question

MrTechPerson-3593 avatar image
0 Votes"
MrTechPerson-3593 asked MrTechPerson-3593 answered

Yubikey not being seen by Vmware VM over RDP connection

Salutations

I have a specific issue that I cannot find much help on so hoping this great community can help me.

I have a physical Windows 10 client that I stick my yubikey into. The workstation can detect the key (verified through device manager) and I then RDP on to a

windows 2019 server that has the Yubikey manager software. That vmware VM (ESXs - vsphere) cannot detect the key.

Just to be clear, I do not want to use the yubikey for authentication, I just want it to appear on the remote windows VM so I can run the yubikey manager software

to start enrollment.

I have found 1 useful guide = https://queensidecastle.com/guides/use-a-yubikey-remotely-over-rdp

but it still did not work for me. For those who do not want to read the link I did the following

Workstation

Enabled - Allow RDP redirection of other supported RemoteFX USB devices from this computer

Updated the Registry with the Class GUID of the Yubikey (Series 5 NFC) - [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services\Client\UsbSelectDeviceByInterfaces]

Remote Windows Server

Disabled - Do not allow supported Plug and Play device redirection

On the workstation I can see the Yubikey but not on the VM.

Any suggestions? I may have gone off tangent and started looking at ESXi USB pass through but that is if I want to stick the yubikey in the ESXi host I believe?

Thanks


Trilby

windows-server
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

DSPatrick avatar image
0 Votes"
DSPatrick answered

Might need to request vendor support here.
https://support.yubico.com/hc/en-us/requests/new

--please don't forget to Accept as answer if the reply is helpful--






5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

MrTechPerson-3593 avatar image
0 Votes"
MrTechPerson-3593 answered

Hello Patrick

Thank you for your suggestion but I do not believe it is Yubikey issue because I have proven I can get yubikey to work on a Windows server 2019.

I think the issue is one which the Workstation has taken "control" of the yubikey and will not let go so the VM does not see it, however my google fu is not finding the correct answer for me.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

DSPatrick avatar image
0 Votes"
DSPatrick answered

The vendor will be your best resource for debugging problems with their product.


--please don't forget to Accept as answer if the reply is helpful--


5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

MrTechPerson-3593 avatar image
0 Votes"
MrTechPerson-3593 answered KarlieWeng-MSFT commented

I will ask, however as the link I have now corrected in my original post shows it did work.


Question posted - they work Mon - Fri so will update here one way or another.

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Have the problem resolved? If any problem, welcome to feedback!

0 Votes 0 ·
DSPatrick avatar image
0 Votes"
DSPatrick answered

Sounds good.

--please don't forget to Accept as answer if the reply is helpful--


5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

DSPatrick avatar image
0 Votes"
DSPatrick answered

Just checking if there's any progress or updates?

--please don't forget to upvote and Accept as answer if the reply is helpful--


5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

MrTechPerson-3593 avatar image
0 Votes"
MrTechPerson-3593 answered

Hello, no answer - yubico not yet responded with a solution.

I still think the fix will be a Microsoft related fix e.g. some reg key no doubt.

I did make 1 tiny bit of progress.

If I RDP to the machine, on the remote machine I do not see Smart Card Readers or Smart Cards appear in device manager.

I installed the remote desktop hosts role on the remote machine and now when I RDP to the machine I see Smart Card Readers appear with Microsoft Usbccid Smartcard Reader (WUDF) but no Smart Card. I can go to add Legacy Hardware and install Smart Cards and choose YubiKey Smart Card Minidriver but the card is not "properly" detected by the yubikey manager. What I mean by properly is that I can remove and insert the yubikey device into the host machine and the remote machine will detect it, Microsoft Usbccid Smartcard Reader (WUDF) will appear and disappear accordingly.

Finally, if I examine the YubiKey Smart Card Minidriver in Device Manager under device status - it says the device is working properly but the location is value is "unknown". It should say scfilter, I have confirmed the scfilter driver is started on the remote machine when the yubikey is inserted so there is some detection.

Sorry if this was long but it may help someone, again this cannot be a unique use case? If I could find a offical (MS) article that says the smart card enrolment machine has to be physical I will accept it.

ta

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.