<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=16&amp;t=2113" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2016-02-01T03:00:40+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=16&amp;t=2113</id>
<entry>
<author><name><![CDATA[asdf345]]></name></author>
<updated>2016-02-01T03:00:40+01:00</updated>
<published>2016-02-01T03:00:40+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2113&amp;p=8236#p8236</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2113&amp;p=8236#p8236"/>
<title type="html"><![CDATA[Re: [QUESTION] Using Yubikey with Kerberos]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2113&amp;p=8236#p8236"><![CDATA[
Have a look at FreeIPA, it's already integrated there.<br />It currently only works with MIT Kerberos on Linux. <br /><br />Kerberos usually works like this: You request a Login for a certain ID, KDC sends you an encrypted message which you locally decrypt using your password. This obviously doesn't work with OTP.<br /><br />For OTP FreeIPA uses the following:<br />You establish a secure channel to the KDC using anonymous PKINIT (you will have to verify the certificate), after that you send Password+OTP in clear text to the KDC, which can use any RADIUS server to verify it.<br /><br />Other platforms:<br />Heimdal doesn't support OTP, MIT Kerberos for Windows has issues with PKINIT, Windows doesn't support it at all.<br />On Mac OS X, you can manually install MIT Kerberos.<br /><br />It's probably easier to use the Yubikey as a smartcard and use certificate based login.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4167">asdf345</a> — Mon Feb 01, 2016 3:00 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Himartin]]></name></author>
<updated>2015-11-30T21:34:19+01:00</updated>
<published>2015-11-30T21:34:19+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2113&amp;p=8033#p8033</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2113&amp;p=8033#p8033"/>
<title type="html"><![CDATA[[QUESTION] Using Yubikey with Kerberos]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2113&amp;p=8033#p8033"><![CDATA[
Hi,<br /><br />is it possible to use use the Yubikey with a Kerberos-Server to obtain the Kerberos tickets and has anybody sucessfully set up such a setup?<br /><br />I don't care if it needs MIT or Heimdal Kerberos. Also challenge-response or OTP are fine (though the latter probably requires less changes in the client software).<br />The most recent thread I found for this topic is <a href="http://forum.yubico.com/viewtopic.php?f=4&amp;t=771" class="postlink">this one</a>, and it's rather old with most of the links being broken by now.<br /><br />Thanks<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4059">Himartin</a> — Mon Nov 30, 2015 9:34 pm</p><hr />
]]></content>
</entry>
</feed>