Yubico Forum

...visit our web-store at store.yubico.com
It is currently Tue Jan 30, 2018 1:42 pm

All times are UTC + 1 hour




Post new topic Reply to topic  [ 8 posts ] 
Author Message
PostPosted: Tue Jan 24, 2017 6:14 pm 
Offline

Joined: Thu Jan 19, 2017 2:02 pm
Posts: 6
Hello! I'm trying to use my YubiKey Neo with Lastpass but it's never worked for me.

In my Lastpass settings, I have setup Yubikey as my PRIMARY multifactor option. My Yubikey is registered in LastPass as key 1.

When I launch Chrome, a second tab opens asking me to INSERT KEY and PRESS BUTTON. When I do this, the field is populated but the tab closes immediately, then open again asking me again to INSERT KEY and PRESS BUTTON. I have uninstalled/reinstalled the extension without any improvement. I have attempted to seek assistance at the LastPass forum without success. I have been told that the tab will reload when the OTP is wrong. How can it be wrong? I registered it as key 1 in LastPass settings, so should it not be the same. No?

I should mention that prior to using LastPass, i tried Password Safe and followed these instructions: https://www.yubico.com/why-yubico/for-i ... word-safe/

Did I mess up my Yubikey by following these instructions. Is there a way to factory restore the Yubikey? My YubiKey works in every other aspect (Yubico authenticator, Google account, etc..) but unable to get it to work with LastPass.

Please help! Thanks!


Last edited by Zoidberg on Sat Jan 28, 2017 5:32 pm, edited 1 time in total.

Top
 Profile  
Reply with quote  

Share On:

Share on Facebook FacebookShare on Twitter TwitterShare on Tumblr TumblrShare on Google+ Google+

PostPosted: Tue Jan 24, 2017 10:28 pm 
Offline
Yubico Team
Yubico Team

Joined: Thu Oct 16, 2014 3:44 pm
Posts: 349
Test the OTP at demo.yubico.com. If it works here, re-register in LastPass. If it doesn't work there again, contact LastPass support.

If our OTP demo doesn't work, you'll need to reprogram following these instructions - https://www.yubico.com/support/knowledg ... ion-guide/


Top
 Profile  
Reply with quote  
PostPosted: Tue Jan 24, 2017 11:52 pm 
Offline

Joined: Thu Jan 19, 2017 2:02 pm
Posts: 6
Thank you! I have gone to demo.yubico.com, selected the SINGLE FACTOR tab, pressed the button, the field populated then I received a message "Congratulations, you have been successfully authenticated". But I still can't get it to work in LastPass.

I followed the instructions in the link you provided. One clarification: It states "Open a text editor. Insert your YubiKey into a USB port of your computer, and touch the gold button. If you see cccccc in the text editor, then your Yubikey is generating OTPs."
Not sure what they mean by "cccccc" because I'm getting a 46 character alphas that starts with "vvbjdl".

I've reached out to LastPass, but not getting much help. Thanks again.


Top
 Profile  
Reply with quote  
PostPosted: Wed Jan 25, 2017 5:53 am 
Offline
Yubico Team
Yubico Team

Joined: Thu Oct 16, 2014 3:44 pm
Posts: 349
The default Yubico OTP credentials that come on all YubiKeys start with "cccccc" and are 44 characters long. That's what LastPass is referring to. The "vv" credentials are user programmed, and work on LastPass as well as long as the AES key has been uploaded to the YubiCloud (the last steps of the programming document I referenced). Basically, as long as the OTP works at demo.yubico.com, the credential can be added to LastPass and used for authentication.

https://helpdesk.lastpass.com/multifact ... ntication/


Top
 Profile  
Reply with quote  
PostPosted: Wed Jan 25, 2017 2:38 pm 
Offline

Joined: Thu Jan 19, 2017 2:02 pm
Posts: 6
Thanks for the reply. It seem that I updated my YubiKey with "vv" credentials. I successfully uploaded them to YubiCloud and passed the test at demo.yubico.com but LastPass still won't accept my OTP in the Chrome extension. Is there any way to revert the credentials to "cccccc" just in case that LastPass insists on "cccccc"?

EDIT: I learned that I can set "cccccc" in Advanced mode. However, the Advanced mode does not have an option to "Upload to Yubico". After writing the "cccccc" configuration, I attempted to register my YubiKey with Lastpass, but receive "Yubikey token failed to validate". If I configure in Advanced mode, how am I supposed to upload to Yubico?


Top
 Profile  
Reply with quote  
PostPosted: Wed Jan 25, 2017 4:41 pm 
Offline
Yubico Team
Yubico Team

Joined: Thu Oct 16, 2014 3:44 pm
Posts: 349
User programmed OTP credentials MUST start with "vv", otherwise they cannot be uploaded to the YubiCloud - there are no exceptions. The default credential cannot be restored - the secrets used during programming are only known by the YubiCloud.

There are no issues with "vv" credentials in LastPass. I have several on my account and they all work perfectly.

LastPass also has their own Yubico OTP test page - https://lastpass.com/debug_yubikey.php


Top
 Profile  
Reply with quote  
PostPosted: Wed Jan 25, 2017 4:51 pm 
Offline

Joined: Thu Jan 19, 2017 2:02 pm
Posts: 6
Thanks. I set my YubiKey with "vv" credentials, re-uploaded to Yubico and then tried the LastPass test page and got: SUCCESS! : [vv...] is a VALID QWERTY OTP

I also tried the LastPass add-on in Firefox and getting the same behavior. The key is properly registered at LastPass.com but when I enter the key (press the button) it isn't accepted.

Looks like my issue is fully with LastPass.

Thanks for your help nonetheless.


Top
 Profile  
Reply with quote  
PostPosted: Sat Jan 28, 2017 5:39 pm 
Offline

Joined: Thu Jan 19, 2017 2:02 pm
Posts: 6
So after several back/forth with LastPass support, they advised me that Yubikey support was only available to Premium (paid) subscribers and I was enrolled in a FREE membership. Although I was aware of this, I signed-up about 2 weeks ago and they sent me an email with the following:

"Thank you for creating a LastPass account. LastPass is always free, but to help you get started we've also unlocked our Premium features for 60 days."

With this, I had reasonable expectations that my Yubikey would work, but they assured me that I need to have a paid account. I replied to them advising that I wasted countless hours trying to get it to work and I strongly suggested they change their welcome email to remove the reference to Premium features being unlocked for 60 days.

At this point, given the negativity of the experience with LastPass, I can't see myself giving them any money to subscribe to Premium.

Cheers.


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 8 posts ] 

All times are UTC + 1 hour


Who is online

Users browsing this forum: Heise IT-Markt [Crawler] and 11 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group