Yubico Forum

...visit our web-store at store.yubico.com
It is currently Tue Jan 30, 2018 3:02 pm

All times are UTC + 1 hour




Post new topic Reply to topic  [ 2 posts ] 
Author Message
PostPosted: Sat Jul 25, 2009 11:08 am 
Offline

Joined: Mon Jul 20, 2009 10:07 pm
Posts: 3
I would like to use a yubikey to log into a local machine, but also use the key for web login with OpenID. In several places it warns about the problems of using more than one validation server but doesn't say what bad things will happen if I do.

Is there some limit on the counter values such that the server won't validate if the delta is too large? I suppose a huge delta would be suspicious but small ones seem to work OK (consider someone demonstrating the key by entering OTPs into a terminal).

What if my local machine ran a validation server purely to service logins, then if / when the network was available it could replay the OTPs that have been used into the Yubico 'master' validation server so that no-one else can use them? Would that be good?

-Cam


Top
 Profile  
Reply with quote  

Share On:

Share on Facebook FacebookShare on Twitter TwitterShare on Tumblr TumblrShare on Google+ Google+

PostPosted: Mon Jul 27, 2009 3:15 pm 
Offline
Yubico Team
Yubico Team

Joined: Wed Oct 01, 2008 8:11 am
Posts: 210
The biggest security risk in validating the OTP with both online and local validation server is the replayed OTP attack. As both the databases will be out of sync, a OTP already validated at one validation server can be successfully re-validated at the other server.

If you replay all the OTP (already validated against the online validation server) with the local validation server, the database will be in sync with the online validation server's database. This way the replayed OTP attack can be avoided, but it is risky if the re-validation of OTP fails or if the user start validating already used OTP before the OTP replay (for syncing the database) is completed.


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 2 posts ] 

All times are UTC + 1 hour


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
Powered by phpBB® Forum Software © phpBB Group