Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Discuss
  3. Yubikey to secure servers.. has anyone tried it?

Yubikey to secure servers.. has anyone tried it?

Scheduled Pinned Locked Moved Discuss
34 Posts 6 Posters 6.3k Views 7 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • humptydumptyH humptydumpty

    @fbartels I came across this Yubico page that lists which keys work with Bitwarden (includes the legacy keys) https://www.yubico.com/works-with-yubikey/catalog/bitwarden-premium/

    fbartelsF Offline
    fbartelsF Offline
    fbartels
    App Dev
    wrote on last edited by fbartels
    #11

    @humptydumpty yes, I know them. the one I previously had is 9+ years old. I don't remember the details but some certificate on my stick was expired and therefore the setup with vaultwarden never worked. I wanted to upgrade to a stick that supports fido 2.0 for quite a while and the Cloudflare promotion was too good to miss.

    humptydumptyH 1 Reply Last reply
    2
    • BrutalBirdieB BrutalBirdie

      @humptydumpty

      https://media.giphy.com/media/SX5y0h1Dh5BQVOBwNo/giphy.gif

      Thanks! Will order some πŸ˜„

      humptydumptyH Offline
      humptydumptyH Offline
      humptydumpty
      wrote on last edited by
      #12

      @BrutalBirdie Thank @fbartels . We owe him a beer now.

      BrutalBirdieB 1 Reply Last reply
      2
      • fbartelsF fbartels

        @humptydumpty yes, I know them. the one I previously had is 9+ years old. I don't remember the details but some certificate on my stick was expired and therefore the setup with vaultwarden never worked. I wanted to upgrade to a stick that supports fido 2.0 for quite a while and the Cloudflare promotion was too good to miss.

        humptydumptyH Offline
        humptydumptyH Offline
        humptydumpty
        wrote on last edited by
        #13

        @fbartels said in Yubikey to secure servers.. has anyone tried it?:

        I wanted to upgrade to a stick that supports fido 2.0 for quite a while

        I hear you. I looked into Yubikeys many times but the cost ramped up quickly since it's best if you have a backup key and with a handful of family members, the bill wasn't easy to swallow. This deal makes it possible. I wish they made a nano NFC version though. I could have it hidden inside a custom made wearable like a pendant, bracelet, or even toss it inside a watch.

        1 Reply Last reply
        1
        • humptydumptyH humptydumpty

          @jdaviescoates It seems you need to have an active zone or use zero trust.

          Exclusive 'good for the Internet' pricing on security keys
          
          Cloudflare has partnered with Yubico to offer hardware authentication security keys at a promotional price to eligible Cloudflare customers. Select "Claim my offer" and Yubico will email the offer to the email address associated with your account if you are eligible. Eligible customers must have an active zone or actively use Cloudflare Zero Trust. You may not claim this offer multiple times from the same email and this offer may be restricted to one email per account. Cloudflare may modify, limit, or discontinue this promotion at any time. Offer is subject to Yubico's terms.
          
          Learn more about how Cloudflare Zero Trust makes it easy to activate and authenticate using your hardware security keys with any identity provider for more secure access to any self-hosted or SaaS application.
          
          By clicking "Claim my offer", you consent to Cloudflare sharing your email address with Yubico AB, Yubico GmbH, Yubico Inc. and Yubico Canada Inc. ("Yubico") solely for the purpose of you claiming this promotion from Yubico. Review the Yubico Privacy Notice to learn more.
          
          jdaviescoatesJ Offline
          jdaviescoatesJ Offline
          jdaviescoates
          wrote on last edited by
          #14

          @humptydumpty said in Yubikey to secure servers.. has anyone tried it?:

          @jdaviescoates It seems you need to have an active zone or use zero trust.

          thanks for the heads up, I guess I had better set something up then... hopefully I'm not too late (probably should've read that and done it before clicking on the claim offer button!)

          I use Cloudron with Gandi & Hetzner

          1 Reply Last reply
          0
          • humptydumptyH humptydumpty

            I found the original Cloudflare blog post about this collab and the direct link is:

            https://dash.cloudflare.com/?to=/:account/yubico-promotion

            Either create an account or log in and that link will take you to the button to claim the offer.

            timconsidineT Offline
            timconsidineT Offline
            timconsidine
            App Dev
            wrote on last edited by timconsidine
            #15

            @humptydumpty do I understand correctly that in order to use Cloudflare on a domain, they have to be registrar for it, i.e. transfer the domain to them?

            I am my own Nominet registrar, so if the above is true, I cannot use Cloudflare on domains currently with Nominet.

            EDIT : should have looked a bit further.
            They don't support registering .UK domains so the above cannot be true.
            Doh !
            Ignore me.

            robiR BrutalBirdieB 2 Replies Last reply
            0
            • timconsidineT timconsidine

              @humptydumpty do I understand correctly that in order to use Cloudflare on a domain, they have to be registrar for it, i.e. transfer the domain to them?

              I am my own Nominet registrar, so if the above is true, I cannot use Cloudflare on domains currently with Nominet.

              EDIT : should have looked a bit further.
              They don't support registering .UK domains so the above cannot be true.
              Doh !
              Ignore me.

              robiR Offline
              robiR Offline
              robi
              wrote on last edited by
              #16

              @timconsidine Yes πŸ˜‰

              They started fronting/protecting domains before they became a registrar which is very recent.

              Conscious tech

              1 Reply Last reply
              1
              • humptydumptyH humptydumpty

                @BrutalBirdie Thank @fbartels . We owe him a beer now.

                BrutalBirdieB Offline
                BrutalBirdieB Offline
                BrutalBirdie
                Partner
                wrote on last edited by
                #17

                @humptydumpty said in Yubikey to secure servers.. has anyone tried it?:

                We owe him a beer now.

                If the yubico e-mail ever arrives 😬 I will sponsor a beer.

                Like my work? Consider donating a drink. Cheers!

                1 Reply Last reply
                2
                • timconsidineT timconsidine

                  @humptydumpty do I understand correctly that in order to use Cloudflare on a domain, they have to be registrar for it, i.e. transfer the domain to them?

                  I am my own Nominet registrar, so if the above is true, I cannot use Cloudflare on domains currently with Nominet.

                  EDIT : should have looked a bit further.
                  They don't support registering .UK domains so the above cannot be true.
                  Doh !
                  Ignore me.

                  BrutalBirdieB Offline
                  BrutalBirdieB Offline
                  BrutalBirdie
                  Partner
                  wrote on last edited by BrutalBirdie
                  #18

                  @timconsidine said in Yubikey to secure servers.. has anyone tried it?:

                  do I understand correctly that in order to use Cloudflare on a domain, they have to be registrar for it, i.e. transfer the domain to them?

                  No, you can also delegate single zones or the whole domain to another name server.
                  For example I have some domains registered at autodns, which cloudron does not have an auto config for.
                  So I can delegate either the whole domain or a zone to another name server.

                  Example:

                  I have my AwesomeDomain.tld and I want to have a cloudron on my.dev.AwesomeDomain.tld and want the .*.dev zone to be managed by DigitalOcean.
                  I can set 3x NS records for dev with ns[1-3].digitalocean.com. as value.

                  Now the zone is delegated to DigitalOcean DNS Servers and can be managed over there.

                  Watch out tho! When configuring Cloudron you have to click Advanced settings for the DNS setup and set the Zone Name (Optional) to dev.AwesomeDomain.tld which would be by default AwesomeDomain.tld

                  Like my work? Consider donating a drink. Cheers!

                  timconsidineT 1 Reply Last reply
                  3
                  • BrutalBirdieB BrutalBirdie

                    @timconsidine said in Yubikey to secure servers.. has anyone tried it?:

                    do I understand correctly that in order to use Cloudflare on a domain, they have to be registrar for it, i.e. transfer the domain to them?

                    No, you can also delegate single zones or the whole domain to another name server.
                    For example I have some domains registered at autodns, which cloudron does not have an auto config for.
                    So I can delegate either the whole domain or a zone to another name server.

                    Example:

                    I have my AwesomeDomain.tld and I want to have a cloudron on my.dev.AwesomeDomain.tld and want the .*.dev zone to be managed by DigitalOcean.
                    I can set 3x NS records for dev with ns[1-3].digitalocean.com. as value.

                    Now the zone is delegated to DigitalOcean DNS Servers and can be managed over there.

                    Watch out tho! When configuring Cloudron you have to click Advanced settings for the DNS setup and set the Zone Name (Optional) to dev.AwesomeDomain.tld which would be by default AwesomeDomain.tld

                    timconsidineT Offline
                    timconsidineT Offline
                    timconsidine
                    App Dev
                    wrote on last edited by
                    #19

                    @BrutalBirdie thank you !
                    For some reason I struggle with Cloudflare.
                    Must try harder - I'm sure it's within my grasp πŸ™‚

                    BrutalBirdieB humptydumptyH fbartelsF 3 Replies Last reply
                    0
                    • timconsidineT timconsidine

                      @BrutalBirdie thank you !
                      For some reason I struggle with Cloudflare.
                      Must try harder - I'm sure it's within my grasp πŸ™‚

                      BrutalBirdieB Offline
                      BrutalBirdieB Offline
                      BrutalBirdie
                      Partner
                      wrote on last edited by
                      #20

                      @timconsidine if you need some help, let me know. I am happy to help.

                      Like my work? Consider donating a drink. Cheers!

                      1 Reply Last reply
                      0
                      • timconsidineT timconsidine

                        @BrutalBirdie thank you !
                        For some reason I struggle with Cloudflare.
                        Must try harder - I'm sure it's within my grasp πŸ™‚

                        humptydumptyH Offline
                        humptydumptyH Offline
                        humptydumpty
                        wrote on last edited by
                        #21

                        @timconsidine No, I still have my domains at their respective registrars. You just edit the nameservers to cloudflare and you're set.

                        Cloudflare Nameservers
                        To use Cloudflare, ensure your authoritative DNS servers, or nameservers have been changed. These are your assigned Cloudflare nameservers.
                        Type	Value
                        NS	sunny.ns.cloudflare.com
                        NS	terin.ns.cloudflare.com
                        

                        BTW, renewal prices have gone up. The .com was $8.57 and it has gone up to $9.15. Namesilo sent an email back in aug-sep(?) about the price increase so it must be ICANN mandated.

                        timconsidineT 1 Reply Last reply
                        1
                        • humptydumptyH humptydumpty

                          @timconsidine No, I still have my domains at their respective registrars. You just edit the nameservers to cloudflare and you're set.

                          Cloudflare Nameservers
                          To use Cloudflare, ensure your authoritative DNS servers, or nameservers have been changed. These are your assigned Cloudflare nameservers.
                          Type	Value
                          NS	sunny.ns.cloudflare.com
                          NS	terin.ns.cloudflare.com
                          

                          BTW, renewal prices have gone up. The .com was $8.57 and it has gone up to $9.15. Namesilo sent an email back in aug-sep(?) about the price increase so it must be ICANN mandated.

                          timconsidineT Offline
                          timconsidineT Offline
                          timconsidine
                          App Dev
                          wrote on last edited by
                          #22

                          @humptydumpty thank you

                          I use my Nominet account for *.UK and dynadot for all else.
                          Dynadot seem similar prices.

                          1 Reply Last reply
                          1
                          • timconsidineT timconsidine

                            @BrutalBirdie thank you !
                            For some reason I struggle with Cloudflare.
                            Must try harder - I'm sure it's within my grasp πŸ™‚

                            fbartelsF Offline
                            fbartelsF Offline
                            fbartels
                            App Dev
                            wrote on last edited by
                            #23

                            @timconsidine i recently documented the steps in a little blog post. https://blog.9wd.eu/posts/9wd-tech-external-services/

                            timconsidineT 1 Reply Last reply
                            2
                            • fbartelsF fbartels

                              @timconsidine i recently documented the steps in a little blog post. https://blog.9wd.eu/posts/9wd-tech-external-services/

                              timconsidineT Offline
                              timconsidineT Offline
                              timconsidine
                              App Dev
                              wrote on last edited by
                              #24

                              @fbartels thank you !

                              1 Reply Last reply
                              1
                              • humptydumptyH Offline
                                humptydumptyH Offline
                                humptydumpty
                                wrote on last edited by humptydumpty
                                #25

                                @jdaviescoates during the mess of figuring out how to get to that offer button, I created a new account and signed up for the offer just like you did. I received an email yesterday with the "decline" and telling me how to become eligible. The sad part is that I haven't received the coupon on my eligible account yet.

                                1 Reply Last reply
                                1
                                • humptydumptyH Offline
                                  humptydumptyH Offline
                                  humptydumpty
                                  wrote on last edited by
                                  #26

                                  Update: I received my coupon email earlier today.

                                  The email came from (add it to your whitelist):

                                  resources {{a.t.}} info [.d.0.t.] yubico [.d.0.t.] com
                                  
                                  Congratulations! You are one step closer to activating phishing-resistant MFA with industry leading Yubico security keys at an exclusive 'good for the Internet' price.
                                  
                                  Even better news! For a limited time, we're excited to surprise you with an upgrade to our multi-protocol YubiKey 5 Series!
                                  
                                  You are now eligible to purchase up to 4 individual YubiKey 5 NFC or YubiKey 5C NFC (minimum 2) starting as low as $10 USD.  
                                  
                                  Ready to get started with the YubiKey?
                                  Here is your single-use coupon for up to four (4) YubiKey 5 NFC or YubiKey 5C NFC (minimum 2) keys for as low as $10 USD or €10 Euros at www.yubico.com
                                  
                                  But there is more…. 
                                  
                                  Looking to purchase more YubiKeys? YubiEnterprise Subscription provides flexible purchasing options of YubiKeys, predictable spend, premium support and a lower cost to entry.
                                  
                                  Cloudflare customers with 500 or more users are eligible to receive an exclusive 50% discount off their first year of YubiEnterprise Subscription.
                                  
                                  BrutalBirdieB 1 Reply Last reply
                                  2
                                  • humptydumptyH humptydumpty

                                    Update: I received my coupon email earlier today.

                                    The email came from (add it to your whitelist):

                                    resources {{a.t.}} info [.d.0.t.] yubico [.d.0.t.] com
                                    
                                    Congratulations! You are one step closer to activating phishing-resistant MFA with industry leading Yubico security keys at an exclusive 'good for the Internet' price.
                                    
                                    Even better news! For a limited time, we're excited to surprise you with an upgrade to our multi-protocol YubiKey 5 Series!
                                    
                                    You are now eligible to purchase up to 4 individual YubiKey 5 NFC or YubiKey 5C NFC (minimum 2) starting as low as $10 USD.  
                                    
                                    Ready to get started with the YubiKey?
                                    Here is your single-use coupon for up to four (4) YubiKey 5 NFC or YubiKey 5C NFC (minimum 2) keys for as low as $10 USD or €10 Euros at www.yubico.com
                                    
                                    But there is more…. 
                                    
                                    Looking to purchase more YubiKeys? YubiEnterprise Subscription provides flexible purchasing options of YubiKeys, predictable spend, premium support and a lower cost to entry.
                                    
                                    Cloudflare customers with 500 or more users are eligible to receive an exclusive 50% discount off their first year of YubiEnterprise Subscription.
                                    
                                    BrutalBirdieB Offline
                                    BrutalBirdieB Offline
                                    BrutalBirdie
                                    Partner
                                    wrote on last edited by
                                    #27

                                    I got my for Yubikeys today. πŸ™‚

                                    Like my work? Consider donating a drink. Cheers!

                                    humptydumptyH 1 Reply Last reply
                                    2
                                    • BrutalBirdieB BrutalBirdie

                                      I got my for Yubikeys today. πŸ™‚

                                      humptydumptyH Offline
                                      humptydumptyH Offline
                                      humptydumpty
                                      wrote on last edited by
                                      #28

                                      @BrutalBirdie Nice! I got mine yesterday (a day ahead of estimated delivery). I just got around to setting mine up. Vaultwarden (webauthn method) works great. I tried to secure my laptop login (W11 Home on a local account) but it's still logging me in without the Yubikey. The drive isn't encrypted so that might have something to do with it. I read that Bitlocker is only available on the Pro version, not Home. I can use Drive Encryption instead but it's asking to log into a Microsoft account. It's days like these when I curse the devs of my work related software for not supporting Linux!

                                      1 Reply Last reply
                                      1
                                      • humptydumptyH Offline
                                        humptydumptyH Offline
                                        humptydumpty
                                        wrote on last edited by
                                        #29

                                        How are you all carrying your Yubikey around?

                                        fbartelsF 1 Reply Last reply
                                        0
                                        • humptydumptyH humptydumpty

                                          How are you all carrying your Yubikey around?

                                          fbartelsF Offline
                                          fbartelsF Offline
                                          fbartels
                                          App Dev
                                          wrote on last edited by
                                          #30

                                          @humptydumpty i'm just carrying mine on my keychain. They are very robust. No problems so far with my 9+ years old key.

                                          BrutalBirdieB 1 Reply Last reply
                                          2
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Don't have an account? Register

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • Bookmarks
                                          • Search