<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>client management &#8211; privacyID3A</title>
	<atom:link href="https://www.privacyidea.org/tag/client-management/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.privacyidea.org</link>
	<description>flexible, Open Source Multi Factor Authentication (2FA)</description>
	<lastBuildDate>Mon, 30 Jun 2014 07:42:48 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://www.privacyidea.org/wp-content/uploads/2016/06/cropped-only-logo-white-background-32x32.png</url>
	<title>client management &#8211; privacyID3A</title>
	<link>https://www.privacyidea.org</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Client and Key Managemet</title>
		<link>https://www.privacyidea.org/client-and-key-managemet/</link>
					<comments>https://www.privacyidea.org/client-and-key-managemet/#respond</comments>
		
		<dc:creator><![CDATA[Cornelius Kölbel]]></dc:creator>
		<pubDate>Mon, 30 Jun 2014 07:37:38 +0000</pubDate>
				<category><![CDATA[Whatsup]]></category>
		<category><![CDATA[client management]]></category>
		<category><![CDATA[key management]]></category>
		<guid isPermaLink="false">https://www.privacyidea.org/?p=218</guid>

					<description><![CDATA[A new idea is born. It started  with a paper I wrote about using LinOTP &#8211; the ancestor of privacyIDEA &#8211; as a mangement system for Yubikey in challenge response that would be used in conjunction with LUKS. The tool to use the Yubikey to protect the encrypted Linux harddisk can be found here at [&#8230;]]]></description>
										<content:encoded><![CDATA[<figure id="attachment_220" aria-describedby="caption-attachment-220" style="width: 168px" class="wp-caption alignleft"><a href="https://www.privacyidea.org/wp-content/uploads/2014/06/keychain-212883_1280.jpg"><img fetchpriority="high" decoding="async" class="wp-image-220 size-medium" src="https://www.privacyidea.org/wp-content/uploads/2014/06/keychain-212883_1280-168x300.jpg" alt="keychain-212883_1280" width="168" height="300" srcset="https://www.privacyidea.org/wp-content/uploads/2014/06/keychain-212883_1280-168x300.jpg 168w, https://www.privacyidea.org/wp-content/uploads/2014/06/keychain-212883_1280-576x1024.jpg 576w, https://www.privacyidea.org/wp-content/uploads/2014/06/keychain-212883_1280.jpg 720w" sizes="(max-width: 168px) 100vw, 168px" /></a><figcaption id="caption-attachment-220" class="wp-caption-text">Keychain, GARU @ pixabay</figcaption></figure>
<p>A new idea is born. It started  with a paper I wrote about using LinOTP &#8211; the ancestor of privacyIDEA &#8211; as a mangement system for Yubikey in challenge response that would be used in conjunction with LUKS. The tool to use the Yubikey to protect the encrypted Linux harddisk can be found <a href="https://github.com/cornelinux/yubikey-luks" target="_blank">here at github</a>. The paper was published at the <a href="http://www.qucosa.de/fileadmin/data/qucosa/documents/13349/linux_2014.pdf" target="_blank">Chemnitzer Linuxtage 2014</a> (German! p. 19).</p>
<p>The idea is to enroll Yubikeys with privacyIDEA and manage the knowledge which yubikey is used to boot which machine. Booting the machine is no usual authentication request issued against the authentication server privacyIDEA. It is handled completely on the client machine. But the central management system (privacyIDEA) would know, which yubikey is allowed to to which client.</p>
<p>Why not generalize this idea? Thus we can have a system that knows which authentication device can be used for which application on which client machine. Being it Yubikey tokens, HMAC tokens, simple passwords or not-yet-existing SSH keys&#8230;</p>
<p>The concept is developed in the <a href="https://github.com/privacyidea/privacyidea/wiki/concept:-machines-or-remote.app" target="_blank">github wiki</a> &#8220;Conecpt for machines and remote applications&#8221;. Feel free to ask questions, nag, contribute!</p>
<p>&nbsp;</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.privacyidea.org/client-and-key-managemet/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
