Replies: 2 comments 11 replies
-
I'm not sure how any self-hosted/alternative yubikey/yubico OTP Server works. You might need to point to the correct verify endpoint for this to work, as you need to provide the full path to the verify URL. |
Beta Was this translation helpful? Give feedback.
-
Hey BlackDex, The Request seems to be ok, in this code line the error occurs: This is the validation algoritm: Can you please take a look to the class, to verify if the validation/signature has any differents on your site? |
Beta Was this translation helpful? Give feedback.
-
Here's the English translation of the provided text:
Hello community, I'm experiencing an issue with Vaultwarden and Yubikey.
We have our own Yubikey authentication server, and my requests are reaching it, but with a BAD_SIGNATURE error.
We've discovered that in the Yubico Validation Protocol Version 2, a signature of the actual request is included in the H parameter.
This is required for authentication. Apparently, Vaultwarden is not sending this signature, causing the server to reject the request.
Has anyone encountered this problem before, or is there perhaps something I need to configure on my end?
I've set the Yubikey variable in the Docker Compose file and also configured it in the admin interface.
Yubikey Settings
I hope anyone here can help me.
Thanks,
Kind regards,
David
Beta Was this translation helpful? Give feedback.
All reactions