<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=35&amp;t=2722" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2017-10-20T14:40:50+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=35&amp;t=2722</id>
<entry>
<author><name><![CDATA[Morthawt]]></name></author>
<updated>2017-10-20T14:40:50+01:00</updated>
<published>2017-10-20T14:40:50+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2722&amp;p=9907#p9907</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2722&amp;p=9907#p9907"/>
<title type="html"><![CDATA[Re: I set a config protection on slot 2, still overwrites]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2722&amp;p=9907#p9907"><![CDATA[
<div class="quotetitle">ChrisHalos wrote:</div><div class="quotecontent"><br />If you're adding an access code without writing a new credential, you MUST click &quot;Update Settings...&quot;, select the configuration slot you want to protect, and then click &quot;Update&quot;. You'll receive a notification that the update was performed. This functionality has been the same for many years without issue.<br /><br />Again, this is a community forum, not an &quot;ask Yubico and get an answer&quot; forum. If you need help from support, create a support ticket at yubi.co/support. We respond quite quickly during business hours.<br /></div><br /><br />Someone from Yubico told me in a ticket that this is not possible, the other day:<br /><br />&quot;This is the expected behavior. The access code is only written to the YubiKey at the time of configuration programming.&quot; I was specifically documenting how I used the update settings feature and the protection was not activated and I could overwrite my slots. That was their response.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1739">Morthawt</a> — Fri Oct 20, 2017 2:40 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[LD2gIlShWrA2J9qFcwS5]]></name></author>
<updated>2017-10-20T11:17:54+01:00</updated>
<published>2017-10-20T11:17:54+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2722&amp;p=9904#p9904</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2722&amp;p=9904#p9904"/>
<title type="html"><![CDATA[Re: I set a config protection on slot 2, still overwrites]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2722&amp;p=9904#p9904"><![CDATA[
<div class="quotetitle">ChrisHalos wrote:</div><div class="quotecontent"><br />If you're adding an access code without writing a new credential, you MUST click &quot;Update Settings...&quot;, select the configuration slot you want to protect, and then click &quot;Update&quot;. You'll receive a notification that the update was performed.<br /></div><br /><br />Thanks for this.<br /><br />This <em>almost </em>answers the very same question have; specifically how to simply &quot;protect config&quot; WITHOUT writing-to (i.e. altering) either Slot1 or Slot2 credentials.<br /><br />However, this follow-on question deals w/ the &quot;mechanics&quot; of actually performing this task this using the <em><strong>Yubikey Personalization Tool</strong> </em>(YPT) screen(s). <br /><br />It would appear that this task should be performed from either the <em><strong>&quot;Yubico OTP&quot;</strong></em> or <em><strong>&quot;OATH-HOTP&quot; </strong></em>screens by <span style="text-decoration: underline">UN-CHECKING</span> the boxes associated w/ those particular parameters <strong><span style="text-decoration: underline">BEFORE </span></strong>executing <em>&quot;Write Configuration&quot;<br /></em><br />Conversely, it appears that this ability would NOT work from either the <strong><em>&quot;Static Password&quot;</em></strong> or <em><strong>&quot;Challenge-Response&quot;</strong></em> screens simply because those screens do NOT provide a way to &quot;Uncheck&quot; alteration of the <em>&quot;credential&quot;</em> parameters.<br /><br /><strong>Am I understanding it correctly ?</strong><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3583">LD2gIlShWrA2J9qFcwS5</a> — Fri Oct 20, 2017 11:17 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[ChrisHalos]]></name></author>
<updated>2017-10-10T15:59:38+01:00</updated>
<published>2017-10-10T15:59:38+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2722&amp;p=9846#p9846</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2722&amp;p=9846#p9846"/>
<title type="html"><![CDATA[Re: I set a config protection on slot 2, still overwrites]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2722&amp;p=9846#p9846"><![CDATA[
If you're adding an access code without writing a new credential, you MUST click &quot;Update Settings...&quot;, select the configuration slot you want to protect, and then click &quot;Update&quot;. You'll receive a notification that the update was performed. This functionality has been the same for many years without issue.<br /><br />Again, this is a community forum, not an &quot;ask Yubico and get an answer&quot; forum. If you need help from support, create a support ticket at yubi.co/support. We respond quite quickly during business hours.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3140">ChrisHalos</a> — Tue Oct 10, 2017 3:59 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Morthawt]]></name></author>
<updated>2017-10-08T15:10:40+01:00</updated>
<published>2017-10-08T15:10:40+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2722&amp;p=9830#p9830</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2722&amp;p=9830#p9830"/>
<title type="html"><![CDATA[Re: I set a config protection on slot 2, still overwrites]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2722&amp;p=9830#p9830"><![CDATA[
I find the lack of official responses, answering people's questions and making things clear etc, very disturbing. I love Yubikeys but my experience from Yubico on your official forum is tainting how I feel about Yubico.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1739">Morthawt</a> — Sun Oct 08, 2017 3:10 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[techwg]]></name></author>
<updated>2017-09-26T13:21:28+01:00</updated>
<published>2017-09-26T13:21:28+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2722&amp;p=9776#p9776</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2722&amp;p=9776#p9776"/>
<title type="html"><![CDATA[I set a config protection on slot 2, still overwrites]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2722&amp;p=9776#p9776"><![CDATA[
I specifically have tried doing it at the time of writing my challenge-response, tried using the update part, any time I add a code, close the pt and open it again, go to write something else or change something it goes right through without failing due to a missing required key.<br /><br />I just read the help info and it says:<br /><br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />For security reasons and for avoiding accidental reprogramming, YubiKeys can be protected using configuration protection access code.<br />If the configuration protection access code is set, no one can reprogram the YubiKey unless the correct access code is provided during reprogramming.<br /></div><br /><br />So why, after setting a code, can I wipe slot 2 and fill it with gibberish, thus crippling my ability to use it? Assuming I were an attacker finding the Yubikey and wanting to deny access to something or somewhere without stealing the device?<br /><br />I want nobody but me being able to mess around with my Yubikey, I thought that is the whole point of the code?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4910">techwg</a> — Tue Sep 26, 2017 1:21 pm</p><hr />
]]></content>
</entry>
</feed>