<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=3&amp;t=1272" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2014-01-08T11:14:24+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=3&amp;t=1272</id>
<entry>
<author><name><![CDATA[Klas]]></name></author>
<updated>2014-01-08T11:14:24+01:00</updated>
<published>2014-01-08T11:14:24+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1272&amp;p=4779#p4779</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1272&amp;p=4779#p4779"/>
<title type="html"><![CDATA[Re: Response does not contain nonce when BAD_OTP]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1272&amp;p=4779#p4779"><![CDATA[
Hello,<br /><br />OTP is not included in the case of BAD_OTP to avoid echoing a potentially mallicious string to the client (as it's failed the validation servers sanity check). And the same goes for the other error conditions where inputs might not have been sanitized yet.<br /><br />/klas<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2019">Klas</a> — Wed Jan 08, 2014 11:14 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[sigfrid]]></name></author>
<updated>2014-01-02T09:38:08+01:00</updated>
<published>2014-01-02T09:38:08+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1272&amp;p=4761#p4761</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1272&amp;p=4761#p4761"/>
<title type="html"><![CDATA[Response does not contain nonce when BAD_OTP]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1272&amp;p=4761#p4761"><![CDATA[
Hello everyone.<br /><br />I'm working on integrating YubiKey into our new platform and I'd like to know if it is by design that the response from YubiCloud does not contain <strong>nonce</strong> (and <strong>otp</strong>) when status is <strong>BAD_OTP</strong>. <br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">&quot;h=rXCkSVYHYUYk+Ju5MvaVSKRhhgY=\r\nt=2014-01-02T08:20:07Z0339\r\nstatus=BAD_OTP\r\n\r\n&quot;</div><br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">&quot;h=ltwiOKRC5X62g8HBDw9+CdxE/0Q=\r\nt=2014-01-02T08:20:05Z0697\r\notp=ccccccbtcvvhgnvvbivkdfkrddgnikfkdhjlhgeinhlb\r\nnonce=58a74a555932b9bca389ff3fd5ac6c2d\r\nstatus=REPLAYED_OTP\r\n\r\n&quot;</div><br /><br />Looking at the documentation (<a href="https://github.com/Yubico/yubikey-val/wiki/ValidationProtocolV20#response" class="postlink">https://github.com/Yubico/yubikey-val/wiki/ValidationProtocolV20#response</a>) nowhere this is mentioned.<br />If it is unintentional, do you plan to include none (and otp) in BAD_OPT responses anytime soon?<br /><br /><br />Thanks<br /><br />Sigfrid<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2757">sigfrid</a> — Thu Jan 02, 2014 9:38 am</p><hr />
]]></content>
</entry>
</feed>