<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=22&amp;t=1955" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2015-07-14T17:58:19+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=22&amp;t=1955</id>
<entry>
<author><name><![CDATA[bmwt]]></name></author>
<updated>2015-07-14T17:58:19+01:00</updated>
<published>2015-07-14T17:58:19+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1955&amp;p=7574#p7574</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1955&amp;p=7574#p7574"/>
<title type="html"><![CDATA[Re: hsm internal database, otp counters]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1955&amp;p=7574#p7574"><![CDATA[
<div class="quotetitle">bmwt wrote:</div><div class="quotecontent"><br />Howdy folks,<br /><br />I'm assuming my other (only?) option is to run my own validation service on each node, continue to sync the yubi_val's postgress tables out of band, and store the keys as AEAD blobs (generated on the controlling workstation) on the validators' filesystems, and sync those using normal unix methods?<br /></div><br /><br />I've been going down this route.  I've initialized an HSM, and set an AEAD AES key.  I've used yhsm-generate-keys to create a key.  I can get the secret out with yhsm-decrypt-aead, *using the aes key on the command line.*  Do i really need to store that AES key in the clear somewhere to decrypt the blobs to provision yubikeys?  Is there a flag im missing to have the HSM use the internal copy of the key?<br /><br />thanks,<br /><br />-bmwt<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3805">bmwt</a> — Tue Jul 14, 2015 5:58 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[bmwt]]></name></author>
<updated>2015-07-07T23:17:51+01:00</updated>
<published>2015-07-07T23:17:51+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1955&amp;p=7534#p7534</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1955&amp;p=7534#p7534"/>
<title type="html"><![CDATA[hsm internal database, otp counters]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1955&amp;p=7534#p7534"><![CDATA[
Howdy folks,<br /><br />I'm wrapping my mind around how best to utilize the yubihsm in my environment. We're implementing two servers (east coast, west coast) for use as two factor radius appliances:<br /><br />Freeradius -&gt; pam -&gt; pam_yubi -&gt; localhost validation server -&gt; localhost ksm<br />(there's also a pam_ldap and a local ldap replica, to provide a second factor)<br /><br />In order to prevent a chicken/egg problem during disasters, we're doing everything possible to stack all these services on a single host, which is then replicated for geographic redundancy.<br /><br />  Without the HSM, we need to manually load keys into each node's database (postgres), separately sync the validator's database to keep OTP counters accurate on both systems.  As i understand it, the HSM module offers the possibility to use the device's internal database to store.  Am I correct in assuming i can *not* use that internal database unless i want to restrict to the one unit?  Is there a way to sync the internal counters of the database?<br /><br />I'm assuming my other (only?) option is to run my own validation service on each node, continue to sync the yubi_val's postgress tables out of band, and store the keys as AEAD blobs (generated on the controlling workstation) on the validators' filesystems, and sync those using normal unix methods?<br /><br />(forgive me if I'm missing something obvious, still trying to wrap my head around the documentation)<br /><br />thanks!<br /><br />-bmwt<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3805">bmwt</a> — Tue Jul 07, 2015 11:17 pm</p><hr />
]]></content>
</entry>
</feed>