<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=35&amp;t=2334" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2016-06-07T09:14:22+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=35&amp;t=2334</id>
<entry>
<author><name><![CDATA[oscarerbetta]]></name></author>
<updated>2016-06-07T09:14:22+01:00</updated>
<published>2016-06-07T09:14:22+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2334&amp;p=8691#p8691</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2334&amp;p=8691#p8691"/>
<title type="html"><![CDATA[yubikey + openvpn]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2334&amp;p=8691#p8691"><![CDATA[
Hi all,<br /><br />I have a working OpenVPN environment and a local yubikey validation server.<br />I need to have this working for non-yubikeys users as well for yubikey users.<br />I have this working with SSH but with OpenVPN it doesn't work the same<br />specifications in the /etc/pam.d/openvpn file.<br /><br />this is my /etc/pam.d/openvpn file:<br />### YUBICO<br /># Call Yubikey module for users with key in /etc/yubikeyauth<br />auth    required       pam_yubico.soauthfile=/etc/yubikeyauth    id=2    key=&lt;aes key&gt;url=&lt;myserver&gt;     debug<br /><br />so what I need is that users listed in /etc/yubikeyauth get authenticated with their password+OTP,<br />and users not listed there just with their password.<br /><br />How can I achieve this?<br /><br />Thanks!<br />Oscar<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4359">oscarerbetta</a> — Tue Jun 07, 2016 9:14 am</p><hr />
]]></content>
</entry>
</feed>