<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=1894" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2015-05-26T16:45:40+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=1894</id>
<entry>
<author><name><![CDATA[keiki]]></name></author>
<updated>2015-05-26T16:45:40+01:00</updated>
<published>2015-05-26T16:45:40+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1894&amp;p=7355#p7355</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1894&amp;p=7355#p7355"/>
<title type="html"><![CDATA[Problem with OATH-HOTP two-factor authentication in OpenVPN]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1894&amp;p=7355#p7355"><![CDATA[
Hello,<br /><br />I configured slot 2 of my YubiKey NEO in OATH-HOTP mode in order to use it for a two-factor authentication. It works fine with SSH login, but with OpenVPN it fails with the following message:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">openvpn&#91;15059&#93;: AUTH-PAM: BACKGROUND: USER: keiki<br />openvpn&#91;15059&#93;: AUTH-PAM: BACKGROUND: my_conv&#91;0&#93; query='Password: ' style=1<br />openvpn&#91;15059&#93;: AUTH-PAM: BACKGROUND: my_conv&#91;0&#93; query='One-time password (OATH) for `keiki': ' style=1<br />openvpn&#91;15059&#93;: AUTH-PAM: BACKGROUND: user 'keiki' failed to authenticate: Authentication failure</div><br />When I connect to my OpenVPN server, the server only asks for the &quot;Auth Username&quot;, the &quot;Auth Password&quot; and the &quot;Private Key Password&quot;. There comes no message asking me for a one-time password (OATH).<br /><br />Maybe you can help me to find out, what is wrong in my PAM configuration /etc/pam.d/openvpn:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">auth    required pam_unix.so shadow nodelay<br />account required pam_unix.so<br />auth    required pam_oath.so usersfile=/etc/users.oath window=10 digits=8</div><br />Kind regards,<br /><br />keiki<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3734">keiki</a> — Tue May 26, 2015 4:45 pm</p><hr />
]]></content>
</entry>
</feed>