<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=5&amp;t=746" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2012-01-27T17:32:10+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=5&amp;t=746</id>
<entry>
<author><name><![CDATA[samir]]></name></author>
<updated>2012-01-27T17:32:10+01:00</updated>
<published>2012-01-27T17:32:10+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=746&amp;p=2904#p2904</id>
<link href="https://forum.yubico.com/viewtopic.php?t=746&amp;p=2904#p2904"/>
<title type="html"><![CDATA[Re: Fallback configuration]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=746&amp;p=2904#p2904"><![CDATA[
Hi,<br /><br />Currently there is no configurable timeout in yubico-c-client.<br /><br />Also, please note, the 2FA approach explained above could be circumvented by anyone who is able to DoS the connectivity between the validation client and the server.<br /><br />Thanks,<br />Samir.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1076">samir</a> — Fri Jan 27, 2012 5:32 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[eltrai]]></name></author>
<updated>2012-01-22T02:22:47+01:00</updated>
<published>2012-01-22T02:22:47+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=746&amp;p=2903#p2903</id>
<link href="https://forum.yubico.com/viewtopic.php?t=746&amp;p=2903#p2903"/>
<title type="html"><![CDATA[Fallback configuration]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=746&amp;p=2903#p2903"><![CDATA[
Hi,<br />I'm trying to set up a 2-way yubikey authentification (using yubico-pam and an internal server) on my server and came across a problem I couldn't solve.<br />What i'm trying to do is to set up a fallback configuration in case my validation server goes dark so that I don't get locked out.<br />So, I did use the distinction pam can make between auth_err and authinfo_unavail to achieve that. (like it is explained here : <!-- m --><a class="postlink" href="http://forum.yubico.com/viewtopic.php?f=3&amp;t=739">http://forum.yubico.com/viewtopic.php?f=3&amp;t=739</a><!-- m -->)<br />However, depending on the kind of issue the validation server is experiencing, it may fail :<br />- If I cut out the network from the server itself, the fallback configuration is indeed used and therefor it's good.<br />- But if the server is network-reachable but simply not responding (service down, iptable ban, etc.), it seems the yubico-pam module is waiting without restraint for it to answer, until the login attempt itself timeouts, therefore not granting a session. I didn't find how to configure a shorter timeout for the pam module.<br /><br />Does any of you has an solution ?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1942">eltrai</a> — Sun Jan 22, 2012 2:22 am</p><hr />
]]></content>
</entry>
</feed>