<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=3&amp;t=33" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2008-05-14T19:09:39+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=3&amp;t=33</id>
<entry>
<author><name><![CDATA[hrag]]></name></author>
<updated>2008-05-14T19:09:39+01:00</updated>
<published>2008-05-14T19:09:39+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=33&amp;p=37#p37</id>
<link href="https://forum.yubico.com/viewtopic.php?t=33&amp;p=37#p37"/>
<title type="html"><![CDATA[Does the one time pass phase have to be prefixed with the...]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=33&amp;p=37#p37"><![CDATA[
Q: Does the one time pass phase have to be prefixed with the user id or does the PAM plugin glue the two together before submitting the request?<br /><br />A: he PAM plugin only submit the OTP for online verification.  The authorization decision, i.e. to decide whether yubikey X is authorized to authenticate a login session for user Y, needs to be performed by the PAM module.  This is currently not implemented, but we have an open issue for it in our bug tracker: <a href="http://code.google.com/p/yubico-pam/issues/detail?id=4" class="postlink">http://code.google.com/p/yubico-pam/issues/detail?id=4</a><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=58">hrag</a> — Wed May 14, 2008 7:09 pm</p><hr />
]]></content>
</entry>
</feed>