Since totp is not phising resitent, we are going to use Yubikeys for admin logons on servers.
We are using the totp mfa for Documents and Secure Gateway.
We wish to use the yubikeys for this also, as an extra layer of security.
Since totp is not phising resitent, we are going to use Yubikeys for admin logons on servers.
We are using the totp mfa for Documents and Secure Gateway.
We wish to use the yubikeys for this also, as an extra layer of security.
Currently, Royal Server supports YubiKeys as MFA factor via Yubico OTP.
FIDO2/WebAuthn is not supported at this time.
However, connections to Royal Server and Secure Gateway are protected by certificate pinning (trust on first use). The first time a client connects, the server’s certificate fingerprint has to be accepted and is stored in Royal TS/X. Every subsequent connection is validated against that stored fingerprint.
If the fingerprint changes, the connection is not established silently — Royal TS/X will show a warning.
As always, an unexpected fingerprint change should be treated as a red flag and verified against the server before it is accepted.
Hi,
We wish to use a phising resistent method of mfa. all OTPs are not secure.
We want to get closer to nis2 and here a phising resistent method is needed.
We are looking into yubikey for this, and have contact to yubico.
We wish to use a yubikey for the mfa, when connecting to Documents/SecureGateway. Certificate pinning does not solve this request.
Hi Thomas,
for the Secure Gateway there’s a hard blocker that isn’t solvable on our side. It’s built on the Rebex SSH library, which doesn’t implement the FIDO2-backed key types ([email protected] and [email protected]). This isn’t a setting we can enable or work around, the key types have to be added by Rebex.
If you’d like to raise a request with Rebex directly, they have a public forum at forum.rebex.net.
Sorry I don’t have better news on this one for now.