Yubico Forum

...visit our web-store at store.yubico.com
It is currently Tue Jan 30, 2018 8:12 pm

All times are UTC + 1 hour




Post new topic Reply to topic  [ 6 posts ] 
Author Message
PostPosted: Fri Feb 19, 2010 10:27 pm 
Offline

Joined: Fri Feb 19, 2010 10:18 pm
Posts: 5
So I get a first Yubi newsletter for Feb:

> We have received reports from happy customers using the YubiKey with Clavid’s free OpenID service, for loging on to FaceBook and other popular websites supporting OpenID.

Your kidding, right? All I can find is forum posts of folks trying to get it to work with no satisfactory result. So whats the trick? Where the how-to?


Last edited by simbo1905 on Sat Feb 20, 2010 10:05 am, edited 1 time in total.

Top
 Profile  
Reply with quote  

Share On:

Share on Facebook FacebookShare on Twitter TwitterShare on Tumblr TumblrShare on Google+ Google+

PostPosted: Fri Feb 19, 2010 10:33 pm 
Offline

Joined: Fri Feb 19, 2010 10:18 pm
Posts: 5
[off topic]


Last edited by simbo1905 on Sat Feb 20, 2010 10:04 am, edited 1 time in total.

Top
 Profile  
Reply with quote  
PostPosted: Sat Feb 20, 2010 12:13 am 
Offline

Joined: Fri Feb 19, 2010 10:18 pm
Posts: 5
Okay I got things working. It works for me with Chrome and Firefox on Linux.

Setup:

1) get your yubikey
2) got to clavid.com. use the yubikey registration. choose a username which matches your yubi username to keep you sane.
3) your are not yet fully registered. you need to login to clavid.com and complete registration by setting up your email address. it will send you an email with a link to activate your account
4) login to clavid (Secure Login link on right which changes to be Reserved Area link if you are logged in which is bad user interface design)
5) within the clavid site once logged in go to the Reserved Area and click Account Settings and then Your OpenID Sites. Add a new site. NOTE you need to know the exact url you are going to use to login to facebook so type it carefully "http://www.facebook.com"
6) go to facebook. if you at this point you should logout of facebook ("Account > Log Out" top right). Unselect the box "Keep Me Logged In" and login with your username and password. this step of logging out and logging in is simply to clear the Keep Me Logged In option from the facebook homepage as it seems to interfer with the automatic login once it is setup as follows.
7) go to Account > Account Settings. On the Setting tab halfway down the page is Linked Accounts. Go into that.
8) Add a new linked account of type OpenID... and enter the url as your username dot clavid dot com "http://username.clavid.com" where you use your username as part of the url.

Now to test it:

1) close down all browsers to ensure you are fully logged out.
2) go to http://username.clavid.com (once again use your username in that - you may as well bookmark that page)
3) click Secure Login on the right and select Yubikey login. Annoyingly you have to retype your username.
4) now go to http://www.facebook.com (IMPORTANT: THIS MUST BE THE EXACT URL THAT YOU SETUP AT SETUP STEP 5)
5) you will see the facebook login screen but the browser should still act like it has not finished loading the page whilst it does the autologin. This take 10 seconds on my machine so be patient.
6) your homepage will automatically load

All in all it is a real hassle to set this up. I would not even try to attempt to persuade someone who did not work in IT to attempt to get all of this working. So right now I would say it is for early adopters.

:ugeek:

p.s. another gripe with clavid is that it says it has the worlds easiest yubikey registration but it does not ask you for your email on that to send you your registration link automatically.

p.p.s this does not work for me using the epiphany browser on linux. since i don't use that browser much at all i am not going to see if fiddling with the cookie security settings would get it to work.


Top
 Profile  
Reply with quote  
PostPosted: Sat Feb 20, 2010 12:25 am 
Offline

Joined: Fri Feb 19, 2010 10:18 pm
Posts: 5
one thought is why cannot I not go to http://myusername.clavid.com and just see a yubikey login form with my username autopopulated (from the url I used) and then once i login with yubikey could it not just show me a list of links to my openId sites for me to click on to go straight into? surely such a google-like minimalistic ui is what people really expect to see these days with a lot less clicking about. heck i would be happy to see some google ad links on such a page as it would make the whole thing so much easier.

Simon


Last edited by simbo1905 on Sat Feb 20, 2010 12:32 am, edited 1 time in total.

Top
 Profile  
Reply with quote  
PostPosted: Sat Feb 20, 2010 12:29 am 
Offline

Joined: Fri Feb 19, 2010 10:18 pm
Posts: 5
i tried to send a link to this post to the clavid folks using their contact us form on their site to be fair to them but their joomla setup is screwed up such that you have to be logged into submit the contact us form. if someone at yubico has their email details please forward them a link to this thread form them to get this end user feedback. thx.


Top
 Profile  
Reply with quote  
PostPosted: Sun Feb 21, 2010 7:05 pm 
Offline
User avatar

Joined: Sun Aug 17, 2008 7:06 pm
Posts: 11
Location: Switzerland
Hi, I'm from Clavid trying to explain some things. The OpenID implementation we support to OpenID based login to facebook is not very user friendly. It would be much simpler if facebook would provide a 'Login with OpenID' possibility on their login page, as most other applications do. Currently, the facebook OpenID implementation requires 3rd party cookies to be enabled (default in Firefox but must be enabled on Safari or other browsers). We can't do much about that. That's something to be solved by facebook. We asked the guys from facebook and they told us they have a improved OpenID implementation on the agenda for 2010.

Thanks a lot simbo1905 for explaining the steps required to login to facebook. We really appreciate your help. The actual really required steps should be:

Account Linking:
1) Your browser must support or be enabled for 3rd party cookies.
2) Link your facebook account with calved in the facebook account settings. You can use your OpenID in the simple form 'username.clavid.com'.

Login: Afterwards, your login steps are:
1) Goto http://clavid.com/portal and login.
2) Goto http://www.facebook.com/ and it should automatically change to your logged in facebook profile.

In the next Clavid release (which in in testing now and should be available in the next 1-2 weeks), we will put a small icon on the Clavid portal page (the URL your end-up after login to http://clavid.com/portal). That will allow you to just click on that facebook symbol which will get you directly to your facebook profile.

BTW: the Clavid support mail address is: support [at] clavid.com

_________________
YubiKey & OpenID/SAML => web security without compromising usability!


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 6 posts ] 

All times are UTC + 1 hour


Who is online

Users browsing this forum: Heise IT-Markt [Crawler] and 4 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group