Show HN: YubiKey HMAC-SHA1 support for KeePassX
github.com
github.com
Presumably the secret key used to generate the HMAC never leaves the YubiKey? So when you want to change the seed, you need to ask the YubiKey to sign the new seed? So saving the database requires pushing the button on the YubiKey again?
Every time the KeePass2 database is written, a new master seed is generated[1]. The master seed is stored raw in the header of the KeePass2 database so that it can be read later for decryption.
This pull request is a nutshell submits the master seed as a challenge to the YubiKey which replies with a deterministic response. We then use the response to generate the final key. The final key is the true encryption key and the file is written out. To decrypt[2], we do the same thing, but read the master seed from the header file. Commit that ties everything in to the final key[3].
[1] https://github.com/keepassx/keepassx/blob/master/src/format/... [2] https://github.com/keepassx/keepassx/blob/master/src/format/... [3] https://github.com/kylemanna/keepassx/commit/45d2add8a3037c3...
The only part I trying to confirm was that you issue a challenge to the yubikey at save time, not just at decryption time.
> Instead you can generate and save the 20 byte HMAC secret prior to programming the YubiKey. You could then program an infinite number of other YubiKeys with the same secret. See the screenshot in the PR showing the Yubico GUI tool, note the key field.
The immediate benefit is that KeePassX is that it is cross platform (tested first hand on Linux and OS X) whereas KeePass itself is Windows only (maybe mono?).
keechallenge is also supposed to work w/ mono. That said, at least on my machine the fonts in keepass2 are rendered too small, making the application very difficult to use. I spent about an hour trying to figure out how to fix them and could not, so I have not tried setting up keechallenge there.