<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=1964" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2015-10-13T19:12:49+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=1964</id>
<entry>
<author><name><![CDATA[darco]]></name></author>
<updated>2015-10-13T19:12:49+01:00</updated>
<published>2015-10-13T19:12:49+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7888#p7888</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7888#p7888"/>
<title type="html"><![CDATA[Re: X.509-based Physical Access Control with a Yubikey NEO]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7888#p7888"><![CDATA[
If you don't mind, I'd like to get a nicer writeup (i.e. blog post) about my setup before I start getting too much attention. With any luck I can have that finished over the next week (since I have some free time this week).<br /><br />If it's already been tweeted, then no worries. If I was really concerned about it I shouldn't have posted about it yet. <img src="https://forum.yubico.com/images/smilies/icon_razz.gif" alt=":P" title="Razz" /><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3288">darco</a> — Tue Oct 13, 2015 7:12 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Tom2]]></name></author>
<updated>2015-10-12T10:28:04+01:00</updated>
<published>2015-10-12T10:28:04+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7883#p7883</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7883#p7883"/>
<title type="html"><![CDATA[Re: X.509-based Physical Access Control with a Yubikey NEO]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7883#p7883"><![CDATA[
Nice, let's see if we can get this tweeted today =)<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3364">Tom2</a> — Mon Oct 12, 2015 10:28 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[darco]]></name></author>
<updated>2015-10-11T23:28:04+01:00</updated>
<published>2015-10-11T23:28:04+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7882#p7882</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7882#p7882"/>
<title type="html"><![CDATA[Re: X.509-based Physical Access Control with a Yubikey NEO]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7882#p7882"><![CDATA[
So I've managed to get the thing working fully! Watch here:<br /><br /><!-- m --><a class="postlink" href="https://www.youtube.com/watch?v=fl5KW1p3LQ8">https://www.youtube.com/watch?v=fl5KW1p3LQ8</a><!-- m --><br /><br />Regarding the authentication speed, it is now much faster than it was(It's now a little more than a second), but it's still a tad slower than ideal... Caching the certificate helps a ton. Using ECDSA is also noticeably faster than RSA. But I think the problem at the moment is in the software I'm using (OpenSC's <em>pkcs15-tool</em>) to get the signed nonce from the token is doing a lot of extraneous transactions.<br /><br />I'll eventually be writing my own software to do this, but I've got so many personal projects going on it may be a bit before I can get around to it. :/<br /><br />In any case, I hope to write up a blog post about this setup soon. Will post a link when I do!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3288">darco</a> — Sun Oct 11, 2015 11:28 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Tom2]]></name></author>
<updated>2015-09-15T10:26:28+01:00</updated>
<published>2015-09-15T10:26:28+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7804#p7804</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7804#p7804"/>
<title type="html"><![CDATA[Re: X.509-based Physical Access Control with a Yubikey NEO]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7804#p7804"><![CDATA[
can you tell us about the reader performances? Are you satisfied with it?<br /><br />Does it require to hold the key for long?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3364">Tom2</a> — Tue Sep 15, 2015 10:26 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[darco]]></name></author>
<updated>2015-09-14T19:27:48+01:00</updated>
<published>2015-09-14T19:27:48+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7799#p7799</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7799#p7799"/>
<title type="html"><![CDATA[Re: X.509-based Physical Access Control with a Yubikey NEO]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7799#p7799"><![CDATA[
Just a quick update with a picture:<br /><br />11988363_543105253463_2195101927042392637_n.jpg<br /><br />It's using a CAT-5 USB extender and ACR122U NFC reader. The setup is temporary until I can build a better enclosure... But it works great for prototyping.<br /><br />Still need to get the software working better, but with this now installed I think I'll be more motivated to get that side of things working better. <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":)" title="Smile" /><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3288">darco</a> — Mon Sep 14, 2015 7:27 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Tom2]]></name></author>
<updated>2015-07-15T14:11:25+01:00</updated>
<published>2015-07-15T14:11:25+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7587#p7587</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7587#p7587"/>
<title type="html"><![CDATA[Re: X.509-based Physical Access Control with a Yubikey NEO]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7587#p7587"><![CDATA[
Well done =)<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3364">Tom2</a> — Wed Jul 15, 2015 2:11 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[brendanhoar]]></name></author>
<updated>2015-07-14T23:37:29+01:00</updated>
<published>2015-07-14T23:37:29+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7584#p7584</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7584#p7584"/>
<title type="html"><![CDATA[Re: X.509-based Physical Access Control with a Yubikey NEO]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7584#p7584"><![CDATA[
Aww, anderson power poles. Serious business! <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":)" title="Smile" /><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3142">brendanhoar</a> — Tue Jul 14, 2015 11:37 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[darco]]></name></author>
<updated>2015-07-14T20:51:12+01:00</updated>
<published>2015-07-14T20:51:12+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7577#p7577</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7577#p7577"/>
<title type="html"><![CDATA[X.509-based Physical Access Control with a Yubikey NEO]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1964&amp;p=7577#p7577"><![CDATA[
Hello everyone,<br /><br />I wanted to enter the Yubikey Neo contest, but my life has just been too crazy to put together a slick entry. But I did want to share what I have so far...<br /><br /><!-- m --><a class="postlink" href="https://www.youtube.com/watch?v=dGSfpO6svW0">https://www.youtube.com/watch?v=dGSfpO6svW0</a><!-- m --><br /><br />Above is a video demonstration of my PIV-based physical access control endpoint. It works great, but it's implementation is a bit crufty (basically a bunch of shell scripts, see <a href="https://github.com/darconeous/SimpleCardAuth" class="postlink">here</a>). I'm planning to do a big re-write in node.js over the next few months, which I'll be calling <a href="https://github.com/darconeous/FlexPACS" class="postlink">FlexPACS</a>.<br /><br />Thoughts and comments are welcome.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3288">darco</a> — Tue Jul 14, 2015 8:51 pm</p><hr />
]]></content>
</entry>
</feed>