<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=5&amp;t=871" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2012-12-07T09:10:33+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=5&amp;t=871</id>
<entry>
<author><name><![CDATA[hvbuel]]></name></author>
<updated>2012-12-07T09:10:33+01:00</updated>
<published>2012-12-07T09:10:33+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=871&amp;p=3372#p3372</id>
<link href="https://forum.yubico.com/viewtopic.php?t=871&amp;p=3372#p3372"/>
<title type="html"><![CDATA[Re: Allowing YubiRADIUS auth without having a Yubikey]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=871&amp;p=3372#p3372"><![CDATA[
You can assign a temporary fixed code to user2.<br />Inform user2 about the code and user2 can then login using his normal credentials and use the temporary code in the yubikey field.<br />Temporary codes can be set from the yubiradius management page.<br /><br />We use this if someone has lost his yubikey and needs access to our Citrix farm.<br />We then set the temp. code to be valid for only 2 or 3 days, the time it takes for the new yubikey to reach him.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1863">hvbuel</a> — Fri Dec 07, 2012 9:10 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[lurch89]]></name></author>
<updated>2012-10-18T01:07:10+01:00</updated>
<published>2012-10-18T01:07:10+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=871&amp;p=3321#p3321</id>
<link href="https://forum.yubico.com/viewtopic.php?t=871&amp;p=3321#p3321"/>
<title type="html"><![CDATA[Allowing YubiRADIUS auth without having a Yubikey]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=871&amp;p=3321#p3321"><![CDATA[
I've been searching for a solution, and I will admit I'm not very good with FreeRADIUS (yet...). I set up the YubiRADIUS VA successfully, and am able to authenticate via RADIUS with an Apache page. I want to implement this for a large group of users, but I am not able to purchase Yubikeys for everyone. I would like to have the Yubikey authorization to be toggle-able for a user.<br /><br />For example:<br /><br />User1 is a system administrator. Their account has access to sensitive information. User2 is a standard user, which has access to only non-sensitive systems and data. Assume Active Directory.<br /><br />User1 has a Yubikey assigned to them. They will always need to use their Yubikey when they want to log in (appended to their password).<br />User2 does not have a Yubikey. They should be able to use their username and password, without a Yubikey.<br /><br />Both authorizations would be done against the same RADIUS server. Even better would be to do this with groups (members of a certain group require Yubikeys).<br /><br />Is there any way to get this going? I know the ideal solution is to give everyone a Yubikey, but that is not practical for my application.<br /><br />Thanks!<br />-Andrew, lurch89<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2180">lurch89</a> — Thu Oct 18, 2012 1:07 am</p><hr />
]]></content>
</entry>
</feed>