<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=4&amp;t=445" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2009-12-07T23:44:32+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=4&amp;t=445</id>
<entry>
<author><name><![CDATA[Jakob]]></name></author>
<updated>2009-12-07T23:44:32+01:00</updated>
<published>2009-12-07T23:44:32+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=445&amp;p=1920#p1920</id>
<link href="https://forum.yubico.com/viewtopic.php?t=445&amp;p=1920#p1920"/>
<title type="html"><![CDATA[Retrieving AES keys and serialization of Yubikeys]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=445&amp;p=1920#p1920"><![CDATA[
We often get the question regarding retrieval of AES keys where customers who have bought Yubikeys later ask for their AES key. As a part of a general security review, we changed the server setup in March 2009 and moved the key storage to a separate machine. The new setup does not allow for keys to be extracted.<br /><br />Customers who have purchased a few keys and want to use them with our validation service therefore have to re-configure their keys and use our AES upload feature. <br /><br />Customers with larger deployments who want their secrets <span style="text-decoration: underline">MUST</span> request the secrets <span style="text-decoration: underline">AT THE TIME OF PURCHASE</span> and further tell if the keys are to be used in a private context or with the Yubico validation server. <br /><br />We can then provide the key secrets on CD together with the order or sent by e-mail, encrypted with a customer supplied GPG key. CD deliveries can be plain text, GPG symmetrically encrypted with passphrase in e-mail or GPG encrypted with customer's public key. Due to the administrative overhead, we have a minimum order quantity of 100 Yubikeys in a single order for this option. And just to have it said again - we need to know the provisioning options at the time of ordering. <br /><br />The default key provisioning format is a semicolon-separated Ascii file<br /><br /><strong>barcode-id ; public-id-modhex ; public-id-hex ; private-id-hex ; aes-key-hex</strong><br /><br />A Sample file looks like:<br /><br />00077404;cccccccbdugr;000000012e5c;9f441fa05922;69fc80be0e757941013c35b70b517d8d <br />00077405;cccccccbdugt;000000012e5d;e0e21cfd110b;36448e5e4501492b031fe85704d933a1<br />00077406;cccccccbdugu;000000012e5e;9b90c435482e;65b43e02586ede3bb361b71dcb8889b4<br />00077407;cccccccbdugv;000000012e5f;3bb64901c5c8;1dcd9f5c9bc57570405db657b28d4f03<br />00077408;cccccccbduhc;000000012e60;3107b6c27658;280d735e327384708190d5216861f289<br />00077409;cccccccbduhb;000000012e61;94fe38ba9b16;aac0525ed2682be2c5376cba70e39f32<br /><br /><br />We have a discounted end-of-the-year special available on the web-store for 100 and 500 units. Take the opportunity to order Yubikeys with secrets delivered in the format of choice. <br /><br />With the best regards,<br /><br />JakobE<br />Hardware- and firmware guy @ Yubico<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=83">Jakob</a> — Mon Dec 07, 2009 11:44 pm</p><hr />
]]></content>
</entry>
</feed>