0 vote
YubiKey OTP is supported, but if the key is lost, there is no backup option and access to the program / database is lost.
It is common to have multiple keys supported, so backups can be registered with the application.
Do you have an example on where you would like the backup to be configured. Directly in File->Options?
Regards
David Hervieux
I think the best place would be where the first key can be registered. Maybe an additional option to register multiple YubiKeys could appear if a registered YubiKey is detected.
Windows Hello support would be ideal - then it can just bring over whatever keys are stored there.
Hello, just checking if there has been any progress on this one.
I'm also concerned that if my YubiKey breaks I'd be locked out of my vaults. Any chance on supporting a backup YubiKey?
-Paul
Hello,
I have increased the priority of this request.
Regards
David Hervieux
Hello David,
is there any progress in there?
To be sure that you can open the database, it would be good to be able to configure an additional second factor - as can be done with Application Security. So Yubikey, TOTP and/or DUO Security. Only one Yubikey good lead to a locked database when the Yubikey is lost.
Hello Tom,
There has not yet been movement on the internal ticket; I have asked the engineering team for an update on this request, we will keep you posted.
Best regards,
Richard Boisvert
Any news on this? We're looking into this either! We need a spare key for our higher privileged users. They need two keys to have a backup guaranteed.
Hello @kmdkeen,
Just to confirm with you, you mean for the lock feature in RDM, is that correct?
At the moment it's not possible but we will see if we can plan it for our 2025.1 roadmap.
Regards,
Hubert Mireault
No... we're looking into the "multiple yubikeys feature". It's common to have a spare key if the main key is lost/broken, but for now there is no (known) way to have two yubikeys linked to the same account in dvls/rdm. Correct?
Thank you for the clarification. We have a thread (and associated internal tickets) to allow configuring a backup MFA in DVLS: https://forum.devolutions.net/topics/39381/alternate-mfa-option-like-rdm-yubikey-duo-totp-instead-of-backup-codes
This would allow you to configure a Yubikey as the MFA, while configuring a different one as the backup. Please note that the plan for now is to have only one backup.
I've notified the DVLS team that you would be interested in this as well. I suggest following that thread, as the current one is specifically for having a second Yubikey configured for the lock feature in RDM.
Regards,
Hubert Mireault