Yubico Forum

...visit our web-store at store.yubico.com
It is currently Tue Jan 30, 2018 8:29 pm

All times are UTC + 1 hour




Post new topic Reply to topic  [ 3 posts ] 
Author Message
 Post subject: [SOLVED] PIN caching
PostPosted: Sat Oct 24, 2015 6:02 pm 
Offline

Joined: Wed Aug 26, 2015 7:36 pm
Posts: 5
I use my Yubikeys NEO with the personal certificate PKCS installed in the PIV applet. I use also a VPN client (Foticlient from Fortigate) to acces to my corporate network.

I have the problem that the VPN client ask me many times the PIN, because make serveral conection stages.

The question is: is posible make PIN caching (time configurable if possible) to avoid the annoyance and ask me the PIN the first time only in each connection? (I work with Windows 7/64 b)

Thanks in advance.


Last edited by jfm2038 on Mon Nov 16, 2015 4:07 pm, edited 1 time in total.

Top
 Profile  
Reply with quote  

Share On:

Share on Facebook FacebookShare on Twitter TwitterShare on Tumblr TumblrShare on Google+ Google+

PostPosted: Sun Nov 15, 2015 11:53 pm 
Offline

Joined: Sun Nov 15, 2015 11:47 pm
Posts: 36
jfm2038 wrote:
I use my Yubikeys NEO with the personal certificate PKCS installed in the PIV applet. I use also a VPN client (Foticlient from Fortigate) to acces to my corporate network.......
The question is: is posible make PIN caching (time configurable if possible) to avoid the annoyance and ask me the PIN the first time only in each connection? (I work with Windows 7/64 b)
Thanks in advance.


I suspect that the key used for this authentication is Digital Signature key. I think PIV standard forbids using that key without a PIN (i.e. one must re-enter PIN every time this private key is used).

If your VPN client would allow PIN caching and would pass your PIN to NEO every time it's needed - that's up to the client. But I don't think there's a way (or even should be a way) to tell NEO to stop asking for PIN for this key.

Another possibility is to use one of the other keys (the card allows 4 keys in the PIV applet). Probably PIV Auth or Card Auth key would do...


Top
 Profile  
Reply with quote  
 Post subject: Re: [SOLVED] PIN caching
PostPosted: Mon Nov 16, 2015 4:05 pm 
Offline

Joined: Wed Aug 26, 2015 7:36 pm
Posts: 5
Thanks a lot, mouse008

I instaled my certificate in the slot 9a (PIV Authentication) and the VPN-SSL client ask me the PIN only in the initial stage of the connection process.

Bests regards.


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 3 posts ] 

All times are UTC + 1 hour


Who is online

Users browsing this forum: Heise IT-Markt [Crawler] and 10 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group