<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=4&amp;t=550" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2010-07-22T12:00:34+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=4&amp;t=550</id>
<entry>
<author><name><![CDATA[samir]]></name></author>
<updated>2010-07-22T12:00:34+01:00</updated>
<published>2010-07-22T12:00:34+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=550&amp;p=2284#p2284</id>
<link href="https://forum.yubico.com/viewtopic.php?t=550&amp;p=2284#p2284"/>
<title type="html"><![CDATA[Re: Lost/damaged key replacement questions]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=550&amp;p=2284#p2284"><![CDATA[
Regarding the static password (Backup Key):<br />Two or more than two YubiKeys can be configured to emit a same static password by programming them using the same programming parameters like same AES Key, same Public ID and same Private ID. For more information please visit the following post:<br /><a href="http://forum.yubico.com/viewtopic.php?f=6&amp;t=513" class="postlink">http://forum.yubico.com/viewtopic.php?f=6&amp;t=513</a><br /><br />For login to online services, Yubico provides the OTP validation service, the Web Service API and corresponding clients in various programming languages that can be easily integrated by application developers.<br /><br />Regarding replacing the lost OTP, it really depends on the application if it provides the administrators to reassign a new key to the user. However, to avoid unauthorized use of the lost YubiKeys (OTP validation), Users/Client administrators can enroll their YubiKeys with the YubiRevoke Service (<!-- m --><a class="postlink" href="https://admin.yubico.com/yubirevoke/login.php">https://admin.yubico.com/yubirevoke/login.php</a><!-- m --> ). YubiRevoke service allows to disable (or re-enable) specific YubiKeys on the Yubico Validation Service in case they are lost. This is very effective in preventing any potential misuse of YubiKeys if they fall in the wrong hands.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1076">samir</a> — Thu Jul 22, 2010 12:00 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[eduqate]]></name></author>
<updated>2010-07-12T12:24:38+01:00</updated>
<published>2010-07-12T12:24:38+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=550&amp;p=2272#p2272</id>
<link href="https://forum.yubico.com/viewtopic.php?t=550&amp;p=2272#p2272"/>
<title type="html"><![CDATA[Lost/damaged key replacement questions]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=550&amp;p=2272#p2272"><![CDATA[
Sorry if some of these questions seem naive, I have tried RTFMing and couldn't find the answers, pointers would be appreciated.<br /><br />I am thinking of deploying the Yubikey in a number of scenarios such as accessing encrypted volumes or login to local or web services.<br /><br />Am I correct in believing that for accessing encrypted volumes I must use a static password? If the yubikey is lost or damaged is it sufficient to program another yubikey with the same password or do I need to somehow clone the old yubikey?<br /><br />For login to online services it would be nice to consider a one time password usage however this will require extra processing at the server to validate the passwords, correct?. <br /><br />Is replacing lost OTP yubikeys feasible or is it only realistic to issue a new yubikey to that user and revoke the old one. If this is the case then do all yubikey installations ultimately hinge on a static password as OTP devices are vulnerable to loss or damage and are thus not reliable for master key usage?<br /><br />In brief, what is best practice for replacing lost or damaged yubikeys either static or OTP?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=480">eduqate</a> — Mon Jul 12, 2010 12:24 pm</p><hr />
]]></content>
</entry>
</feed>