<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>yubik &#8211; privacyID3A</title>
	<atom:link href="https://www.privacyidea.org/tag/yubik/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.privacyidea.org</link>
	<description>flexible, Open Source Multi Factor Authentication (2FA)</description>
	<lastBuildDate>Tue, 20 Dec 2022 07:49:16 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://www.privacyidea.org/wp-content/uploads/2016/06/cropped-only-logo-white-background-32x32.png</url>
	<title>yubik &#8211; privacyID3A</title>
	<link>https://www.privacyidea.org</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>privacyIDEA 3.8 released</title>
		<link>https://www.privacyidea.org/privacyidea-3-8-released/</link>
		
		<dc:creator><![CDATA[Cornelius Kölbel]]></dc:creator>
		<pubDate>Tue, 20 Dec 2022 07:49:14 +0000</pubDate>
				<category><![CDATA[release]]></category>
		<category><![CDATA[Whatsup]]></category>
		<category><![CDATA[certificate]]></category>
		<category><![CDATA[yubik]]></category>
		<guid isPermaLink="false">https://www.privacyidea.org/?p=2318</guid>

					<description><![CDATA[With privacyIDEA 3.8 you can use the Yubikey for Smartcard domain Login. 
A generic token enrollment at any application without the need for the user to go to the selfservice portal.]]></description>
										<content:encoded><![CDATA[
<p><strong>Transparent Rollout and Smartcard Login</strong></p>



<figure class="wp-block-image size-large"><a href="https://www.privacyidea.org/wp-content/uploads/2022/12/privacyIDEA_3.8.jpg"><img fetchpriority="high" decoding="async" width="1024" height="683" src="https://www.privacyidea.org/wp-content/uploads/2022/12/privacyIDEA_3.8-1024x683.jpg" alt="" class="wp-image-2319" srcset="https://www.privacyidea.org/wp-content/uploads/2022/12/privacyIDEA_3.8-1024x683.jpg 1024w, https://www.privacyidea.org/wp-content/uploads/2022/12/privacyIDEA_3.8-300x200.jpg 300w, https://www.privacyidea.org/wp-content/uploads/2022/12/privacyIDEA_3.8-768x512.jpg 768w, https://www.privacyidea.org/wp-content/uploads/2022/12/privacyIDEA_3.8.jpg 1200w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>



<p><em>We are happy to inform you, that we released privacyIDEA 3.8 today. 3.8 is an important milestone, since we start to support the Yubikey as a smartcard, that can also be used to login to Windows domains.</em></p>



<h2 class="wp-block-heading">Support for smartcard login on Windows systems</h2>



<p>privacyIDEA 3.8 can manage the Yubikey as a smartcard that holds a smartcard logon certificate. To obtain the smartcard logon certificate, the privacyIDEA server has a new certificate connector to communicate to all Microsoft Active Directory Certiticate Services in the connected Windows domain.</p>



<p>Thus the certificate on the Yubikey can directly be obtained from the Micrsoft CA but be managed within privacyIDEA.</p>



<h2 class="wp-block-heading">Rollout during authentication</h2>



<p>privacyIDEA supports Multi-Challenge-Response for a while. This mechanism can be used to reset an OTP PIN or authenticate with 4-eyes tokens or index-secret tokens. </p>



<p>In version 3.8 this same mechanism can now be used to enroll a token during authentication. The administrator can define a policy, which token type should be enrolled by the user. In several challenge-response steps thus the user can enroll HOTP, TOTP, email, SMS or PUSH tokens. Email and SMS tokens can even be enrolled in standard applications like the Netscaler.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><a href="https://www.privacyidea.org/wp-content/uploads/2022/12/privacyIDEA-SMS-Enrollment-via-Citrix.png"><img decoding="async" width="663" height="358" src="https://www.privacyidea.org/wp-content/uploads/2022/12/privacyIDEA-SMS-Enrollment-via-Citrix.png" alt="" class="wp-image-2320" srcset="https://www.privacyidea.org/wp-content/uploads/2022/12/privacyIDEA-SMS-Enrollment-via-Citrix.png 663w, https://www.privacyidea.org/wp-content/uploads/2022/12/privacyIDEA-SMS-Enrollment-via-Citrix-300x162.png 300w" sizes="(max-width: 663px) 100vw, 663px" /></a><figcaption>SMS token enrollment during the login to Citrix ADC</figcaption></figure></div>



<p>HOTP, TOTP and PUSH enrollment require the application to display a QR code. This mechanism will be supported by all privacyIDEA plugins for e.g. Keycloak, simpleSAMLphp or ADFS.</p>



<h2 class="wp-block-heading">Fast login, fast debugging, token groups</h2>



<p>Using a new &#8220;preferred client mode&#8221; the administrator can define, which should be the preferred way for a user to authenticate, in case the user has more than one token type.</p>



<p>The audit log has been greatly improved for bug tracking. It now also records the thread ID of an API request.<br>Since the threat ID is also contained in the debug log file, this is a great handle to find the relevant detailed information to a specific request in the logs.</p>



<p>privacyIDEA 3.8 comes with the new conecpt of &#8220;token groups&#8221;. We plan to use this to improve SSH key management and the management of offline tokens.</p>



<p>For more details see the <a href="https://github.com/privacyidea/privacyidea/blob/master/Changelog" target="_blank" rel="noreferrer noopener">changelog at Github</a>.</p>



<h2 class="wp-block-heading">Install or Update</h2>



<p>You can download and update privacyIDEA 3.8 via the community repositories for <a href="https://privacyidea.readthedocs.io/en/master/installation/ubuntu.html" target="_blank" rel="noreferrer noopener">Ubuntu 18.04, 20.04 and now also 22.04 or via the python package index</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
