<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=23&amp;t=810" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2012-10-29T19:48:00+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=23&amp;t=810</id>
<entry>
<author><name><![CDATA[ferrix]]></name></author>
<updated>2012-10-29T19:48:00+01:00</updated>
<published>2012-10-29T19:48:00+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=810&amp;p=3326#p3326</id>
<link href="https://forum.yubico.com/viewtopic.php?t=810&amp;p=3326#p3326"/>
<title type="html"><![CDATA[Re: Feature Request: Remote Yubikey Recognition]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=810&amp;p=3326#p3326"><![CDATA[
Challenge-response mode over RDP can never work, at least not without very major changes to yubikey or by using different client-side RDP software.  Smart cards work extremely differently than yubikey OTP or C/R mode, in terms of cryptography and also interface.  There's no way to make a yubikey &quot;look like&quot; a smart card.<br /><br />Even if one day some yubico product might support public key crypto, it would essentially have to *be* a smart card, in every true sense, in order to authenticate this way using default RDP software.<br /><br />The alternative if you need remote logon working is simply to use OTP mode instead of C/R mode.  All the other logon solutions for yubikey support this mode.  Yubico's stance (correct) is that this leads to less endpoint security since the shared secret must be stored on the workstation.  But if you encrypt your drive this is somewhat mitigated.<br /><br />Also in terms of security, the yubico windows logon software has a very long way to go in terms of security best practices.  Right now the software is making a lot of rookie security mistakes.  But I'm sure over time it will improve, as free solutions do, slowly.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=162">ferrix</a> — Mon Oct 29, 2012 7:48 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Onedutch]]></name></author>
<updated>2012-06-22T09:22:51+01:00</updated>
<published>2012-06-22T09:22:51+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=810&amp;p=3142#p3142</id>
<link href="https://forum.yubico.com/viewtopic.php?t=810&amp;p=3142#p3142"/>
<title type="html"><![CDATA[Re: Feature Request: Remote Yubikey Recognition]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=810&amp;p=3142#p3142"><![CDATA[
<img src="https://forum.yubico.com/images/smilies/icon_cry.gif" alt=":cry:" title="Crying or Very Sad" /> I was just making my way to use th Yubico way of logging into a workstation. We use RDP (MSTSC) alot for remote work. So the Yubikey isn't used with the USB Keyboard device way. <br /><br />Currently we use <a href="http://www.rohos.com/support/knowledge-base/windows-logon-with-yubikey/" class="postlink">http://www.rohos.com/support/knowledge-base/windows-logon-with-yubikey/</a> which does work with Yubikey. It's paid software <img src="https://forum.yubico.com/images/smilies/icon_e_sad.gif" alt=":(" title="Sad" /> <br /><br />Should it be able to use Yubikey with challenge response in the future ? When starting RDP you the 'default' for smartcards is allway's enabled? Perhaps the Yubikey should present itself as a USB SmartCard, so the RDP client can pass trough the Challenge Response over this SmartCard way of doing things.<br /><br /><img src="http://img515.imageshack.us/img515/8400/smartcard.jpg" alt="Image" /><br />Regards Onedutch<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2076">Onedutch</a> — Fri Jun 22, 2012 9:22 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[davbran]]></name></author>
<updated>2012-05-15T12:20:16+01:00</updated>
<published>2012-05-15T12:20:16+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=810&amp;p=3094#p3094</id>
<link href="https://forum.yubico.com/viewtopic.php?t=810&amp;p=3094#p3094"/>
<title type="html"><![CDATA[Feature Request: Remote Yubikey Recognition]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=810&amp;p=3094#p3094"><![CDATA[
I live and breath by my Yubikey, and now I can add the same level of security to my desktop as I do with my Lastpass.<br /><br />There is a slight hiccough though, with the state of the Yubikey Windows Login Administration, there is no remote support from the remote PC.<br /><br />I would like to use RDP to connect to my remote computer, but my remote computer doesn't recognize the local yubikey.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2060">davbran</a> — Tue May 15, 2012 12:20 pm</p><hr />
]]></content>
</entry>
</feed>