Yubico Forum
https://forum.yubico.com/

[SOLVED] Yubikey 4 with Keepass 2 -Dosent work
https://forum.yubico.com/viewtopic.php?f=35&t=2273
Page 1 of 1

Author:  HDDControler [ Sat Apr 02, 2016 4:06 pm ]
Post subject:  [SOLVED] Yubikey 4 with Keepass 2 -Dosent work

Hello and greatings to all.

1.
Ive done with a brand new Yubikey 4 (not Neo) the following steps. And I become a error after the fields are filled. But I can recover the Passwordfile sucessfull. The Hexadecimal Code isnt incorrect. I repeat Ist is the correct Hex Code. I done my yubikey4 "restore to Defaults". And now i do the Prozedure live again. Please say me there are my fault(s) or mistakes.

2. Thirst Things Thirst: :lol:

O.S. Version : Microsoft Windows 10
Keepass Version: 2.3.2
otpkeyprov Version: 2.4
yubikey-personalization-gui Version: 3.1.24
3. lets go:


I open the Yubikey....gui:
I go to Settings:
cange Enter to off
I go to oath-hotp :
And i Switch to the second Slot .
then i thake the next Settings

I disable Oath-Token Identifier

Check thé Box: Hotp-Length 8 Digits

Then i push the"generate" button and Copy the Hex-Code into a Textfile.


then i press Write Configuration
see Pictures above:

That Looks like so:

Attachment:
yubisetupend.PNG
yubisetupend.PNG [ 39.23 KiB | Viewed 3976 times ]


Thats all for the Yubikey at first. the next ive done in Keepass. See the Next Pictures:

open keepass and create new Password datafile. Ive put a Password in and select one time Password then i hit ok.
Attachment:
File comment: i put the write Code in and do the setings
puthexin.PNG
puthexin.PNG [ 41.11 KiB | Viewed 3976 times ]

When i try to open this error Comes:
Attachment:
error.PNG
error.PNG [ 66.32 KiB | Viewed 3976 times ]


Im Verry verry Hopefully for Help.
Please Help.

Author:  horvathrudolf [ Sun Apr 03, 2016 9:10 am ]
Post subject:  Re: [Question] Yubikey 4 with Keepass 2 -Dosent work

You have to press and hold your yubikey button for several seconds in order to get the slot 2 output.
If you only press it shortly, you get your slot 1 output (yubikey OTP).

Apart from this, I have the same problem. I tried all steps four times. When I finally try to open my locked KeePass file, I enter my password, select OTP and then I have to enter 3 OTPs. I press and hold my yubikey button and an 8-digit code is entered. I choose the second and then third text field and repeat the process twice. So all (three) text fields contain a different 8-digit code and when I press "OK", I get "Failed to create OTP key!".

Author:  HDDControler [ Sun Apr 03, 2016 2:46 pm ]
Post subject:  Re: [Question] Yubikey 4 with Keepass 2 -Dosent work

Hello and thanks for your answer.

I must tell you that i find out how it is Funktion. You MUST THAKE THE CALLANGE-RESPONSE MODE.
Oh i hope i have write it correctly. But Then ist is O.K. . It works.

After i bekame an answer i Close tis thread. As Sucesssfull.

I Repeat : The Goal is The Cannenge- ...Mode.

Byby

Author:  ChrisHalos [ Sun Apr 03, 2016 6:29 pm ]
Post subject:  Re: [Question] Yubikey 4 with Keepass 2 -Dosent work

If using OATH-HOTP, you'll also want to make sure that the "Look-ahead count" is AT MINIMUM 5 (between 5 and 10 seems to work consistently). Since it's counter-based, even one OATH-HOTP sent outside of KeePass will make your counter out of sync and the look-ahead count is used to mitigate this issue.

You are correct, though, that Challenge-Response (at least in my opinion) is a more useful option, and you can use the same Challenge-Response credential for other services.

Author:  horvathrudolf [ Sun Apr 03, 2016 7:06 pm ]
Post subject:  Re: [Question] Yubikey 4 with Keepass 2 -Dosent work

ChrisHalos wrote:
If using OATH-HOTP, you'll also want to make sure that the "Look-ahead count" is AT MINIMUM 5 (between 5 and 10 seems to work consistently).


Maybe you should add this tip to your own guide. I currently use challenge-response mode. Thanks. (Wouldn't be implementing HMAC-SHA256 far more secure?)

Author:  HDDControler [ Sun Apr 03, 2016 9:33 pm ]
Post subject:  Re: [Question] Yubikey 4 with Keepass 2 -Dosent work

Hey Ho thanks to all.
I try it just not out but the solution seems to be the Look-Ahead Accound.
Thanks for this Information.

Author:  Tom2 [ Tue Apr 05, 2016 8:48 am ]
Post subject:  Re: [SOLVED] Yubikey 4 with Keepass 2 -Dosent work

I recommend using KeeChallenge instead.
http://www.kahusecurity.com/2014/securi ... nd-factor/

Author:  r00f [ Sun May 22, 2016 11:15 am ]
Post subject:  Re: [SOLVED] Yubikey 4 with Keepass 2 -Dosent work

I had the same problem, after many tries never managed to make OTP work with Keepass.

As suggested, switched to Keechallenge, works like a charm.

Page 1 of 1 All times are UTC + 1 hour
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/