Yubico Forum

...visit our web-store at store.yubico.com
It is currently Tue Jan 30, 2018 9:21 pm

All times are UTC + 1 hour




Post new topic Reply to topic  [ 5 posts ] 
Author Message
PostPosted: Tue Dec 09, 2014 8:25 pm 
Offline

Joined: Thu Oct 23, 2014 1:05 am
Posts: 5
I have a Yubico Standard Key that my company has setup for VPN access using OTP.

I recently got a Yubico NEO to use with Google. I'm starting with looking to replace my existing Standard Yubico with the NEO. I've received the Yubico OTP parameters my original standard key was programmed with and I've duplicated that onto the Neo ... but it fails to work with the VPN.

So we have a Yubico OTP Test web site at our company. The original Standard Yubico USB key I have says it verified fine. The NEO which is supposedly programmed with the same configuration details fails.

If the two keys are (supposedly) using identical configuration parameters for OTP, should the NEO both verify on the OTP test side as well as work in our VPN ?

If there anything else related to the NEO that would cause it to fail even though its programmed like my Standard Key ?


Top
 Profile  
Reply with quote  

Share On:

Share on Facebook FacebookShare on Twitter TwitterShare on Tumblr TumblrShare on Google+ Google+

PostPosted: Wed Dec 10, 2014 10:08 am 
Offline
Site Admin
Site Admin

Joined: Mon Dec 08, 2014 2:52 pm
Posts: 314
Counters will fail if you use two keys at the same time, please read how the Yubico OTP protocol works here:
https://www.yubico.com/wp-content/uploa ... l-v3.3.pdf

You can find an implementation of Yubico OTP generation in this repository:
https://github.com/Yubico/yubico-c


Top
 Profile  
Reply with quote  
PostPosted: Fri Dec 12, 2014 4:57 am 
Offline

Joined: Thu Oct 23, 2014 1:05 am
Posts: 5
Ahhh thank you for the reference. Thinking this is specifically what you are referring to:

The non-volatile counter is compared with the previously received
value. If lower than or equal to the stored value, the received OTP is
rejected as a replay.

That is likely exactly what is happening.

So what should be done to my account in this case ? Does the account get "reset" somehow to reset the server's expectation of my counter value ?


Top
 Profile  
Reply with quote  
PostPosted: Fri Dec 12, 2014 10:39 am 
Offline
Site Admin
Site Admin

Joined: Mon Dec 08, 2014 2:52 pm
Posts: 314
Use one Yubikey, and submit OTP until the counter is synced again

stop using the other key


Top
 Profile  
Reply with quote  
PostPosted: Fri Dec 12, 2014 9:00 pm 
Offline

Joined: Tue Nov 18, 2014 9:14 pm
Posts: 95
Location: San Jose, CA
I believe you can also set the moving factor seed (if you happen to know approximately what the counter it in your other yubikey) in the yubikey personalization tool if you don't want to manually press the OTP button a crazy number of times.


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 5 posts ] 

All times are UTC + 1 hour


Who is online

Users browsing this forum: Heise IT-Markt [Crawler] and 6 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group