Yubico Forum https://forum.yubico.com/ |
|
[SOLVED] Yubikey 4 with Keepass 2 -Dosent work https://forum.yubico.com/viewtopic.php?f=35&t=2273 |
Page 1 of 1 |
Author: | HDDControler [ Sat Apr 02, 2016 4:06 pm ] |
Post subject: | [SOLVED] Yubikey 4 with Keepass 2 -Dosent work |
Hello and greatings to all. 1. Ive done with a brand new Yubikey 4 (not Neo) the following steps. And I become a error after the fields are filled. But I can recover the Passwordfile sucessfull. The Hexadecimal Code isnt incorrect. I repeat Ist is the correct Hex Code. I done my yubikey4 "restore to Defaults". And now i do the Prozedure live again. Please say me there are my fault(s) or mistakes. 2. Thirst Things Thirst: O.S. Version : Microsoft Windows 10 Keepass Version: 2.3.2 otpkeyprov Version: 2.4 yubikey-personalization-gui Version: 3.1.24 3. lets go: I open the Yubikey....gui: I go to Settings: cange Enter to off I go to oath-hotp : And i Switch to the second Slot . then i thake the next Settings I disable Oath-Token Identifier Check thé Box: Hotp-Length 8 Digits Then i push the"generate" button and Copy the Hex-Code into a Textfile. then i press Write Configuration see Pictures above: That Looks like so: Attachment: yubisetupend.PNG [ 39.23 KiB | Viewed 3976 times ] Thats all for the Yubikey at first. the next ive done in Keepass. See the Next Pictures: open keepass and create new Password datafile. Ive put a Password in and select one time Password then i hit ok. Attachment:
File comment: i put the write Code in and do the setings puthexin.PNG [ 41.11 KiB | Viewed 3976 times ] When i try to open this error Comes: Attachment: error.PNG [ 66.32 KiB | Viewed 3976 times ] Im Verry verry Hopefully for Help. Please Help. |
Author: | horvathrudolf [ Sun Apr 03, 2016 9:10 am ] |
Post subject: | Re: [Question] Yubikey 4 with Keepass 2 -Dosent work |
You have to press and hold your yubikey button for several seconds in order to get the slot 2 output. If you only press it shortly, you get your slot 1 output (yubikey OTP). Apart from this, I have the same problem. I tried all steps four times. When I finally try to open my locked KeePass file, I enter my password, select OTP and then I have to enter 3 OTPs. I press and hold my yubikey button and an 8-digit code is entered. I choose the second and then third text field and repeat the process twice. So all (three) text fields contain a different 8-digit code and when I press "OK", I get "Failed to create OTP key!". |
Author: | HDDControler [ Sun Apr 03, 2016 2:46 pm ] |
Post subject: | Re: [Question] Yubikey 4 with Keepass 2 -Dosent work |
Hello and thanks for your answer. I must tell you that i find out how it is Funktion. You MUST THAKE THE CALLANGE-RESPONSE MODE. Oh i hope i have write it correctly. But Then ist is O.K. . It works. After i bekame an answer i Close tis thread. As Sucesssfull. I Repeat : The Goal is The Cannenge- ...Mode. Byby |
Author: | ChrisHalos [ Sun Apr 03, 2016 6:29 pm ] |
Post subject: | Re: [Question] Yubikey 4 with Keepass 2 -Dosent work |
If using OATH-HOTP, you'll also want to make sure that the "Look-ahead count" is AT MINIMUM 5 (between 5 and 10 seems to work consistently). Since it's counter-based, even one OATH-HOTP sent outside of KeePass will make your counter out of sync and the look-ahead count is used to mitigate this issue. You are correct, though, that Challenge-Response (at least in my opinion) is a more useful option, and you can use the same Challenge-Response credential for other services. |
Author: | horvathrudolf [ Sun Apr 03, 2016 7:06 pm ] |
Post subject: | Re: [Question] Yubikey 4 with Keepass 2 -Dosent work |
ChrisHalos wrote: If using OATH-HOTP, you'll also want to make sure that the "Look-ahead count" is AT MINIMUM 5 (between 5 and 10 seems to work consistently). Maybe you should add this tip to your own guide. I currently use challenge-response mode. Thanks. (Wouldn't be implementing HMAC-SHA256 far more secure?) |
Author: | HDDControler [ Sun Apr 03, 2016 9:33 pm ] |
Post subject: | Re: [Question] Yubikey 4 with Keepass 2 -Dosent work |
Hey Ho thanks to all. I try it just not out but the solution seems to be the Look-Ahead Accound. Thanks for this Information. |
Author: | Tom2 [ Tue Apr 05, 2016 8:48 am ] |
Post subject: | Re: [SOLVED] Yubikey 4 with Keepass 2 -Dosent work |
I recommend using KeeChallenge instead. http://www.kahusecurity.com/2014/securi ... nd-factor/ |
Author: | r00f [ Sun May 22, 2016 11:15 am ] |
Post subject: | Re: [SOLVED] Yubikey 4 with Keepass 2 -Dosent work |
I had the same problem, after many tries never managed to make OTP work with Keepass. As suggested, switched to Keechallenge, works like a charm. |
Page 1 of 1 | All times are UTC + 1 hour |
Powered by phpBB® Forum Software © phpBB Group https://www.phpbb.com/ |