Hi, I'm not able to answer (technical issues) to the already existing corresponding emails here, so I'm trying to send this seperately.
There's a quite new Qubes discussion/set-up here – not finished yet?: https://github.com/QubesOS/qubes-issues/issues/3307 https://github.com/QubesOS/qubes-doc/pull/478 I've also been following/studying mig5's proposals here: https://mig5.net/content/yubikey-challenge-response-mode-qubes https://mig5.net/content/yubikey-2fa-qubes-redux-adding-backup-key *Test it with Xscreensaver first in order to not lock you out of the system.* It looks like you have to play around with 'variable input' and 'fixed 64 bytes' in Yubikey personalization tool and sending 63 or 64 bytes in the yubikey-auth script. For me, Qubes 3.2., Fedora 25 sys-usbVM, it may differ for your set-up, mig5's version for now, not mixing up anything from the Qubes proposals worked perfectly, i.e., sending 63 bytes in the auth script, no spaces in the auth script for AES key, 'variable input' in Yubikey programming. *Adjust your new Yubikey settings at the right time for other apps, e.g. KeePassXC where challenge-response is working well.* Best regards. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/p1eaiu%241l5%241%40blaine.gmane.org. For more options, visit https://groups.google.com/d/optout.