<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=5&amp;t=843" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2012-11-27T06:36:29+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=5&amp;t=843</id>
<entry>
<author><name><![CDATA[kevbo]]></name></author>
<updated>2012-11-27T06:36:29+01:00</updated>
<published>2012-11-27T06:36:29+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=843&amp;p=3357#p3357</id>
<link href="https://forum.yubico.com/viewtopic.php?t=843&amp;p=3357#p3357"/>
<title type="html"><![CDATA[Re: YubiRadiusVA - Authentication fails if one of the YRVA f]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=843&amp;p=3357#p3357"><![CDATA[
So, I'm finally back to this.<br /><br />I don't understand, well, several things:<br />1) Why do you recommend 4?  If you have 4 running, how many can be _failed_ and have authentication still proceed?<br />2) I don't understand the &quot;25%&quot; setting.  The .php file seems to default to 60%, so at the very least, for the 25% setting to stick, I'd need to edit both the file and the template, right?  If this is a setting that users will need to change, maybe it should be in the GUI?<br />3) To continue, I don't understand what that setting means.  Can you explain what it means?<br />4) I only have 3 physical machines.  Making more VMs than that seems kind of silly.  Can I set it up so that there are 3 VMs in the cluster and a user can be validated if only 2 of the 3 are responding?  How would I do that?  (I can't figure out a reliable way to do this with my 3 machines without setting at least 2 VMs up on each physical machine....I want my authentication to proceed if one of my physical machines is down, regardless.  I need to be able to reboot them every once in a while.)<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2105">kevbo</a> — Tue Nov 27, 2012 6:36 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[kevbo]]></name></author>
<updated>2012-08-13T20:06:49+01:00</updated>
<published>2012-08-13T20:06:49+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=843&amp;p=3219#p3219</id>
<link href="https://forum.yubico.com/viewtopic.php?t=843&amp;p=3219#p3219"/>
<title type="html"><![CDATA[Re: YubiRadiusVA - Authentication fails if one of the YRVA f]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=843&amp;p=3219#p3219"><![CDATA[
Out of curiosity, how do you get to a minimum of 4?  I could see three.<br /><br />Also, I want to make sure I understand how to set up the synchronization in the YubiRadius GUI.  Does _each_ server need a shared secret with _each other_ server?<br /><br />So, if you have two servers:<br /><br />A has a secret for B listed<br />B has a secret for B listed<br /><br />If you have three servers:<br /><br />A has a secret for B listed<br />A has a secret for C listed<br />B has a secret for A listed<br />B has a secret for C listed<br />C has a secret for A listed<br />C has a secret for B listed<br /><br />And 12 for 4 servers...<br /><br />Is that right?<br /><br />Kevin<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2105">kevbo</a> — Mon Aug 13, 2012 8:06 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[samir]]></name></author>
<updated>2012-08-13T11:01:46+01:00</updated>
<published>2012-08-13T11:01:46+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=843&amp;p=3216#p3216</id>
<link href="https://forum.yubico.com/viewtopic.php?t=843&amp;p=3216#p3216"/>
<title type="html"><![CDATA[Re: YubiRadiusVA - Authentication fails if one of the YRVA f]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=843&amp;p=3216#p3216"><![CDATA[
Hello,<br /><br />We do not recommend customers to use only two servers for synchronization because if one server is down, all data will be centralized to the remaining server and if that server also fails then there will be data loss. If you still interested in using 2 servers for synchronization, please set the sync level to 0. We recommend you to have four servers and set the sync level to 25% to have each request sync with at least one other server.<br /><br />You can set the default sync level required in the validation server(s) but the clients can also tell the servers how much sync they require per request<br /><br />For more information about the sync level, please refer the below link: <!-- m --><a class="postlink" href="http://code.google.com/p/yubikey-val-server-php/">http://code.google.com/p/yubikey-val-server-php/</a><!-- m --><br /><br />Here are the step by step instructions to set the sync level.<br /><br />1) SSH to the YubiRADIUS<br /><br />2) Navigate to the location '/etc/ykval'<br /><br />3) Open the ykval-config.php file <br /><br /># vim ykval-config.php<br /><br />4) Set the $baseParams['__YKVAL_SYNC_DEFAULT_LEVEL__'] value as per your requirement.<br /><br />5) Save the file <br /><br />6) restart the ykval sync service <br /><br />/etc/init.d/ykval-queue restart<br /><br />Hope this helps!<br /><br />Thanks and best regards,<br />Samir.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1076">samir</a> — Mon Aug 13, 2012 11:01 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[kevbo]]></name></author>
<updated>2012-08-10T18:55:14+01:00</updated>
<published>2012-08-10T18:55:14+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=843&amp;p=3211#p3211</id>
<link href="https://forum.yubico.com/viewtopic.php?t=843&amp;p=3211#p3211"/>
<title type="html"><![CDATA[Re: YubiRadiusVA - Authentication fails if one of the YRVA f]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=843&amp;p=3211#p3211"><![CDATA[
Sorry to be a pain, but Yubico: bump?<br /><br />This actually makes a cluster less useful than a single machine, because now, if one goes out, they both do.<br /><br />Is there something wrong with the software, or the configuration?<br /><br />We want to go live with this next week, and we're seriously considering taking down the mirror machine.<br /><br />Thanks.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2105">kevbo</a> — Fri Aug 10, 2012 6:55 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[kevbo]]></name></author>
<updated>2012-08-09T14:47:28+01:00</updated>
<published>2012-08-09T14:47:28+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=843&amp;p=3205#p3205</id>
<link href="https://forum.yubico.com/viewtopic.php?t=843&amp;p=3205#p3205"/>
<title type="html"><![CDATA[Re: YubiRadiusVA - Authentication fails if one of the YRVA f]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=843&amp;p=3205#p3205"><![CDATA[
I was just logging in to ask the exact same question.  Odd.<br /><br />We thought that the VPN appliance wasn't properly failing over, until we dug into the logs and noticed the same behavior as you: server 2 quits sending status=OK when server 1 is down, and instead sends status=NOT_ENOUGH_ANSWERS.  Bring server 1 back up, and server 2 starts working.<br /><br />Kind of the opposite of what we want.<br /><br />One thing that I wasn't sure about&#058; I set up synchronization parameters on each unit.  Was that right, or should synchronization only be set up one-way?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2105">kevbo</a> — Thu Aug 09, 2012 2:47 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[remcobierings]]></name></author>
<updated>2012-08-09T13:56:13+01:00</updated>
<published>2012-08-09T13:56:13+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=843&amp;p=3204#p3204</id>
<link href="https://forum.yubico.com/viewtopic.php?t=843&amp;p=3204#p3204"/>
<title type="html"><![CDATA[YubiRadiusVA - Authentication fails if one of the YRVA fails]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=843&amp;p=3204#p3204"><![CDATA[
We've got two YubiRadius VirtualAppliances which are in sync.<br />But when i shutdown one of the two YRVA, authentification fails on the running still running YRVA.<br /><br />The IP adresses of the YRVA are: <br />172.30.66.72 yubico01.iam.ia <br />172.30.66.73 yubico02.iam.ia<br /><br />I've added some logging of the working and not working situation:<br /><br />Working situation (2 active in sync YRVA):<br /><span style="font-size: 80%; line-height: normal"><div class="codetitle"><b>Code:</b></div><div class="codecontent">Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_INFO:ykval-verify:&#91;127.0.0.1&#93; Request: id=1&amp;nonce=dbd034d222b3837618a4c46f2726aaa2&amp;otp=--- MY YUBIKEY OTP ---&amp;h=f9QhPNglNI45%2BC6zzkblZA38%2BXE= (at 2012-08-<br /><br />09T10:54:39+02:00 0.70370900 1344502479) HTTP<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_DEBUG:ykval-verify:synclib:db:&#91;127.0.0.1&#93; &#91;--- MY YUBIKEY OTP ---&#93; DB query is: SELECT id, secret FROM clients WHERE active AND id='1'<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_DEBUG:ykval-verify:&#91;127.0.0.1&#93; &#91;--- MY YUBIKEY OTP ---&#93; Client data: id=1  secret=s1lgixvlvNAtrqJeYH4VPLkJxT0=<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_DEBUG:ykval-common:SIGN: id=1&amp;nonce=dbd034d222b3837618a4c46f2726aaa2&amp;otp=--- MY YUBIKEY OTP --- H=f9QhPNglNI45+C6zzkblZA38+XE=<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_DEBUG:ykval-verify:&#91;127.0.0.1&#93; &#91;--- MY YUBIKEY OTP ---&#93; Decrypted OTP: session_counter=10  low=53616  high=114  session_use=5<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_INFO:ykval-verify:synclib:&#91;127.0.0.1&#93; &#91;--- MY YUBIKEY OTP ---&#93; searching for yk_publicname --- MY YUBIKEY --- in local db<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_DEBUG:ykval-verify:synclib:db:&#91;127.0.0.1&#93; &#91;--- MY YUBIKEY OTP ---&#93; DB query is: SELECT * FROM yubikeys WHERE yk_publicname = '--- MY YUBIKEY ---' LIMIT 1<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_INFO:ykval-verify:synclib:&#91;127.0.0.1&#93; &#91;--- MY YUBIKEY OTP ---&#93; yubikey found in db  modified=1344502391 nonce=6e9d071896eea37f8f7516954613aa3e yk_publicname=--- MY YUBIKEY <br /><br />--- yk_counter=10 yk_use=4 yk_high=114 yk_low=52911<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_DEBUG:ykval-verify:&#91;127.0.0.1&#93; &#91;--- MY YUBIKEY OTP ---&#93; Auth data: modified=1344502391  nonce=6e9d071896eea37f8f7516954613aa3e  active=1  yk_publicname=--- MY YUBIKEY ---  <br /><br />yk_counter=10  yk_use=4  yk_high=114  yk_low=52911<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_DEBUG:ykval-verify:synclib:db:&#91;127.0.0.1&#93; &#91;--- MY YUBIKEY OTP ---&#93; DB query is: UPDATE yubikeys SET  modified='1344502479', yk_counter='10', yk_use='5', yk_low='53616', <br /><br />yk_high='114', nonce='dbd034d222b3837618a4c46f2726aaa2' WHERE yk_publicname = '--- MY YUBIKEY ---' and (10&gt;yk_counter or (10=yk_counter and 5&gt;yk_use))<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_INFO:ykval-verify:synclib:&#91;127.0.0.1&#93; &#91;--- MY YUBIKEY OTP ---&#93; updated database  modified=1344502479 nonce=dbd034d222b3837618a4c46f2726aaa2 yk_publicname=--- MY YUBIKEY --- <br /><br />yk_counter=10 yk_use=5 yk_high=114 yk_low=53616<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_DEBUG:ykval-verify:synclib:db:&#91;127.0.0.1&#93; &#91;--- MY YUBIKEY OTP ---&#93; DB query is: INSERT INTO queue (queued,modified,otp,server,server_nonce,info) VALUES <br /><br />('1344502479','1344502479','--- MY YUBIKEY OTP ---','http://172.30.66.73/wsapi/2.0/sync','8bb7650ce1a22250609b600c26ab8401','yk_publicname=--- MY YUBIKEY ---<br /><br />&amp;yk_counter=10&amp;yk_use=5&amp;yk_high=114&amp;yk_low=53616&amp;nonce=dbd034d222b3837618a4c46f2726aaa2,local_counter=10&amp;local_use=4')<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_DEBUG:ykval-verify:synclib:db:&#91;127.0.0.1&#93; &#91;--- MY YUBIKEY OTP ---&#93; DB query is: SELECT * FROM queue WHERE modified = '1344502479' and server_nonce = <br /><br />'8bb7650ce1a22250609b600c26ab8401'<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_DEBUG:ykval-verify:synclib:&#91;127.0.0.1&#93; &#91;--- MY YUBIKEY OTP ---&#93; url in retrieveURLasync is http://172.30.66.73/wsapi/2.0/sync?otp=--- MY YUBIKEY OTP ---<br /><br />&amp;modified=1344502479&amp;yk_publicname=--- MY YUBIKEY ---&amp;yk_counter=10&amp;yk_use=5&amp;yk_high=114&amp;yk_low=53616&amp;nonce=dbd034d222b3837618a4c46f2726aaa2<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_DEBUG:ykval-common:YK-KSM errno/error: 0/ url=http://172.30.66.73/wsapi/2.0/sync?otp=--- MY YUBIKEY OTP ---&amp;modified=1344502479&amp;yk_publicname=--- MY YUBIKEY ---<br /><br />&amp;yk_counter=10&amp;yk_use=5&amp;yk_high=114&amp;yk_low=53616&amp;nonce=dbd034d222b3837618a4c46f2726aaa2 content_type=text/plain http_code=200 header_size=245 request_size=268 filetime=-1 ssl_verify_result=0 redirect_count=0 <br /><br />total_time=0.042231 namelookup_time=5.4E-5 connect_time=0.000512 pretransfer_time=0.000517 size_upload=0 size_download=214 speed_download=5067 speed_upload=0 download_content_length=214 upload_content_length=0 <br /><br />starttransfer_time=0.042209 redirect_time=0 certinfo=Array<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_DEBUG:ykval-verify:synclib:&#91;127.0.0.1&#93; &#91;--- MY YUBIKEY OTP ---&#93; local db contains  modified=1344502391 nonce=6e9d071896eea37f8f7516954613aa3e yk_publicname=--- MY YUBIKEY <br /><br />--- yk_counter=10 yk_use=4 yk_high=114 yk_low=52911<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_DEBUG:ykval-verify:synclib:&#91;127.0.0.1&#93; &#91;--- MY YUBIKEY OTP ---&#93; response contains  modified=1344502391 nonce=6e9d071896eea37f8f7516954613aa3e yk_publicname=--- MY YUBIKEY <br /><br />--- yk_counter=10 yk_use=4 yk_high=114 yk_low=52911<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_DEBUG:ykval-verify:synclib:&#91;127.0.0.1&#93; &#91;--- MY YUBIKEY OTP ---&#93; OTP contains  modified=1344502479 nonce=dbd034d222b3837618a4c46f2726aaa2 yk_publicname=--- MY YUBIKEY --- <br /><br />yk_counter=10 yk_use=5 yk_high=114 yk_low=53616<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_DEBUG:ykval-verify:synclib:db:&#91;127.0.0.1&#93; &#91;--- MY YUBIKEY OTP ---&#93; DB query is: UPDATE yubikeys SET  modified='1344502391', yk_counter='10', yk_use='4', yk_low='52911', <br /><br />yk_high='114', nonce='6e9d071896eea37f8f7516954613aa3e' WHERE yk_publicname = '--- MY YUBIKEY ---' and (10&gt;yk_counter or (10=yk_counter and 4&gt;yk_use))<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_INFO:ykval-verify:synclib:&#91;127.0.0.1&#93; &#91;--- MY YUBIKEY OTP ---&#93; database not updated modified=1344502391 nonce=6e9d071896eea37f8f7516954613aa3e yk_publicname=--- MY YUBIKEY <br /><br />--- yk_counter=10 yk_use=4 yk_high=114 yk_low=52911<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_INFO:ykval-verify:synclib:&#91;127.0.0.1&#93; &#91;--- MY YUBIKEY OTP ---&#93; deleting server=http://172.30.66.73/wsapi/2.0/sync modified=1344502479 <br /><br />server_nonce=8bb7650ce1a22250609b600c26ab8401<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_DEBUG:ykval-verify:synclib:db:&#91;127.0.0.1&#93; &#91;--- MY YUBIKEY OTP ---&#93; DB query is: DELETE FROM queue WHERE modified = '1344502479' and server_nonce = <br /><br />'8bb7650ce1a22250609b600c26ab8401' and server = 'http://172.30.66.73/wsapi/2.0/sync'<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_DEBUG:ykval-verify:synclib:db:&#91;127.0.0.1&#93; &#91;--- MY YUBIKEY OTP ---&#93; DB query is: UPDATE queue SET  queued=NULL WHERE server_nonce = '8bb7650ce1a22250609b600c26ab8401'<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_INFO:ykval-verify:&#91;127.0.0.1&#93; &#91;--- MY YUBIKEY OTP ---&#93; ykval-verify:notice:synclevel=60 nr servers=1 req answers=1 answers=1 valid answers=1 sl success rate=100 timeout=1<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_INFO:ykval-verify:&#91;127.0.0.1&#93; &#91;--- MY YUBIKEY OTP ---&#93; Timestamp seen=7524015 this=7524720 delta=705 secs=88.125 accessed=1344502391 (2012-08-09 10:53:11) now=1344502479 <br /><br />(2012-08-09 10:54:39) elapsed=88 deviation=0.125 secs or 0%<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_DEBUG:ykval-common:SIGN: nonce=dbd034d222b3837618a4c46f2726aaa2&amp;otp=--- MY YUBIKEY OTP ---&amp;sl=100&amp;status=OK&amp;t=2012-08-09T08:54:39Z0895 H=CcI6ldcs5iB3xKbt3mE9d9HByGo=<br />Aug  9 10:54:39 yubico01 ykval&#91;16269&#93;: LOG_INFO:ykval-common:Response: h=CcI6ldcs5iB3xKbt3mE9d9HByGo=#015#012t=2012-08-09T08:54:39Z0895#015#012otp=--- MY YUBIKEY OTP ---<br /><br />#015#012nonce=dbd034d222b3837618a4c46f2726aaa2#015#012sl=100#015#012status=OK#015#012#015#012 (at 2012-08-09T08:54:39+00:00 0.89565800 1344502479)</div></span><br /><br />Not working situation yubico02.iam.ia powered off:<br /><span style="font-size: 80%; line-height: normal"><div class="codetitle"><b>Code:</b></div><div class="codecontent">Aug  9 10:57:03 yubico01 ykval&#91;16270&#93;: LOG_INFO:ykval-verify:&#91;127.0.0.1&#93; Request: id=1&amp;nonce=68074094b8a386bfc4966dc00fb344e0&amp;otp= --- MY YUBIKEY OTP ---&amp;h=2OCW3/eEWwXF1Cd70AzNERtrU9U= (at 2012-08-09T10:57:03+02:00 0.88526200 1344502623) HTTP<br />Aug  9 10:57:03 yubico01 ykval&#91;16270&#93;: LOG_DEBUG:ykval-verify:synclib:db:&#91;127.0.0.1&#93; &#91; --- MY YUBIKEY OTP ---&#93; DB query is: SELECT id, secret FROM clients WHERE active AND id='1'<br />Aug  9 10:57:03 yubico01 ykval&#91;16270&#93;: LOG_DEBUG:ykval-verify:&#91;127.0.0.1&#93; &#91; --- MY YUBIKEY OTP ---&#93; Client data: id=1  secret=s1lgixvlvNAtrqJeYH4VPLkJxT0=<br />Aug  9 10:57:03 yubico01 ykval&#91;16270&#93;: LOG_DEBUG:ykval-common:SIGN: id=1&amp;nonce=68074094b8a386bfc4966dc00fb344e0&amp;otp= --- MY YUBIKEY OTP --- H=2OCW3/eEWwXF1Cd70AzNERtrU9U=<br />Aug  9 10:57:04 yubico01 ykval&#91;16270&#93;: LOG_DEBUG:ykval-verify:&#91;127.0.0.1&#93; &#91; --- MY YUBIKEY OTP ---&#93; Decrypted OTP: session_counter=10  low=54768  high=114  session_use=6<br />Aug  9 10:57:04 yubico01 ykval&#91;16270&#93;: LOG_INFO:ykval-verify:synclib:&#91;127.0.0.1&#93; &#91; --- MY YUBIKEY OTP ---&#93; searching for yk_publicname djcccbcccbrd in local db<br />Aug  9 10:57:04 yubico01 ykval&#91;16270&#93;: LOG_DEBUG:ykval-verify:synclib:db:&#91;127.0.0.1&#93; &#91; --- MY YUBIKEY OTP ---&#93; DB query is: SELECT * FROM yubikeys WHERE yk_publicname = 'djcccbcccbrd' LIMIT 1<br />Aug  9 10:57:04 yubico01 ykval&#91;16270&#93;: LOG_INFO:ykval-verify:synclib:&#91;127.0.0.1&#93; &#91; --- MY YUBIKEY OTP ---&#93; yubikey found in db  modified=1344502479 nonce=dbd034d222b3837618a4c46f2726aaa2 yk_publicname=djcccbcccbrd yk_counter=10 yk_use=5 yk_high=114 yk_low=53616<br />Aug  9 10:57:04 yubico01 ykval&#91;16270&#93;: LOG_DEBUG:ykval-verify:&#91;127.0.0.1&#93; &#91; --- MY YUBIKEY OTP ---&#93; Auth data: modified=1344502479  nonce=dbd034d222b3837618a4c46f2726aaa2  active=1  yk_publicname=djcccbcccbrd  yk_counter=10  yk_use=5  yk_high=114  yk_low=53616<br />Aug  9 10:57:04 yubico01 ykval&#91;16270&#93;: LOG_DEBUG:ykval-verify:synclib:db:&#91;127.0.0.1&#93; &#91; --- MY YUBIKEY OTP ---&#93; DB query is: UPDATE yubikeys SET  modified='1344502624', yk_counter='10', yk_use='6', yk_low='54768', yk_high='114', nonce='68074094b8a386bfc4966dc00fb344e0' WHERE yk_publicname = 'djcccbcccbrd' and (10&gt;yk_counter or (10=yk_counter and 6&gt;yk_use))<br />Aug  9 10:57:04 yubico01 ykval&#91;16270&#93;: LOG_INFO:ykval-verify:synclib:&#91;127.0.0.1&#93; &#91; --- MY YUBIKEY OTP ---&#93; updated database  modified=1344502624 nonce=68074094b8a386bfc4966dc00fb344e0 yk_publicname=djcccbcccbrd yk_counter=10 yk_use=6 yk_high=114 yk_low=54768<br />Aug  9 10:57:04 yubico01 ykval&#91;16270&#93;: LOG_DEBUG:ykval-verify:synclib:db:&#91;127.0.0.1&#93; &#91; --- MY YUBIKEY OTP ---&#93; DB query is: INSERT INTO queue (queued,modified,otp,server,server_nonce,info) VALUES ('1344502624','1344502624',' --- MY YUBIKEY OTP ---','http://172.30.66.73/wsapi/2.0/sync','fb3ce2b60e28af2cf4d2f2032e2d89da','yk_publicname=djcccbcccbrd&amp;yk_counter=10&amp;yk_use=6&amp;yk_high=114&amp;yk_low=54768&amp;nonce=68074094b8a386bfc4966dc00fb344e0,local_counter=10&amp;local_use=5')<br />Aug  9 10:57:04 yubico01 ykval&#91;16270&#93;: LOG_DEBUG:ykval-verify:synclib:db:&#91;127.0.0.1&#93; &#91; --- MY YUBIKEY OTP ---&#93; DB query is: SELECT * FROM queue WHERE modified = '1344502624' and server_nonce = 'fb3ce2b60e28af2cf4d2f2032e2d89da'<br />Aug  9 10:57:04 yubico01 ykval&#91;16270&#93;: LOG_DEBUG:ykval-verify:synclib:&#91;127.0.0.1&#93; &#91; --- MY YUBIKEY OTP ---&#93; url in retrieveURLasync is http://172.30.66.73/wsapi/2.0/sync?otp= --- MY YUBIKEY OTP ---&amp;modified=1344502624&amp;yk_publicname=djcccbcccbrd&amp;yk_counter=10&amp;yk_use=6&amp;yk_high=114&amp;yk_low=54768&amp;nonce=68074094b8a386bfc4966dc00fb344e0<br />Aug  9 10:57:06 yubico01 ykval&#91;16270&#93;: LOG_WARNING:ykval-verify:synclib:&#91;127.0.0.1&#93; &#91; --- MY YUBIKEY OTP ---&#93; No responses from validation server pool<br />Aug  9 10:57:06 yubico01 ykval&#91;16270&#93;: LOG_DEBUG:ykval-verify:synclib:db:&#91;127.0.0.1&#93; &#91; --- MY YUBIKEY OTP ---&#93; DB query is: UPDATE queue SET  queued=NULL WHERE server_nonce = 'fb3ce2b60e28af2cf4d2f2032e2d89da'<br />Aug  9 10:57:06 yubico01 ykval&#91;16270&#93;: LOG_INFO:ykval-verify:&#91;127.0.0.1&#93; &#91; --- MY YUBIKEY OTP ---&#93; ykval-verify:notice:synclevel=60 nr servers=1 req answers=1 answers=0 valid answers=0 sl success rate=0 timeout=1<br />Aug  9 10:57:06 yubico01 ykval&#91;16270&#93;: LOG_WARNING:ykval-verify:&#91;127.0.0.1&#93; &#91; --- MY YUBIKEY OTP ---&#93; ykval-verify:notice:Sync failed<br />Aug  9 10:57:06 yubico01 ykval&#91;16270&#93;: LOG_DEBUG:ykval-common:SIGN: nonce=68074094b8a386bfc4966dc00fb344e0&amp;otp= --- MY YUBIKEY OTP ---&amp;sl=0&amp;status=NOT_ENOUGH_ANSWERS&amp;t=2012-08-09T08:57:06Z0037 H=1gEpAlbSfF3zcnKohnk4lkN4Dr0=<br />Aug  9 10:57:06 yubico01 ykval&#91;16270&#93;: LOG_INFO:ykval-common:Response: h=1gEpAlbSfF3zcnKohnk4lkN4Dr0=#015#012t=2012-08-09T08:57:06Z0037#015#012otp= --- MY YUBIKEY OTP ---#015#012nonce=68074094b8a386bfc4966dc00fb344e0#015#012sl=0#015#012status=NOT_ENOUGH_ANSWERS#015#012#015#012 (at 2012-08-09T08:57:06+00:00 0.03761800 1344502626)<br />Aug  9 10:57:07 yubico01 ykval&#91;2241&#93;: LOG_INFO:ykval-queue:synclib:server=http://172.30.66.73/wsapi/2.0/sync , info=yk_publicname=djcccbcccbrd&amp;yk_counter=10&amp;yk_use=6&amp;yk_high=114&amp;yk_low=54768&amp;nonce=68074094b8a386bfc4966dc00fb344e0,local_counter=10&amp;local_use=5<br />Aug  9 10:57:07 yubico01 ykval&#91;2241&#93;: LOG_DEBUG:ykval-queue:synclib:url is http://172.30.66.73/wsapi/2.0/sync?otp= --- MY YUBIKEY OTP ---&amp;modified=1344502624&amp;yk_publicname=djcccbcccbrd&amp;yk_counter=10&amp;yk_use=6&amp;yk_high=114&amp;yk_low=54768&amp;nonce=68074094b8a386bfc4966dc00fb344e0<br />&#91;b&#93;Aug  9 10:57:29 yubico01 ykval&#91;2241&#93;: LOG_INFO:ykval-queue:synclib:server=http://172.30.66.73/wsapi/2.0/sync ,&#91;/b&#93; info=yk_publicname=djcccbcccbrd&amp;yk_counter=10&amp;yk_use=6&amp;yk_high=114&amp;yk_low=54768&amp;nonce=68074094b8a386bfc4966dc00fb344e0,local_counter=10&amp;local_use=5<br />Aug  9 10:57:29 yubico01 ykval&#91;2241&#93;: LOG_DEBUG:ykval-queue:synclib:url is http://172.30.66.73/wsapi/2.0/sync?otp= --- MY YUBIKEY OTP ---&amp;modified=1344502624&amp;yk_publicname=djcccbcccbrd&amp;yk_counter=10&amp;yk_use=6&amp;yk_high=114&amp;yk_low=54768&amp;nonce=68074094b8a386bfc4966dc00fb344e0</div></span><br /><br />As you see above when i try to authenticate on yubico01.iam.ia, yubico01 tries to make an connection with yubico02.iam.ia 172.30.66.73.<br /><br />I hope someone can help me, with this stange problem. We need to go live with our yubiradius servers.<br /><br />Kind regards,<br />Remco Bierings<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2106">remcobierings</a> — Thu Aug 09, 2012 1:56 pm</p><hr />
]]></content>
</entry>
</feed>