Yubico Forum

...visit our web-store at store.yubico.com
It is currently Tue Jan 30, 2018 1:04 pm

All times are UTC + 1 hour




Post new topic Reply to topic  [ 3 posts ] 
Author Message
PostPosted: Thu Oct 24, 2013 6:24 pm 
Offline

Joined: Thu Oct 24, 2013 4:20 pm
Posts: 2
I´m currently using Password Safe version V3.32.
In order to improve security I decided to use Password Safe with Yubikeys Challenge-Response based on HMAC-SHA1.
So I purchased Yubikey Firmware Version 2.4.1 preconfigured for Password Safe.
I followed the installation described by yubico: http://www.yubico.com/applications/password-management/consumer/password-safe/
Configuring an existing database for use with Yubikey was easy and works fine - every time I open the database I´m asked to press the Yubikey.

But: Without plugged in Yubikey no addl. auth-factor is required to open the database!
If no Yubikey is plugged, no Yubikey input field is displayed in the logon menue.
Everybody who knowns my master password has access to my secrets.
This renders the use of a Yubikey useless in my opinion.


Can someone confirm this behavior or give me hint, if I might have a mistake in the configuration?
Thanks a lot.


Top
 Profile  
Reply with quote  

Share On:

Share on Facebook FacebookShare on Twitter TwitterShare on Tumblr TumblrShare on Google+ Google+

PostPosted: Fri Oct 25, 2013 9:56 am 
Offline

Joined: Fri Oct 25, 2013 9:29 am
Posts: 2
Hi,

My config is quite similar to yours. I run passwordsafe V 3.32 (German) on an Acer 5670. OS is Win XP full up-to-date. My yubikey - preconf. as "Yubikey for passwordsafe" - is FWV 2.4.2 I had a working passwordsafe before I got Yubikey. Now, what did I do when I received my Yubikey:

Following the instruction on the webpage you cited I jumped directly to "Installing & Configuring Password Safe for YubiKey" / ref 4. "If you already have an existing database....." I followed the instrucions and the Yubikey worked fine.

Now - after reading your post - I tried to open my passwordsafe in the manner you described. I can not confirm your finding My safe keeps shut with PW only and unplugged Yubikey.

BTW Did you configure Passwordsafe/Yubikey? --> menue "Verwalten" --> Yubikey?

Greetings
pepe


Top
 Profile  
Reply with quote  
PostPosted: Fri Oct 25, 2013 11:32 am 
Offline

Joined: Thu Oct 24, 2013 4:20 pm
Posts: 2
Thanks for your reply. I found what was wrong.
I made the same mistake as described in this link http://sourceforge.net/p/passwordsafe/support-requests/372/.

I assume many users will make this mistake, its easy if you know:
You need to click on the YubiKey button on the screen <<< NOT on the Input-field >>> and then touch your YubiKey to access the database.


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 3 posts ] 

All times are UTC + 1 hour


Who is online

Users browsing this forum: No registered users and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
Powered by phpBB® Forum Software © phpBB Group