<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=5&amp;t=851" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2012-10-19T01:41:27+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=5&amp;t=851</id>
<entry>
<author><name><![CDATA[11010490]]></name></author>
<updated>2012-10-19T01:41:27+01:00</updated>
<published>2012-10-19T01:41:27+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=851&amp;p=3323#p3323</id>
<link href="https://forum.yubico.com/viewtopic.php?t=851&amp;p=3323#p3323"/>
<title type="html"><![CDATA[Re: Is there a solution out there that can protect my webmai]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=851&amp;p=3323#p3323"><![CDATA[
Use TMG 2010. You won't have access to ActiveSync unless you have two external IPs for two different listeners tho.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2181">11010490</a> — Fri Oct 19, 2012 1:41 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[jakobjs]]></name></author>
<updated>2012-08-21T13:03:31+01:00</updated>
<published>2012-08-21T13:03:31+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=851&amp;p=3254#p3254</id>
<link href="https://forum.yubico.com/viewtopic.php?t=851&amp;p=3254#p3254"/>
<title type="html"><![CDATA[Re: Is there a solution out there that can protect my webmai]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=851&amp;p=3254#p3254"><![CDATA[
Would it be possible to set up a PHP app that would authenticate the keys and then forward requests to OWA?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2128">jakobjs</a> — Tue Aug 21, 2012 1:03 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[jakobjs]]></name></author>
<updated>2012-08-21T12:02:03+01:00</updated>
<published>2012-08-21T12:02:03+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=851&amp;p=3253#p3253</id>
<link href="https://forum.yubico.com/viewtopic.php?t=851&amp;p=3253#p3253"/>
<title type="html"><![CDATA[Re: Is there a solution out there that can protect my webmai]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=851&amp;p=3253#p3253"><![CDATA[
Its OWA on Exchange 2010.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2128">jakobjs</a> — Tue Aug 21, 2012 12:02 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[David]]></name></author>
<updated>2012-08-20T17:38:23+01:00</updated>
<published>2012-08-20T17:38:23+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=851&amp;p=3252#p3252</id>
<link href="https://forum.yubico.com/viewtopic.php?t=851&amp;p=3252#p3252"/>
<title type="html"><![CDATA[Re: Is there a solution out there that can protect my webmai]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=851&amp;p=3252#p3252"><![CDATA[
<div class="quotetitle">jakobjs wrote:</div><div class="quotecontent"><br />Hi all.<br /><br />Just got my first YubiKey and plan to use them along with YubiRADIUS and Cisco ASA.<br /><br />Is there some way to protect my exposed webmail application from the Internet with YubiKey's OTP? I mean, is it possible to set up some kind of a front-end to it, that only allows valid YubiKey users through to the login window?<br /></div><br /><br /><br />Hello Sir,<br /><br />Can you provide us with some more information about your webmail application?<br /><br />Are you using OWA, Gmail or another application. Due to the different methods used by various webmail apps to connect to the web, you will need to approach this solution differently. Any additional information you may provide will help!<br /><br />Thanks!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2104">David</a> — Mon Aug 20, 2012 5:38 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[samir]]></name></author>
<updated>2012-08-20T16:48:17+01:00</updated>
<published>2012-08-20T16:48:17+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=851&amp;p=3251#p3251</id>
<link href="https://forum.yubico.com/viewtopic.php?t=851&amp;p=3251#p3251"/>
<title type="html"><![CDATA[Re: Is there a solution out there that can protect my webmai]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=851&amp;p=3251#p3251"><![CDATA[
Hello,<br /><br />At a high-level the Yubico technology and ecosystem comprises of following main parts:<br /><br />a. YubiKey hardware token that generates one time passwords (OTPs)<br />b. Yubico Validation server that validates the OTPs generated by YubiKeys and<br />c. Validation Protocol that defines the client-server communication protocol between the clients and Yubico Validation server<br /><br />The link <!-- m --><a class="postlink" href="http://www.yubico.com/technical-description">http://www.yubico.com/technical-description</a><!-- m --> gives an overview and details of various components mentioned above. This page has several links on the left side for further reading on each component.<br /><br />We further recommend the following links:<br /><br />1. For more information on Yubico Validation Server please visit <!-- m --><a class="postlink" href="http://www.yubico.com/validation-server">http://www.yubico.com/validation-server</a><!-- m --> and look for Yubico PHP server which is free open-source project you can download and deploy in your environment to meet your requirements. The Validation server has a dependency on key storage module for secure storage of Secret AES keys. Yubico YK-KSM is an open-source implementation of secure key storage module and YubiHSM is hardware based solution that offers much stronger security of the key storage module. Please visit <!-- m --><a class="postlink" href="http://www.yubico.com/yubihsm">http://www.yubico.com/yubihsm</a><!-- m --> for more information on YubiHSM.<br /><br />2. Yubico also offers open-source client implementation in a number of programming languages (including for .NET) to make it easy for customers to implement YubiKey based strong 2 factor authentication. Please visit <!-- m --><a class="postlink" href="http://www.yubico.com/web-api-clients">http://www.yubico.com/web-api-clients</a><!-- m --> for more details on the validation clients and links to Validation Protocol.<br /><br />3. Most relevant to your needs could be YubiRADIUS solution from Yubico which is enterprise class software for secure remote access with YubiKey two-factor authentication. It provides 3 potential ways of integrating YubiKey based authentication into your environments:<br />    a) RADIUS<br />    b) Web API for YubiKey based two-factor authentication. (In both a) and b) one of the factors for authentication is standard username + password based on AD binding and the second factor is YubiKey OTP)<br />    c) Web API for validating the YubiKey OTPs<br /><br />The solution is based on FreeRADIUS and open source components and is offered as a free virtual appliance for easy download and quick installation. YubiRADIUS virtual appliance has a pre-configured instance of the Yubico PHP validation server that can be used for OTP validation and an option to use YK-KSM and YubiHSM for secure key storage.<br /><br />4. Finally, Yubico offers guidelines and best practices on how YubiKey based two-factor authentication can be implemented. Please visit <!-- m --><a class="postlink" href="http://www.yubico.com/development-guidelines">http://www.yubico.com/development-guidelines</a><!-- m --> for more details.<br /><br />Hope this helps.<br /><br />Thanks and best regards,<br />Samir.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1076">samir</a> — Mon Aug 20, 2012 4:48 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[jakobjs]]></name></author>
<updated>2012-08-17T14:27:31+01:00</updated>
<published>2012-08-17T14:27:31+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=851&amp;p=3245#p3245</id>
<link href="https://forum.yubico.com/viewtopic.php?t=851&amp;p=3245#p3245"/>
<title type="html"><![CDATA[Is there a solution out there that can protect my webmail?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=851&amp;p=3245#p3245"><![CDATA[
Hi all.<br /><br />Just got my first YubiKey and plan to use them along with YubiRADIUS and Cisco ASA.<br /><br />Is there some way to protect my exposed webmail application from the Internet with YubiKey's OTP? I mean, is it possible to set up some kind of a front-end to it, that only allows valid YubiKey users through to the login window?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2128">jakobjs</a> — Fri Aug 17, 2012 2:27 pm</p><hr />
]]></content>
</entry>
</feed>