<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=16&amp;t=1847" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2015-04-23T09:18:35+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=16&amp;t=1847</id>
<entry>
<author><name><![CDATA[Tom2]]></name></author>
<updated>2015-04-23T09:18:35+01:00</updated>
<published>2015-04-23T09:18:35+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1847&amp;p=7231#p7231</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1847&amp;p=7231#p7231"/>
<title type="html"><![CDATA[Re: Issue with OTP second slot on limited edition yubikeys]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1847&amp;p=7231#p7231"><![CDATA[
please contact yubi.co/support<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3364">Tom2</a> — Thu Apr 23, 2015 9:18 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[frog]]></name></author>
<updated>2015-04-22T12:09:10+01:00</updated>
<published>2015-04-22T12:09:10+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1847&amp;p=7223#p7223</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1847&amp;p=7223#p7223"/>
<title type="html"><![CDATA[Issue with OTP second slot on limited edition yubikeys]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1847&amp;p=7223#p7223"><![CDATA[
Hi,<br /><br />We ordered a batch of limited edition 3-colour yubikeys (red/white/green) and the first short-press slot is working fine in OTP mode, but we're having trouble with the long-press second slot.  Are there some limitations on these yubikeys that would prevent us from using the second slot in otp mode?  <br /><br />We're programming both slots into otp mode using the personalization tool on windows, closing the tool and then adding a keypress and aes code into the local yubipam user helper.  The first slot will authenticate fine and returns codes yubipam accepts, yubipam rejects all logins from the second slot.<br /><br />This was tested by reinitialising both slots on the yubikey, registering each slot against a new user and then only the user mapped to the first slot works, the user mapped to the second slot cannot authenticate at all.<br /><br /><br />We have tested some upgrades and alternative versions of yubipam, but it only appears to be these new yubikeys and the second slot it has issue with.  An older yubikey running firmware 2.2.3 works fine, the new ones just dont seem to be happy with that second slot.<br /><br />Any ideas?  I've included some data below that may be useful but some help would be much appreciated!<br /><br />Cheers,<br /><br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">&#91;11:32 root:~&#93;# ykpasswd -a -u test1 -o vvibuirgjcelegnvclekiltljngchvfnifvlnfnnvtgh<br />Adding Yubikey entry for test1<br />AES key &#91;exactly 32 hex chars&#93;: 3bcfef7da404e7f700719af19d6106b7<br />Using public UID: ff 71 e7 c5 80 3a <br />Using private UID: 22 ff f8 14 3a 05 <br />Completed successfully.<br />&#91;11:34 root:~&#93;# ykpasswd  -a -u test2 -o vvntfltfgncgurnuegciulbfrejntnlclnuledudhbrc<br />Adding Yubikey entry for test2<br />AES key &#91;exactly 32 hex chars&#93;: 1031577e37f3709f8b3e1c9ef0b906d1<br />Using public UID: ff bd 4a d4 5b 05 <br />Using private UID: 98 a8 76 3a 8d 8b <br /># first press of slot 1<br />&#91;11:34 root:~&#93;# ykvalidate -u test1 vvibuirgjceluvbklnienvbvvlllrjrrcvrhkgviriev<br />test1: OTP is VALID.<br /># first press of slot 2<br />&#91;11:34 root:~&#93;# ykvalidate -u test2 vvntfltfgncgcgjtinntuitctlgthrbedcnfdbbgdrnv<br />test2: OTP is INVALID!<br /><br />We then reran it with an older yubikey:<br /><br />&#91;12:07 root:~&#93;# ykpasswd -a -u test1 -o vvedjfgfrtdfkfhikugekeckgdbhvlukvdgddhevvbcu <br />Adding Yubikey entry for test1<br />AES key &#91;exactly 32 hex chars&#93;: 73a6ad28ea768aabe735d66000bc594d<br />Using public UID: ff 32 84 54 cd 24 <br />Using private UID: be 62 3c 0b 7a df <br />Completed successfully.<br />&#91;12:07 root:~&#93;# ykpasswd -a -u test2 -o vvbueitifvlecnvtnhffieiuurcubgfencejrcnkuhii<br />Adding Yubikey entry for test2<br />AES key &#91;exactly 32 hex chars&#93;: 06a6bbd78aecdf22926bbd55228023e2<br />Using public UID: ff 1e 37 d7 4f a3 <br />Using private UID: 91 ce 05 ef 55 7a <br />Completed successfully.<br />&#91;12:07 root:~&#93;# ykvalidate -u test1 vvedjfgfrtdfknukvigjnrnnjtdrnjnhrnrjbcchubcv<br />test1: OTP is VALID.<br />&#91;12:07 root:~&#93;# ykvalidate -u test2 vvbueitifvlegvnvhcfibivcnubviijcrhcnjhgltjkh<br />test2: OTP is VALID.<br /><br /><br /><br /></div><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3667">frog</a> — Wed Apr 22, 2015 12:09 pm</p><hr />
]]></content>
</entry>
</feed>