<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=23&amp;t=1448" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2014-08-20T13:24:06+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=23&amp;t=1448</id>
<entry>
<author><name><![CDATA[hobleyd]]></name></author>
<updated>2014-08-20T13:24:06+01:00</updated>
<published>2014-08-20T13:24:06+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1448&amp;p=5494#p5494</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1448&amp;p=5494#p5494"/>
<title type="html"><![CDATA[[BUG] pam config no longer working after SSL renewal]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1448&amp;p=5494#p5494"><![CDATA[
Hello,<br /><br />I have a couple of Yubikeys which I have configured with my own authentication server; I have pam configured to use that server and it has all been working well.<br /><br />I renewed my ssl certificates a few days ago and since then, the pam authentication has failed to work. If I put pam into debug mode, I get:<br /><br />[pam_yubico.c:pam_sm_authenticate(972)] conv returned 44 bytes<br />[pam_yubico.c:pam_sm_authenticate(990)] Skipping first 0 bytes. Length is 44, token_id set to 12 and token OTP always 32.<br />[pam_yubico.c:pam_sm_authenticate(997)] OTP: &lt;OTP&gt; ID: cccccccccccb <br /><strong>[pam_yubico.c:pam_sm_authenticate(1028)] ykclient return value (101): Could not parse server response</strong><br />[pam_yubico.c:pam_sm_authenticate(1089)] done. [Authentication service cannot retrieve authentication info]<br /><br />However, if I run curl from the command line to double check things:<br /><br />curl &quot;https://&lt;url&gt;/wsapi/2.0/verify?id=1&amp;otp=cccccccccccbuejgbetvinrggvhbblghibrlbnefudif&amp;nonce=12345678901234567890&quot;<br />h=ZNrvPCKBjfbPA6sVuBaIQcZ2wtc=<br />t=2014-08-20T10:50:53Z0954<br />otp=cccccccccccbuejgbetvinrggvhbblghibrlbnefudif<br />nonce=12345678901234567890<br />sl=0<br />status=OK<br /><br />If I put the old SSL certs back in place, everything starts working again. The only thing I can think of is that I use a 4096 byte SSL key, rather than the standard 2048 - could this case the issue?<br /><br />Any idea how I can debug things? The rest of my SSL infrastructure works fine - Firefox recognises everything as normal; curl has no issues, I don't really know where to go next...<br /><br />The pam config is:<br /><br />authsufficientpam_yubico.so debug id=1 url=https://&lt;url&gt;/wsapi/2.0/verify?id=%d&amp;otp=%s<br /><br />Cheers,<br />David<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2983">hobleyd</a> — Wed Aug 20, 2014 1:24 pm</p><hr />
]]></content>
</entry>
</feed>