<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=5&amp;t=781" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2012-04-11T11:06:42+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=5&amp;t=781</id>
<entry>
<author><name><![CDATA[samir]]></name></author>
<updated>2012-04-11T11:06:42+01:00</updated>
<published>2012-04-11T11:06:42+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=781&amp;p=2999#p2999</id>
<link href="https://forum.yubico.com/viewtopic.php?t=781&amp;p=2999#p2999"/>
<title type="html"><![CDATA[Re: YubiRADIUS with Forefront TMG]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=781&amp;p=2999#p2999"><![CDATA[
Hi,<br /><br />We believe it is possible to configurable the MS FUAG to not require double authentications but we would encourage you to contact Yubico at <!-- e --><a href="mailto:support@yubico.com">support@yubico.com</a><!-- e --> so that we together can test out any options and once we have a working configuration we can post the result back to the forum.<br /><br />Thanks!<br />Samir.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1076">samir</a> — Wed Apr 11, 2012 11:06 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[chris5287]]></name></author>
<updated>2012-04-06T11:53:46+01:00</updated>
<published>2012-04-06T11:53:46+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=781&amp;p=2990#p2990</id>
<link href="https://forum.yubico.com/viewtopic.php?t=781&amp;p=2990#p2990"/>
<title type="html"><![CDATA[YubiRADIUS with Forefront TMG]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=781&amp;p=2990#p2990"><![CDATA[
Hi, does anyone have any experience setting up Forefront TMG to use YubiRADIUS. (I have YubiRADIUS setup as an Active Directory client)<br /><br />I can setup TMG to use 'Radius OTP' on it's listener, so the form page appears asking for username, passcode (ie: Password+OTP) and internal password, however this requires the user to enter their password twice (Once so that the YubiRADIUS can perform the 2FA, and then again so the internal service can be delegated the credentials required). <br /><br />From my reading on the internet, it appears I need to get the YubiRADIUS to send 'access-challenge' to TMG to get it so that the user can first enter their normal username/password and then when it received 'access-challenge', TMG asks the user for their OTP, keeping their password and otp separate and therefore allowing delegation to occurr after TMG has completed the 2FA with YubiRADIUS.<br /><br />I hope this makes sense! If not please correct me as this is all a bit new to me and i'm keen to learn.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2009">chris5287</a> — Fri Apr 06, 2012 11:53 am</p><hr />
]]></content>
</entry>
</feed>