Yubico Forum
https://forum.yubico.com/

Questions about local vs yubico validation server
https://forum.yubico.com/viewtopic.php?f=5&t=360
Page 1 of 1

Author:  Cam [ Sat Jul 25, 2009 11:08 am ]
Post subject:  Questions about local vs yubico validation server

I would like to use a yubikey to log into a local machine, but also use the key for web login with OpenID. In several places it warns about the problems of using more than one validation server but doesn't say what bad things will happen if I do.

Is there some limit on the counter values such that the server won't validate if the delta is too large? I suppose a huge delta would be suspicious but small ones seem to work OK (consider someone demonstrating the key by entering OTPs into a terminal).

What if my local machine ran a validation server purely to service logins, then if / when the network was available it could replay the OTPs that have been used into the Yubico 'master' validation server so that no-one else can use them? Would that be good?

-Cam

Author:  network-marvels [ Mon Jul 27, 2009 3:15 pm ]
Post subject:  Re: Questions about local vs yubico validation server

The biggest security risk in validating the OTP with both online and local validation server is the replayed OTP attack. As both the databases will be out of sync, a OTP already validated at one validation server can be successfully re-validated at the other server.

If you replay all the OTP (already validated against the online validation server) with the local validation server, the database will be in sync with the online validation server's database. This way the replayed OTP attack can be avoided, but it is risky if the re-validation of OTP fails or if the user start validating already used OTP before the OTP replay (for syncing the database) is completed.

Page 1 of 1 All times are UTC + 1 hour
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/