<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Nitrokey &#8211; privacyID3A</title>
	<atom:link href="https://www.privacyidea.org/tag/nitrokey/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.privacyidea.org</link>
	<description>flexible, Open Source Multi Factor Authentication (2FA)</description>
	<lastBuildDate>Thu, 06 Oct 2016 07:03:33 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://www.privacyidea.org/wp-content/uploads/2016/06/cropped-only-logo-white-background-32x32.png</url>
	<title>Nitrokey &#8211; privacyID3A</title>
	<link>https://www.privacyidea.org</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>privacyIDEA with Nitrokey support</title>
		<link>https://www.privacyidea.org/privacyidea-with-nitrokey-support/</link>
					<comments>https://www.privacyidea.org/privacyidea-with-nitrokey-support/#respond</comments>
		
		<dc:creator><![CDATA[Cornelius Kölbel]]></dc:creator>
		<pubDate>Thu, 06 Oct 2016 07:03:33 +0000</pubDate>
				<category><![CDATA[release]]></category>
		<category><![CDATA[Whatsup]]></category>
		<category><![CDATA[Benchmark]]></category>
		<category><![CDATA[FreeRADIUS]]></category>
		<category><![CDATA[Nitrokey]]></category>
		<category><![CDATA[Performance]]></category>
		<guid isPermaLink="false">https://www.privacyidea.org/?p=1082</guid>

					<description><![CDATA[privacyIDEA adds Nitrokey OTP support in release 2.15 Today we released privacyIDEA 2.15. In this release privacyIDEA command line client supports the initialization and enrollment of the Nitrokey. The Nitrokey is an open USB devices that acts as authentication device and password safe. It can hold your PGP keys but also provides several OTP slots. [&#8230;]]]></description>
										<content:encoded><![CDATA[<h1>privacyIDEA adds Nitrokey OTP support in release 2.15</h1>
<figure id="attachment_931" aria-describedby="caption-attachment-931" style="width: 300px" class="wp-caption alignright"><a href="https://www.privacyidea.org/wp-content/uploads/2016/05/nitrokey.png"><img fetchpriority="high" decoding="async" class="size-medium wp-image-931" src="https://www.privacyidea.org/wp-content/uploads/2016/05/nitrokey-300x200.png" alt="The open hardware pyhsical authentication device: Nitrokey (source: Nitrokey.com)" width="300" height="200" srcset="https://www.privacyidea.org/wp-content/uploads/2016/05/nitrokey-300x200.png 300w, https://www.privacyidea.org/wp-content/uploads/2016/05/nitrokey-768x513.png 768w, https://www.privacyidea.org/wp-content/uploads/2016/05/nitrokey.png 1024w" sizes="(max-width: 300px) 100vw, 300px" /></a><figcaption id="caption-attachment-931" class="wp-caption-text">The open hardware pyhsical authentication device: Nitrokey (source: Nitrokey.com)</figcaption></figure>
<p>Today we released privacyIDEA 2.15. In this release privacyIDEA command line client supports the initialization and enrollment of the <a href="http://nitrokey.com" target="_blank">Nitrokey</a>. The Nitrokey is an open USB devices that acts as authentication device and password safe. It can hold your PGP keys but also provides several OTP slots. privacyIDEA now can initialize these OTP slots, so that you can use your own key material and use the Nitrokey as an open and trusted authenticator. This way you get the maximum trust and transparency by running open source software, using open and standardized algorithms and open hardware.</p>
<h2>Arbitrary User Attributes and Client Overview</h2>
<p>With privacyIDEA 2.15 the administrator now can edit arbitrary user attributes. These user attributes can be included in the authentication response and the new privacyIDEA FreeRADIUS plugin can map these user attributes to any RADIUS response attribute.</p>
<p>In the Web UI the administrator now also gets an overview of all authenticating clients. This may help him to keep track of the connected applications.</p>
<h2>Download</h2>
<p>You can download privacyIDEA via <a href="https://github.com/privacyidea/privacyidea" target="_blank">github</a>, the <a href="https://pypi.python.org/pypi/privacyIDEA/" target="_blank">python package index</a> or the <a href="https://launchpad.net/~privacyidea/+archive/ubuntu/privacyidea" target="_blank">Ubuntu Launchpad repository</a>. privacyIDEA is also available as <a href="https://netknights.it/en/produkte/privacyidea/">privacyIDEA Enterprise Edition from NetKnights</a> providing additional downloads for CentOS or the Univention Corporate Server.</p>
<h2>Changelog</h2>
<div class="-x-evo-paragraph">  Features</div>
<ul>
<li class="-x-evo-paragraph">Client Overview. Display the type of the requesting   authenticating clients (#489)</li>
<li class="-x-evo-paragraph">Support for NitroKey OTP mode (admin client)</li>
</ul>
<p>Enhancements</p>
<ul>
<li class="-x-evo-paragraph">You can edit arbitrary user attributes in privacyIDEA.</li>
<li class="-x-evo-paragraph">Such user attributes can be mapped to any RADIUS attribute.</li>
<li class="-x-evo-paragraph">Performance enhancements using Caching singletons for Config, Realm, Resolver and Policies</li>
<li class="-x-evo-paragraph">Allow configuration of the registration email text (#494)</li>
<li class="-x-evo-paragraph">Return SAML attributes only in case of successful authentication (#500)</li>
<li class="-x-evo-paragraph">Policy &#8220;reset_all_user_tokens&#8221; allow to reset all  failcounters on successful authentication (#471)</li>
<li class="-x-evo-paragraph">Client rewrite mapping also checks for X-Forwarded-For (#395, #495)</li>
</ul>
<p>Fixes</p>
<ul>
<li class="-x-evo-paragraph">Fixing RemoteUser fails to display WebUI (#499)</li>
<li class="-x-evo-paragraph">String comparison in HOSTS resolver (#484)</li>
</ul>
]]></content:encoded>
					
					<wfw:commentRss>https://www.privacyidea.org/privacyidea-with-nitrokey-support/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Manage Nitrokey with privacyIDEA</title>
		<link>https://www.privacyidea.org/manage-nitrokey-privacyidea/</link>
					<comments>https://www.privacyidea.org/manage-nitrokey-privacyidea/#respond</comments>
		
		<dc:creator><![CDATA[Cornelius Kölbel]]></dc:creator>
		<pubDate>Tue, 06 Sep 2016 08:32:03 +0000</pubDate>
				<category><![CDATA[Howto]]></category>
		<category><![CDATA[Whatsup]]></category>
		<category><![CDATA[Command Line Client]]></category>
		<category><![CDATA[key management]]></category>
		<category><![CDATA[mass enrollment]]></category>
		<category><![CDATA[Nitrokey]]></category>
		<guid isPermaLink="false">https://www.privacyidea.org/?p=1026</guid>

					<description><![CDATA[Maximum Transparancy &#8211; Maximum Trust Look at my Nitrokeys. The pre-release of the Nitrokey Pro, the Nitrokey Storage and Nitrokey HSM. The Nitrokey is a crypto device, which you can use to store your PGP Keys or just RSA keys and thus sign and decrypt data. It comes with a password safe and the ability [&#8230;]]]></description>
										<content:encoded><![CDATA[<h2>Maximum Transparancy &#8211; Maximum Trust</h2>
<p><a href="https://www.privacyidea.org/wp-content/uploads/2016/09/Nitrokeys.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-1027 aligncenter" src="https://www.privacyidea.org/wp-content/uploads/2016/09/Nitrokeys-300x237.jpg" alt="Nitrokeys" width="300" height="237" srcset="https://www.privacyidea.org/wp-content/uploads/2016/09/Nitrokeys-300x237.jpg 300w, https://www.privacyidea.org/wp-content/uploads/2016/09/Nitrokeys-768x607.jpg 768w, https://www.privacyidea.org/wp-content/uploads/2016/09/Nitrokeys.jpg 1000w" sizes="auto, (max-width: 300px) 100vw, 300px" /></a></p>
<p>Look at my Nitrokeys. The pre-release of the Nitrokey Pro, the Nitrokey Storage and Nitrokey HSM. The <a href="http://nitrokey.com" target="_blank">Nitrokey</a> is a crypto device, which you can use to store your PGP Keys or just RSA keys and thus sign and decrypt data. It comes with a password safe and the ability to generate one time passwords. It is open hardware and all necessary software is open source. Thus it is a great device to be combined with the open source authentication system privacyIDEA.</p>
<h3>Nitrokey managed by privacyIDEA</h3>
<p>You can manage your keys locally on your desktop with the <a href="https://github.com/nitrokey/nitrokey-app" target="_blank">Nitrokey-App</a>. You can reset the user PIN and the administrator PIN (SO PIN). And you can manage the passwords in your password safe.</p>
<p><a href="https://www.privacyidea.org/wp-content/uploads/2016/09/nitrokey-app.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-1029 aligncenter" src="https://www.privacyidea.org/wp-content/uploads/2016/09/nitrokey-app-300x111.jpg" alt="nitrokey-app" width="300" height="111" srcset="https://www.privacyidea.org/wp-content/uploads/2016/09/nitrokey-app-300x111.jpg 300w, https://www.privacyidea.org/wp-content/uploads/2016/09/nitrokey-app.jpg 426w" sizes="auto, (max-width: 300px) 100vw, 300px" /></a></p>
<p>But you can not use the OTP functionality as you need a backend or an application to authenticate against. The idea to manage the <a href="https://github.com/privacyidea/privacyidea/issues/3" target="_blank">Nitrokey with privacyIDEA was around for a while</a>. Issues have been filed to the privacyIDEA github project and the <a href="https://github.com/privacyidea/privacyideaadm/issues/27" target="_blank">privacyIDEA command line client</a>. Managing the OTPs of the Nitrokey seemed to be a logical first step.</p>
<p>Just yesterday <a href="https://github.com/privacyidea/privacyideaadm/commit/1d840ae834f1c59da7b01421c5280f28d2b94f96" target="_blank">I pushed the code</a> to the <a href="https://github.com/privacyidea/privacyideaadm/" target="_blank">github repository of the privacyIDEA command line client</a>. The good news is, that there are no changes in the privacyIDEA backend necessary. The Nitrokey acts as an HOTP or TOTP token &#8211; both token types are already supported by privacyIDEA. The command line client takes care of initializing the Nitrokey and creates the token object in the privacyIDEA backend.</p>
<h3>privacyIDEA and hardware tokens</h3>
<p>privacyIDEA already supports several hardware tokens, which can be seeded: like the Yubikey, U2F devices, eToken NG or daplug token. Most of these tokens (except U2F) are initialized via the command line client. The great thing with the command line client is, that the tokens like the Yubikeys can be <a href="https://www.privacyidea.org/privacyidea-admin-client-for-yubikey-mass-enrollment/">mass enrolled</a>. This way the administrator can initialize hundrets of tokens in a few minutes and initialize these with new key material &#8211; being independent of the vendor.</p>
<p>With the Nitrokey you can do this, too. But you also get a bonus. You are indepent with your key material of any vendor <strong>and</strong> you get a hardware, that is <strong>open</strong>, where you can simply run your audits on it.</p>
<h3>Enroll a Nitrokey HOTP token</h3>
<p>To be able to enroll the Nitrokey you need to get and install the <a href="https://github.com/nitrokey/nitrokey-app" target="_blank">Nitrokey-App</a> and <a href="https://github.com/nitrokey/libnitrokey" target="_blank">libnitrokey</a>. The privacyIDEA admin client uses libnitrokey to initialize the OTP slot. The Nitrokey support in the privacyIDEA admin client is totally new. It is not contained in the <a href="https://launchpad.net/~privacyidea" target="_blank">packages of the privacyIDEA admin client</a>, yet. So you also need to get the <a href="https://github.com/privacyidea/privacyideaadm" target="_blank">github repository</a> and install the privacyIDEA admin client via</p>
<pre>  python setup.py install</pre>
<p>Now you can enroll Nitrokeys:</p>
<pre>  privacyidea -U https://localhost --admin super --nosslcheck token nitrokey_mass_enroll --slotname meiner0 --slot 0</pre>
<p>The new command option <strong>nitrokey_mass_enroll</strong> will start the mass enrollment process for Nitrokeys. This will only work if all Nitrokeys have the same admin PIN. At the moment the admin PIN is requested during startup and not for each enrolled Nitrokey.</p>
<p>You can specify which <strong>slot</strong> should be written. There are 3 HOTP slots, so this value can be 0 &#8211; 2. You can also set a <strong>slotname</strong> for this slot.</p>
<p>The admin client will ask you for the next Nitrokey to be inserted. This way you can initialize OTP slots of many Nitrokeys and then give these keys to your users.</p>
<p>The great thing is, the admin client will read the serial number of each Nitrokey during the rollout process. It then create an HOTP token object in the privacyIDEA backend with the token serial <em>NK&lt;serial&gt;_&lt;slotnumber&gt;.</em> This way you can easily identify devices.</p>
<h3>Maximum trust</h3>
<p>privacyIDEA once more improves the level of trust by supporting the open hardware Nitrokey. Get transparent software and transparent hardware to boost trust to the max.</p>
<p>&nbsp;</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.privacyidea.org/manage-nitrokey-privacyidea/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>privacyIDEA 2.12 is delayed &#8211; Event Handling Framework</title>
		<link>https://www.privacyidea.org/privacyidea-2-12-delayed-event-handling-framework/</link>
					<comments>https://www.privacyidea.org/privacyidea-2-12-delayed-event-handling-framework/#comments</comments>
		
		<dc:creator><![CDATA[Cornelius Kölbel]]></dc:creator>
		<pubDate>Fri, 06 May 2016 06:35:02 +0000</pubDate>
				<category><![CDATA[release]]></category>
		<category><![CDATA[Whatsup]]></category>
		<category><![CDATA[Event Handler]]></category>
		<category><![CDATA[Nitrokey]]></category>
		<guid isPermaLink="false">https://www.privacyidea.org/?p=929</guid>

					<description><![CDATA[As you might have realized we planned privacyIDEA Release 2.12 for these days. But due to several reasons it is delayed. We found a nasty bug this week, which required our attention. Support for Nitrokey We are talking a lot to Nitrokey, since it is a great idea to combine transparent, open source authentication software with [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>As you might have realized we <a href="https://github.com/privacyidea/privacyidea/milestones" target="_blank">planned privacyIDEA Release 2.12 for these days</a>. But due to several reasons it is delayed.</p>
<p>We found a <a href="https://www.privacyidea.org/bug-passonnouser-policy-allows-arbitrary-authentication/">nasty bug this week</a>, which required our attention.</p>
<h2>Support for Nitrokey</h2>
<figure id="attachment_931" aria-describedby="caption-attachment-931" style="width: 201px" class="wp-caption alignright"><a href="https://www.privacyidea.org/wp-content/uploads/2016/05/nitrokey.png"><img loading="lazy" decoding="async" class="wp-image-931" src="https://www.privacyidea.org/wp-content/uploads/2016/05/nitrokey-300x200.png" alt="The open hardware pyhsical authentication device: Nitrokey (source: Nitrokey.com)" width="201" height="134" srcset="https://www.privacyidea.org/wp-content/uploads/2016/05/nitrokey-300x200.png 300w, https://www.privacyidea.org/wp-content/uploads/2016/05/nitrokey-768x513.png 768w, https://www.privacyidea.org/wp-content/uploads/2016/05/nitrokey.png 1024w" sizes="auto, (max-width: 201px) 100vw, 201px" /></a><figcaption id="caption-attachment-931" class="wp-caption-text">The open hardware pyhsical authentication device: Nitrokey (source: Nitrokey.com)</figcaption></figure>
<p>We are talking a lot to <a href="https://www.nitrokey.com/" target="_blank">Nitrokey</a>, since it is a great idea to combine transparent, open source authentication software with open authentication hardware like the <a href="https://shop.nitrokey.com/shop/product/nitrokey-pro-3" target="_blank">Nitrokey Pro</a>. As you can <a href="https://github.com/privacyidea/privacyidea/issues/3" target="_blank">see in the ticket</a>, this idea is around for quite a while. But to do an easy enrollment we need some high level function in the just upcoming <a href="https://github.com/Nitrokey/libnitrokey" target="_blank">libnitrokey</a>. This is not as straightforward as wished. If you are an experienced C/C++ and Python programmer, you are welcome to <a href="https://www.privacyidea.org/contact/">contact me</a> and assist!</p>
<p>Finally a simple feature request which we decided to put into 2.12 turned out to be an interesting concept, when designing and implementing it in a flexible way.</p>
<h2>Event Handling Framework</h2>
<p>We could <a href="https://github.com/privacyidea/privacyidea/issues/360" target="_blank">send an email to a user, if an administrator modified his token</a>. But which modifications, how and why? Thinking about it resulted in a more flexible concept, of an <a href="https://github.com/privacyidea/privacyidea/wiki/concept%3A-event-handling" target="_blank">event handling framework</a>, where you can define rule, which should happen in which occasion under which condition. Different event handler module will be able to enhance the possible actions in response to events.</p>
<p>Finally we have done the database model and are just working on the base class and the decorator. We will come up with the user notification on modified user tokens.</p>
<p>But therefor we need to push the release data accordingly.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.privacyidea.org/privacyidea-2-12-delayed-event-handling-framework/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
	</channel>
</rss>
