<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=16&amp;t=2033" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2015-11-23T09:28:28+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=16&amp;t=2033</id>
<entry>
<author><name><![CDATA[Tom2]]></name></author>
<updated>2015-11-23T09:28:28+01:00</updated>
<published>2015-11-23T09:28:28+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2033&amp;p=8007#p8007</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2033&amp;p=8007#p8007"/>
<title type="html"><![CDATA[Re: [QUESTION] Can I have U2F, OTP and SSH/PGP on the same k]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2033&amp;p=8007#p8007"><![CDATA[
0) Are my needs even realistic with EDGE or NEO - is Yubikey the way to go?<br /><br />You need Yubikey4 - yubi.co/yk4<br /><br />1) Modes. It seems most guides say switch to mode 82. This effectively disables the Google authentication. Can I use mode 86 just as well? I'm in 86 right now, and the OTP to this forum works as well as Google (U2F?) with chrome.<br /><br />Depends on what you want activated. If you want supercombo modes (all on)  &quot;ykneomgr -M 86&quot; is the command you're looking for<br /><br />2) Windows drivers for modes 82 and 86 - I have to manually install/select NIST SP 800-73 - Windows 7 does not find drivers manually. Is this a bug - and moreover, does it make a difference<br /><br />This is a problem of your workstation. Windows detects the Yubikey 4 as a PIV smartcard from Windows 7 onward <br /><br />3) Is it even possible to get the desired setup, U2F, OTP (in slot 1) and SSH/PGP (in slot 2)<br /><br />U2F does not consume a &quot;slot&quot;. Slots are only for the OTP side of the device. Please read documentation about U2F at <!-- m --><a class="postlink" href="https://developers.yubico.com/U2F/">https://developers.yubico.com/U2F/</a><!-- m --><br /><br />4) What is wrong: C:\Users\tsmalmbe&gt;gpg-connect-agent --hex &quot;scd apdu 00 f1 00 00&quot; /bye<br />ERR 100663297 General error &lt;SCD&gt;<br /><br />Most likely your Yubikey has CCID interface off or your gpg-agent is not properly configured. You mentioned you have an EDGE which has no smartcard capabilities, thus no OpenPGP. Please read about what your product does on <!-- w --><a class="postlink" href="http://www.yubico.com">www.yubico.com</a><!-- w --><br /><br />5) What is wrong: C:\Users\tsmalmbe&gt;gpg --card-status<br />gpg: OpenPGP card not available: Not supported<br /><br />Same as 4)<br /><br />6) Am I missing this: <!-- m --><a class="postlink" href="https://developers.yubico.com/PGP/Card_edit.html">https://developers.yubico.com/PGP/Card_edit.html</a><!-- m --> - it does not say anything about windows?<br /><br />APDUs are operating system independent. Here is some beginners reading about smart-card which are required to understand common operations:<br /><!-- m --><a class="postlink" href="http://www.smartcardbasics.com/">http://www.smartcardbasics.com/</a><!-- m --><br /><!-- m --><a class="postlink" href="https://en.wikipedia.org/wiki/Smart_card_application_protocol_data_unit">https://en.wikipedia.org/wiki/Smart_car ... _data_unit</a><!-- m --><br /><!-- m --><a class="postlink" href="http://www.cardwerk.com/smartcards/smartcard_standard_ISO7816-4_5_basic_organizations.aspx">http://www.cardwerk.com/smartcards/smar ... tions.aspx</a><!-- m --><br /><br /><br />7 ish<br /><br />Yes you can have OTP, U2F and use your Yubikey for SSH/PAM all together<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3364">Tom2</a> — Mon Nov 23, 2015 9:28 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[tsmalmbe]]></name></author>
<updated>2015-09-17T09:47:54+01:00</updated>
<published>2015-09-17T09:47:54+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2033&amp;p=7810#p7810</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2033&amp;p=7810#p7810"/>
<title type="html"><![CDATA[Re: [QUESTION] Can I have U2F, OTP and SSH/PGP on the same k]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2033&amp;p=7810#p7810"><![CDATA[
...and my next set of questions will then be around the different Linux PAM-approaches as soon as possible. So to make things clear - I would like to have both SSH-keys on the yubico as well as the U2F or OTP pam-module as an option for my customers ssh-logins. All of them are using putty as the client. I'm not really sure which PAM-module is the right way to go. Looking at Centos, RHEL and Ubuntu.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3926">tsmalmbe</a> — Thu Sep 17, 2015 9:47 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[tsmalmbe]]></name></author>
<updated>2015-09-17T09:46:00+01:00</updated>
<published>2015-09-17T09:46:00+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2033&amp;p=7809#p7809</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2033&amp;p=7809#p7809"/>
<title type="html"><![CDATA[[QUESTION] Can I have U2F, OTP and SSH/PGP on the same key?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2033&amp;p=7809#p7809"><![CDATA[
Hi, new here and just got my keys yesterday. I work as a security consultant, and if I get this thing configured and setup, this will most probably be my go-to solution for quite a few of my customers. So on to the questions.<br /><br />Pre's: I'm working in a windows environment. I'm familiar with PGP and SSH as well as ldap, linux and 2FA in general. I have the EDGE-version of the key, but keep in mind I can choose the neo for my customers just as well.<br /><br />Aim: To be able to provide a secure and convenient solution for my customers needs. It has to be convenient.<br />I need the following:<br />* U2F foor google apps and google-based email<br />* U2F for local Linux-servers<br />* SSH-keys for Linux-servers<br />* OTP for various(like this forum for instance)<br />* PGP-keys for email - both windows and Mac (thunderbird/enigmail/kleopatra)<br /><br />Problems: I've ran into a few already.<br />0) Are my needs even realistic with EDGE or NEO - is Yubikey the way to go?<br />1) Modes. It seems most guides say switch to mode 82. This effectively disables the Google authentication. Can I use mode 86 just as well? I'm in 86 right now, and the OTP to this forum works as well as Google (U2F?) with chrome.<br />2) Windows drivers for modes 82 and 86 - I have to manually install/select NIST SP 800-73 - Windows 7 does not find drivers manually. Is this a bug - and moreover, does it make a difference<br />3) Is it even possible to get the desired setup, U2F, OTP (in slot 1) and SSH/PGP (in slot 2)<br />4) What is wrong: C:\Users\tsmalmbe&gt;gpg-connect-agent --hex &quot;scd apdu 00 f1 00 00&quot; /bye<br />ERR 100663297 General error &lt;SCD&gt;<br />5) What is wrong: C:\Users\tsmalmbe&gt;gpg --card-status<br />gpg: OpenPGP card not available: Not supported<br />6) Am I missing this: <!-- m --><a class="postlink" href="https://developers.yubico.com/PGP/Card_edit.html">https://developers.yubico.com/PGP/Card_edit.html</a><!-- m --> - it does not say anything about windows?<br /><br />So all in all. It seems like a huge undertaking to get everything up and running. I would not like to bother my customers with one key per need/requirement. And I cannot have them go thru most of this process themselves - I need to get the keys preconfigured as far as possible, and only have instructions for adding their privates. That's the aim.<br /><br />I will surely appreciate any pointers and all help. I've been playing around for two days now and reading tons of blogs and docs - the basics should be clear to me (but not sure if they are).<br /><br />Thanks.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3926">tsmalmbe</a> — Thu Sep 17, 2015 9:46 am</p><hr />
]]></content>
</entry>
</feed>