p3883"><![CDATA[
Hello,<br /><br />The Client ID and API key will need to be provided as per the selected validation server.<br /><br />For Local Validation Server on YubiRADIUS Virtual Appliance:<br />Client ID: 1<br />API Key: &quot;IXazp2MoffwFYj/pfcc+v20SMVc=&quot; (without quotes)<br /><br />For YubiCloud - Online Validation Server:<br />Client ID: 4233<br />API Key: &quot;H9xX7BeTIbhYK3xCb/PSEeRVNvY=&quot; (without quotes)<br /><br />If you are using Local Validation Server then you need to import the YubiKeys in YubiRADIUS and no need to import the YubiKeys in YubiRADIUS if you are using YubiCloud - Online Validation Server.<br /><br />To import the YubiKeys in YubiRADIUS local validation server please follow the steps below:<br />Go to YubiRADIUS &gt;&gt; click on &quot;Import YubiKeys&quot; tab &gt;&gt; select the &quot;Log file source&quot; &gt;&gt; locate the appropriate log file &gt;&gt; click on &quot;Upload&quot; button.<br /><br />Go to &quot;List YubiKeys&quot; tab which contains all the imported YubiKey public id and confirm that the YubiKey which you want to use with YubiRADIUS is imported.<br /><br />To check for OTP validation:<br />Go to YubiRADIUS &gt;&gt; click on &quot;Troubleshoot&quot; &gt;&gt; go to &quot;Validate OTP&quot; section &gt;&gt; Enter the OTP in &quot;YubiKey OTP&quot; field &gt;&gt; click on &quot;Validate&quot; button.<br /><br />If OTP validation is successful then import the users from AD/LDAP and assign the YubiKey to the user.<br /><br />To assign the YubiKey to user:<br />Go to YubiRADIUS &gt;&gt; click on &quot;Domain&quot; &gt;&gt; select the domain name &gt;&gt; select the user from the user list &gt;&gt; click on &quot;Assign a new YubiKey&quot; option &gt;&gt; enter the Login name in &quot;Login Name&quot; field &gt;&gt; enter the YubiKey OTP in &quot;YubiKey OTP&quot; field  &gt;&gt; click on &quot;create&quot; button.<br /><br />To check two factor authentication:<br />Go to YubiRADIUS &gt;&gt; click on &quot;Troubleshoot&quot; &gt;&gt; enter the username in &quot;Username&quot; field (if you have multiple domains then please enter the username as &quot;username@domainname&quot; (without quotes)) &gt;&gt; enter the password in the &quot;Password&quot; field &gt;&gt; enter the YubiKey OTP in &quot;YubiKey OTP&quot; field &gt;&gt; click on &quot;Send Request&quot; button.<br /><br />To generate Temporary Token:<br />Go to YubiRADIUS &gt;&gt; click on &quot;Domain&quot; &gt;&gt; select the domain name &gt;&gt; select the user from the user list &gt;&gt; click on &quot;Temporary token settings&quot; &gt;&gt; select &quot;Enable Temporary Token&quot; option to &quot;Yes&quot; &gt;&gt; click on &quot;Generate&quot; button &gt;&gt; enter the expiry date of token in &quot;Temporary Token Expiry After&quot; field &gt;&gt; enter the &quot;Maximum Authentications Allowed&quot; as per your requirement &gt;&gt; click on &quot;Save&quot; button.<br /><br />Please write to &quot;support@yubico.com&quot; if you have further questions.<br /><br />Thanks and best regards,<br />Samir.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1076">samir</a> — Wed Apr 10, 2013 4:05 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[HardKnoX]]></name></author>
<updated>2013-01-14T20:26:49+01:00</updated>
<published>2013-01-14T20:26:49+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=903&amp;p=3454#p3454</id>
<link href="https://forum.yubico.com/viewtopic.php?t=903&amp;p=3454#p3454"/>
<title type="html"><![CDATA[Re: YubiRADIUS 3.6 - assinging new tokens issue]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=903&amp;p=3454#p3454"><![CDATA[
Hi;<br /><br />I have figured out some more since the last post I found that the default configuration of the 3.6 Radius VM is to verify the token key against it self I have changed that and and I also noticed that the customer ID was set to 1 instead of 4233, now I get the following message;<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Validate OTP Response:<br />Last Client Query:<br />http://api.yubico.com/wsapi/2.0/verify?id=4233&amp;nonce=(-Removed-)=<br />Server Responses:<br />Authentication Failed!<br />Error message: NO_VALID_ANSWER</div><br /><br />We looked for any other default misconfigured properties but could not find any that could explain why it is failing. <br /><br />Are there any new updates available that would fix this issue are does anybody know what I need to do to get it fixed?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2208">HardKnoX</a> — Mon Jan 14, 2013 8:26 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[HardKnoX]]></name></author>
<updated>2013-01-06T23:11:34+01:00</updated>
<published>2013-01-06T23:11:34+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=903&amp;p=3438#p3438</id>
<link href="https://forum.yubico.com/viewtopic.php?t=903&amp;p=3438#p3438"/>
<title type="html"><![CDATA[Re: YubiRADIUS 3.6 - assinging new tokens issue]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=903&amp;p=3438#p3438"><![CDATA[
Do you need the whole log files or just the last 100 lines shortly after the token assigned attempt was done?<br /><br />Also we noticed the following error when we used the troubleshooting tool;<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Troubleshoot – Validate OTP<br /><br />Validate OTP Response:<br />Last Client Query:<br />http://127.0.0.1/wsapi/2.0/verify?id=1&amp;nonce=f54266b6ff59faee493a1504b4b1d22d&amp;otp=&#91;token removed&#93;&amp;h=EYhPUCUuS4XFRCB2GsEPtS2nV6s=<br />Server Responses:<br />Authentication Failed!<br />Error message: NO_VALID_ANSWER</div><br /><br />I removed the token from the message above ( ignore [token removed])<br /><br />The &quot;127.0.0.1&quot; bit is api.yubico.com on our 3.5.4 Radius server which would explain why it failing as its using itself to verify the token instead of the cloud service.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2208">HardKnoX</a> — Sun Jan 06, 2013 11:11 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[samir]]></name></author>
<updated>2013-01-04T12:26:41+01:00</updated>
<published>2013-01-04T12:26:41+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=903&amp;p=3416#p3416</id>
<link href="https://forum.yubico.com/viewtopic.php?t=903&amp;p=3416#p3416"/>
<title type="html"><![CDATA[Re: YubiRADIUS 3.6 - assinging new tokens issue]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=903&amp;p=3416#p3416"><![CDATA[
Hello,<br /><br />We have never heard of such a problem before, we are very interested to diagnose any potential failures. Can you please send us the following logs to &quot;support@yubico.com&quot; to analyze the issue?<br /><br />1. Please configure the log files with the following settings from the webmin console:<br />1. Login to webmin<br />2. Go to &quot;System&quot; &gt;&gt; &quot;System Logs&quot;<br />3. Click on log file (ykropval.log ,etc. mentioned below)<br />4. Select &quot;all&quot; option in &quot;priorities&quot; field of &quot;Message types to log&quot; section<br />5. Please click on &quot;save&quot; button to save the changes.<br />6. Please repeat step 3, 4 and 5 for other log files mentioned below.<br />7. Please click on &quot;Apply Changes&quot; button on System Logs page<br />8. Go to &quot;Servers&quot; &gt;&gt; &quot;YubiRADIUS Virtual Appliance&quot;<br />9. Navigate 'Global Configuration' &gt;&gt; 'FreeRADIUS' menu, please enable FreeRADIUS Logging<br />10. Could you please ssh to the YRVA instance and restart the rsyslog process by executing the following command:<br />    /etc/init.d/rsyslog restart<br />11. Please try to add the user and test the user with YubiKey credentials.<br /><br />Please send us the following log files:<br />/var/log/syslog<br />/var/log/messages<br />/var/log/ykval.log<br />/var/log/ykropval.log<br />/var/log/ykmap.log<br />/var/log/freeradius/radius.log<br />/var/log/postgresql/postgresql-8.4-main.log<br />/var/log/apache2/error.log<br />/var/log/apache2/access.log<br />/var/log/debug<br /><br />2. If you have already configure the webmin logs, please send &quot;webmin.debug&quot; file available at /var/webmin/webmin.debug<br /><br />If not please configure the log file with the following settings from the webmin console: <br />1. Login to webmin<br />2. Go to &quot;Webmin&quot; &gt;&gt; &quot;Webmin Configuration&quot;<br />3. Please Click on &quot;Debugging Log File&quot;<br />4. Please Click on &quot;yes&quot; option of &quot;Debug log enabled?&quot; <br />5. Please click on &quot;save&quot; button to save the changes.<br />6. Please once again Import Users.<br /><br />Please find the &quot;webmin.debug&quot; file at /var/webmin/webmin.debug<br /><br />3. Please brief on any other observations and please send the screen shots, error messages observed.<br /><br />Thanks and best regards,<br />Samir.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1076">samir</a> — Fri Jan 04, 2013 12:26 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[HardKnoX]]></name></author>
<updated>2013-01-04T04:32:20+01:00</updated>
<published>2013-01-04T04:32:20+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=903&amp;p=3414#p3414</id>
<link href="https://forum.yubico.com/viewtopic.php?t=903&amp;p=3414#p3414"/>
<title type="html"><![CDATA[YubiRADIUS 3.6 - assinging new tokens issue]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=903&amp;p=3414#p3414"><![CDATA[
Hi;<br /><br />I'm trying to use the new YubiRADIUS 3.6 build, freshly installed from scratch. Newly installed because the upgrade from 3.5.4 to 3.6 failed.  <br /><br />Now with the freshly installed 3.6 I'm getting the following error when I'm trying to assign a token to a user account;<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Error in adding the key mapping : Unknown error</div><br /><br />We can add a domain (eg: acme.local), we can set AD import and successfully import users however no matter what we do we cannot assign a token to an acme.local user. <br /><br />I got the same error yesterday while we were playing with 3.5.4 and I had the DNS server misconfigured however it took longer to show, where as under 3.6 the DNS settings are correct and the MS AD user accounts imported all as expected. <br /><br />Is this a known issue with 3.6 and if so are there any fixes available for it?<br /><br />I think I'm going to stick with 3.5.4 for now.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2208">HardKnoX</a> — Fri Jan 04, 2013 4:32 am</p><hr />
]]></content>
</entry>
</feed>