<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=23&amp;t=2439" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2017-09-11T10:16:50+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=23&amp;t=2439</id>
<entry>
<author><name><![CDATA[owl]]></name></author>
<updated>2017-09-11T10:16:50+01:00</updated>
<published>2017-09-11T10:16:50+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2439&amp;p=9739#p9739</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2439&amp;p=9739#p9739"/>
<title type="html"><![CDATA[Re: Mac logon: PAM vs PIV?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2439&amp;p=9739#p9739"><![CDATA[
interestingly, Richard Purves recommends (see reference in my previous post) using BOTH PIV and PAM logon at the same time. In my understanding PAM is something stronger, because 1) it's based on challenge-response, so an adversary won't be able to mount a replay attack, 2) you can require presenting your key with PAM, while with PIV both username/pwd and Yubikey/PIN will log you on.<br /><br />So what are the benefits of invoking PIV in addition to PAM? any ideas? thanks!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3625">owl</a> — Mon Sep 11, 2017 10:16 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[owl]]></name></author>
<updated>2017-07-15T15:53:53+01:00</updated>
<published>2017-07-15T15:53:53+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2439&amp;p=9658#p9658</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2439&amp;p=9658#p9658"/>
<title type="html"><![CDATA[Re: Mac logon: PAM vs PIV?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2439&amp;p=9658#p9658"><![CDATA[
Good stuff on the topic:<br /><!-- m --><a class="postlink" href="http://www.richard-purves.com/2017/02/13/locking-macos-with-yubikey-4-piv-and-pam/">http://www.richard-purves.com/2017/02/1 ... v-and-pam/</a><!-- m --><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3625">owl</a> — Sat Jul 15, 2017 3:53 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Greybeard]]></name></author>
<updated>2016-10-11T13:11:20+01:00</updated>
<published>2016-10-11T13:11:20+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2439&amp;p=9080#p9080</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2439&amp;p=9080#p9080"/>
<title type="html"><![CDATA[Re: Mac logon: PAM vs PIV?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2439&amp;p=9080#p9080"><![CDATA[
Thank you for that information.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4502">Greybeard</a> — Tue Oct 11, 2016 1:11 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[ChrisHalos]]></name></author>
<updated>2016-10-03T21:07:51+01:00</updated>
<published>2016-10-03T21:07:51+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2439&amp;p=9066#p9066</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2439&amp;p=9066#p9066"/>
<title type="html"><![CDATA[Re: Mac logon: PAM vs PIV?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2439&amp;p=9066#p9066"><![CDATA[
Yes, multiple YubiKeys can be added to the same account via PIV. Just go through the same setup procedure (start to finish).<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3140">ChrisHalos</a> — Mon Oct 03, 2016 9:07 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Greybeard]]></name></author>
<updated>2016-10-03T16:14:14+01:00</updated>
<published>2016-10-03T16:14:14+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2439&amp;p=9065#p9065</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2439&amp;p=9065#p9065"/>
<title type="html"><![CDATA[Re: Mac logon: PAM vs PIV?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2439&amp;p=9065#p9065"><![CDATA[
I can't speak directly to the security, but from an ease of use I much prefer the PAM.  I converted to the smartcard method once Sierra was released, and now it successfully unlocks when I enter my pin from screensaver lock, but I am now frequently asked to provide my password to unlock my Local Items keychain for applications.  When I was using the PAM method, this did not occur.<br /><br />Secondarily, I have not found documentation as to whether I can enroll multiple Yubikeys as smartcards for my account.  I have two for my work machine (one 4, one 4 Nano), and in PAM mode, I had them both enrolled in case one was lost or left at home, etc.   This latter question is what brought me here today, but I don't see any posts on point.<br /><br />Best of luck<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4502">Greybeard</a> — Mon Oct 03, 2016 4:14 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[owl]]></name></author>
<updated>2016-09-24T19:46:15+01:00</updated>
<published>2016-09-24T19:46:15+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2439&amp;p=9047#p9047</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2439&amp;p=9047#p9047"/>
<title type="html"><![CDATA[Mac logon: PAM vs PIV?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2439&amp;p=9047#p9047"><![CDATA[
Hello!<br /><br />it is announced on Yubico website that starting from Sierra macOS supports logon with smartcards. That said, it becomes possible to logon to macOS using Yubikey's PIV module, not only PAM. But which one is better from security perspective? Shall one prefer new PIV-enabled way or stick to old PAM?<br /><br />Thanks!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3625">owl</a> — Sat Sep 24, 2016 7:46 pm</p><hr />
]]></content>
</entry>
</feed>