I have one Yubikey which works fine with KeeChallenge. If I program another Yubikey using the same Secret Key, will it open my original KeePass database without having to use recovery mode or update anyting in Keepass? In other words, can just duplicate hardware (Yubikey) without any software changes? On a related note... If I forget my Secret Key, but have working Yubikey programmed with that Secret Key, I will be able to open a copy of the original database on a new PC. Correct?
I have one Yubikey which works fine with KeeChallenge. If I program another Yubikey using the same Secret Key, will it open my original KeePass database without having to use recovery mode or update anyting in Keepass? In other words, can just duplicate hardware (Yubikey) without any software changes?
I am having the same issue: there is no Recovery Mode option or button when using with portable KeePass-2.43 for Windows. Otherwise, works well, thank you for good product!
I am having the same issue: there is no Recovery Mode option or button when using with portable KeePass-2.43. Otherwise, works well, thank you for good product!
deleted
I'm not a cryptography-expert. However, I'd like to understand why the KeeChallenge approach is safe. HMAC is usually used to verify authentication and data integrity of a message where sender and receiver are required to hold a shared secret. If I understand it correctly, KeyChallenge uses the HMAC as the AES key to en/decrypt the shared secret (stored in XML file). The challenge is used as some kind of salt mechanism. Thus: R = AESenc(S, HMAC(S, C)) S = AESdec(R, HMAC(S, C)) where: - S is the shared...
I'm not a cryptography-expert. However, I'd like to understand why the KeeChallenge approach is safe. HMAC is usually used to verify authentication and data integrity of a message where sender and receiver are required to hold a shared secret. If I understand it correctly, KeyChallenge uses the HMAC as the AES key to en/decrypt the shared secret (stored in XML file). The challenge is used as some kind of salt mechanism. Thus: R = AESenc(S, HMAC(S, C)) S = AESdec(R, HMAC(S, C)) where: - S is the shared...
I'm not a cryptography-expert. However, I'd like to understand why the KeeChallenge approach is safe. HMAC is usually used to verify authentication and data integrity of a message where sender and receiver are required to hold a shared secret. If I understand it correctly, KeyChallenge uses the HMAC as the AES key to en/decrypt the shared secret (stored in XML file). The challenge is used as some kind of salt mechanism. Thus: R = AESenc(S, HMAC(S, C)) S = AESdec(R, HMAC(S, C)) where: - S is the shared...
Hello, is there any update ? i have a HyperFIDO too.
I get an error that KeeChallenge.dll is not compatabile with keepass. I replaced...
I setup Keepass 2.4 with Yubikey challenge-response. I backed up my Keepass database...
Updated to v1.5
Thank you. It is good that you keep the plugin updated.
Marek, sorry to take so long to get back to you on this. I've had limited time to...
Sorry for taking so long to respond, I've had limited time to dedicate to this project...
Sorry for the delay on this, I had some personal things that have limited my ability...
Avitus, Sorry for taking so long on this! I have had some personal things going on...
Hello, is there a way to add more then one yubikey fot challenge response? Thx.
(To the best of my understanding.) U2F/Fido has a very different use-case from what...
(To the best of my understanding.) U2F/Fido has a very different use-case from what...
I own a HyperFIDO-Security Token from HYPERSECU. This works perfect with Chrome and...
it does since late 2015
it does now
I own a HyperFIDO-Security Token from HYPERSECU. This works perfect with Chrome and...
Hi Ben. Been using KeeChallenge for quite a while now. And the Android/NFC version...
ok i think i found the problem. everything works fine if i start keepass2 as root....
error connecting to yubikey on linuxmint
Hi, Keechallange works fine for me with one yubikey. But I don´t find the switch...
Hello, thank you for great plugin! There is some situation during recovery missing...
Hi, Can you have a look on some files in attachment (svg images) ? I have tried to...
Hi, Can you have a look on some files in attachment (svg images) ? I have tried to...
I just checked the sources and it seemes to me, that the second slot is challenged...
I just checked the sources and it seemes to me, that the second slot is challenged...
I'm facing the same (or similar) problem when creating a new keyring. KeePass asks...
Basil, sorry for letting this go for so long. I haven't seen this error before. Can...
Any update on this? Thanks, Basil On Thu, Jul 23, 2015 at 10:16 PM, Basil Yokarinis...
Yes, please find it attached. Is it the right file? On Wed, Jul 22, 2015 at 11:52...
KeeChallenge uses an XML sidecar file to store the next challenge for Yubikey and...
Undefined error with Yubikey Neo on Ubuntu
Win 7, KeePass 2.29, KeeChallenge 1.4, YubiKey neo 3.2
Robert, I did see your message and just responded this morning. I'd welcome the contributions...
I can sympathize with you on this one. I've found myself without my yubikey multiple...
Added support for variable length challenges
Ben, (I sent you a message via SourceForge, but this site has no way to see them...
FYI, I'm running Ubuntu 14.04 and Mono 3.2.8 and the text in the instructions for...
I got it! After review your code and trying the plugin at an other computer (also...
Error getting response from yubikey
I love the idea of this plug in but don't like the security hole that is present...
The biggest problem I'm having is lack of documentation. The only official description...
I'm also running into the same problem. The plugin works perfect with fixed length....
I'm not actually using the PAM module; I also looked through the code! Like you,...
I just dug into the source for the PAM module since I was curious to see if yubico...
You make a very good point that HMAC challenges usually involve the secret being...
You make a very good point that HMAC challenges usually involve the secret being...
FYI these are now at the top of the README, which you can view online from the "Files"...
Your point is well taken, and I definitely sympathize. Here's my thought process...
No problem, I should have done this sooner. I'll put them up momentarily
Hi Ben. Thanks for your work on this plug-in. Would it be possible for you to provide...
Thanks for developing KeeChallenge and for your post. It certainly didn't come across...
Guy, I originally shared a lot of your concerns when developing the keechallenge....
From your description of KeeChallenge at http://forum.yubico.com/viewtopic.php?f=8&t=1337?...
Ben, you've done an amazing job of looking into this problem even over the Christmas...
Dear All, Ben (the developer) has done an amazing job of looking into this problem...
1.3 works well, thank you!
Glad to hear you got the YubiKey! Just loaded up 1.3 with the updated libs in Windows8...
Debian / linux wine compatibility
Help please.
This ticket appears to be the same problem as ticket #12. Please try the new version...
-Updated assembly version
I got the yubikey yesterday and have been working to resolve this. I'm having difficulty...
Guys, just a status update at this point. I'm aware that there's a problem here,...
Hi guys, I'm having the same problem as Mike, specifically trying to use OTP+U2F....
Hi guys, I'm having the same problem as Mike, specifically trying to use OTP+U2F....
Also, the U2F functionality works on the desktop with no problem.
windows 7 not recognizing my yubikey
May be answering my own question... U2F doesn't support NFC (yet).
Since U2F is specifically designed for just such a task (KeeChallenge), what's the...
I did try this, however I'm still not able to get KeePass to connect in either OTP+U2F...
I did try this, however I'm still not able to get KeePass to connect in either OTP+U2F...
I did try this, however I'm still not able to get KeePass to connect in either OTP+U2F...
I seem to have fixed it. Nevermind -- If you have this error: I deleted the whole...
Help please.
Matt, keechallenge definitely works under debian via mono. With mono installed, you...
Bart, the verification is the cryptographic hash of the shared secret. This is used...
That did the trick, thanks a lot mate.
As I also just posted under Discussions, what ended up solving the problem for me...
Hi niceuser, I have been experiencing the same problem, I believe, though I did not...
Error connecting to YubiKey being in new combined mode OTP+CCID+U2F
Hello, Yubico has just started to support all three modes simultaneously (OTP+U2F+CCID)...
Hi Ben, thanks for this nice plugin, it works fine (after some fiddling) on Ubuntu...
Debian / linux wine compatibility
Thanks Markku, I just merged this change into the master. This is great work and...
Thanks, this is very interesting. I would love to help you build the yubico libraries,...
HI, Finally I had the time to look in to this issue. First I was like "What dll.config?",...
Updated Assembly Version
Recovery mode