Not tested myself, but maybe USB via IP mounted in WSL could work? Either by installing a USBIP tool on Windows or using a network host and sharing the token via the network?
Wow. Never heard about USBIP but it sound astonishing. it should be possible to centralize all the keys of our company in a single room so
Manu thanks @nku , but I don’t really understand how it can be done locally on the host.
Yes, we are also not really happy that there is need for administrator permissions in order to properly make use of the Nitrokey (3) tools within Windows. Anyways please keep in mind that the FIDO2 and Smartcard functionality by itself is not requiring admin-permissions. But we are also looking into improving the situation for pynitrokey and thus NitrokeyApp2.
Hi @daringer
Good to know, thanks.
But OpenVpn community does not support FIDO2 protocol, and we don’t know any other option than using TOTP which is agnostic of the app : to do so our users paste the TOTP code next to the password and the whole code is handled by our privacyID server (which hitself relies on a freeradius server).
But with this config, I don’t know any other way to proceed, except using HOTP of the Ubikey, unfortunately.