Yubico Forum

...visit our web-store at store.yubico.com
It is currently Tue Jan 30, 2018 11:08 am

All times are UTC + 1 hour




Post new topic Reply to topic  [ 6 posts ] 
Author Message
PostPosted: Sat Oct 28, 2017 8:52 pm 
Offline

Joined: Sun Mar 08, 2015 5:05 pm
Posts: 8
I had previously posed this question in another thread -- viewtopic.php?f=35&t=2722 -- but never received a definitive answer.

So I'm trying again here w/ a more "descriptive" Subj line

Question: Is it possible to config-protect a "Challenge-Reply" configuration in Slot 2 WITHOUT changing / over-writing the previously-entered "Secret Key" ?

I've tried several times but have been unsuccessful on each attempt.


Last edited by LD2gIlShWrA2J9qFcwS5 on Wed Nov 01, 2017 2:34 am, edited 1 time in total.

Top
 Profile  
Reply with quote  

Share On:

Share on Facebook FacebookShare on Twitter TwitterShare on Tumblr TumblrShare on Google+ Google+

PostPosted: Sun Oct 29, 2017 4:49 pm 
Offline

Joined: Tue Feb 02, 2016 9:23 pm
Posts: 58
you go into settings press update settings and there you can set the protection.


Top
 Profile  
Reply with quote  
PostPosted: Tue Oct 31, 2017 12:21 am 
Offline
Yubico Team
Yubico Team

Joined: Thu Oct 16, 2014 3:44 pm
Posts: 349
I think I figured out what's going on here. Firmware 4.3.4 and 4.3.5 there was a bug that didn't allow updating configuration protection on the slot credentials. 4.2.6-4.3.3 work, as do 4.3.6 and newer. When I responded on the other thread I'm speaking from experience (works). When my colleague responded on the support case that was referred to on the other post, he was testing on 4.3.4 because he wasn't sure (hence the two different answers).

So on a 4.3.4 or 4.3.5 firmware YK4, you need to reprogram the credential in order to set an access code. If you have the configuration log (csv file), you can simply choose the same settings in the Personalization Tool and set the access code during programming. Just remember... forgetting an access code after setting one means there's no way to make changes to that slot anymore (or enable/disable modes - OTP/CCID/U2F).


Top
 Profile  
Reply with quote  
PostPosted: Tue Oct 31, 2017 8:06 pm 
Offline

Joined: Tue Feb 02, 2016 9:23 pm
Posts: 58
ChrisHalos wrote:
Just remember... forgetting an access code after setting one means there's no way to make changes to that slot anymore (or enable/disable modes - OTP/CCID/U2F).


how does that last part even make sense? the config protection applies to slot 1 or 2, but the modes the Yubi acts in are neither related to the slots to nor the personalization tool in the first place.


Top
 Profile  
Reply with quote  
PostPosted: Wed Nov 01, 2017 2:27 am 
Offline

Joined: Sun Mar 08, 2015 5:05 pm
Posts: 8
My1 wrote:
... you go into settings press update settings and there you can set the protection ...

My1:

Thank you so much! :D

I'd never investigated that innocuous little button down there at the bottom of the page w/ the grayed-out text.

It was EXACTLY what I was looking for.

Thanks again,

Cheers,


Top
 Profile  
Reply with quote  
PostPosted: Wed Nov 01, 2017 2:33 am 
Offline

Joined: Sun Mar 08, 2015 5:05 pm
Posts: 8
ChrisHalos wrote:
... I think I figured out what's going on here ...

Chris:

A sincere "Thank You" for the extra clarifications re: potentially differing behaviors based on firmware versions.

Cheers,


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 6 posts ] 

All times are UTC + 1 hour


Who is online

Users browsing this forum: No registered users and 4 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group