<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=23&amp;t=2036" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2015-09-18T14:28:34+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=23&amp;t=2036</id>
<entry>
<author><name><![CDATA[mruser100]]></name></author>
<updated>2015-09-18T14:28:34+01:00</updated>
<published>2015-09-18T14:28:34+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2036&amp;p=7813#p7813</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2036&amp;p=7813#p7813"/>
<title type="html"><![CDATA[[Q?] Local certificate login to OS X with NEO]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2036&amp;p=7813#p7813"><![CDATA[
I'd like to enable logging into OS X Yosemite with certificates. This should allow 3 functionalities that I'm not sure that Yubico-PAM gives (correct me if I'm wrong)<br /><ul><li>Bind multiple certificates to a single username.</li><li>Automatically detect if the certificate is present, otherwise allow password login (which I can keep backed up elsewhere in case I need it.)</li><li>Require a PIN along with the NEO</li></ul><br />Below are the steps I took to try and set this up. But here is the fundamental problem/question:<br /><strong>When I insert the NEO, the Password input box flashes, but continues to only accept my password. Any ideas how to fix this?</strong> With traditional smartcards, when you insert the smartcard, the Password input box switches and asks for a PIN instead. My guess is that the CCID aspect of the NEO isn't behaving like a traditional smartcard, so Yosemite isn't responding appropriately by requesting a PIN. Maybe  there is a different <em>security authorizationdb</em> attribute than the one I used below (&quot;smartcard&quot;)?<br /><br />Thanks for your help!<br /><br />~~~~~<br /><br />I've installed OpenSC 0.15.0, insert my NEO with the certificate I want installed on slot 9a, and tried the following commands which work with traditional smartcards:<br /><br /><span style="color: #408040">$ sudo security authorizationdb smartcard enable<br />$ sudo sc_auth accept -u </span><span style="color: #0000FF">my_username</span><span style="color: #408040"> -h </span><span style="color: #0000FF">my_key_hash</span><br /><br />I can verify that the settings are correct with these commands:<br /><br /><span style="color: #408040">$ sudo security authorizationdb smartcard status</span><br /><span style="color: #BF0000">Current smartcard login state: enabled (system.login.console enabled, authentication rule enabled)<br />YES (0)</span><br /><span style="color: #408040">$ sc_auth hash -k</span><br /><span style="color: #BF0000"><em>my_key_hash</em> PIV AUTH key</span><br /><span style="color: #408040">$ sc_auth list -u</span> <span style="color: #0000FF">my_username</span><br /><span style="color: #BF0000"><em>my_key_hash</em></span><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3902">mruser100</a> — Fri Sep 18, 2015 2:28 pm</p><hr />
]]></content>
</entry>
</feed>