<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=23&amp;t=1786" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2015-03-14T00:32:01+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=23&amp;t=1786</id>
<entry>
<author><name><![CDATA[tabg]]></name></author>
<updated>2015-03-14T00:32:01+01:00</updated>
<published>2015-03-14T00:32:01+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1786&amp;p=7029#p7029</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1786&amp;p=7029#p7029"/>
<title type="html"><![CDATA[SSH/Linux login]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1786&amp;p=7029#p7029"><![CDATA[
Hello,<br /><br />I have Yubikey Std and want to use it for remote ssh login. As far as I know, the existing method is with cloud server or similar solution with local/private installation of &quot;cloud&quot; login server. I have idea for more simple and useful solution (not sure whether it already exists). I will explain it from user viewpoint:<br /><br />1. When connected on ssh/telnet/local console, you get &quot;Username:&quot; prompt;<br />2. If you enter normal username, Password: prompt follows for regular login;<br />3. If you click on Yubikey configured for OTP, the long string &quot;ccccccblr.....&quot; is entered for username. Here is the modified module/library - it recognizes the YC OTP user name (from the length + starting cccc..) and allows or denies the access (without Password prompt line). Linux module keeps increasing counter for OTP in protected file and the AES shared secret;<br />4. The module/software calculates the counter from OTP username and if the value is greather than stored value, the login is successful.<br /><br />There is no cloud or other 3rd party or local server. The only security risk is from replay attack - if the same YC is used on 2+ servers. The advantage of all this is ability to login to remote server from unsafe terminal without risk of keyboard loggers.<br /><br />The question is: If such module already exists, where to find it?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3597">tabg</a> — Sat Mar 14, 2015 12:32 am</p><hr />
]]></content>
</entry>
</feed>