<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=1656" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2015-09-26T20:26:27+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=1656</id>
<entry>
<author><name><![CDATA[basteed]]></name></author>
<updated>2015-09-26T20:26:27+01:00</updated>
<published>2015-09-26T20:26:27+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1656&amp;p=7841#p7841</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1656&amp;p=7841#p7841"/>
<title type="html"><![CDATA[Re: potential issue with OS X 10.10 Yosemite and smartcards]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1656&amp;p=7841#p7841"><![CDATA[
<div class="quotetitle">CypherCookie wrote:</div><div class="quotecontent"><br />I've managed to follow the guide Yubico have produced, to install the yubico-pam module, generate the key and set screen saver &amp; login requiring the yubikey to be present to unlock the device all on a OS X 10.9 Mac. <br /><br />The problem i have is that this doesn't work on OS X 10.10. I have followed the exact same steps and screensaver lock works but login 2fa doesn't.<br /><br />I've had a look at the suggestions already given and none of them have helped me to get around this.<br /><br />Any thoughts on how to get around this would be most appreciated! <br /><br />Cypher.<br /></div><br />Have screensaver &amp; user account login 2FA working on 10.10.5 with my Neo-n with homebrew installed pam_yubico module. Had to move the pam_yubico.so file to /usr/lib/pam from the homebrew installed location.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3942">basteed</a> — Sat Sep 26, 2015 8:26 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[ChrisHalos]]></name></author>
<updated>2015-07-22T00:28:30+01:00</updated>
<published>2015-07-22T00:28:30+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1656&amp;p=7628#p7628</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1656&amp;p=7628#p7628"/>
<title type="html"><![CDATA[Re: potential issue with OS X 10.10 Yosemite and smartcards]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1656&amp;p=7628#p7628"><![CDATA[
PAM module works just fine for me in OSX 10.10.4. Make sure you're adding the &quot;auth       required       pam_yubico.so mode=challenge-response&quot; line between the &quot;auth&quot; and &quot;account&quot; lines. The order seems to be important.<br /><br /><!-- m --><a class="postlink" href="https://www.yubico.com/wp-content/uploads/2015/04/YubiKey-OSX-Login.pdf">https://www.yubico.com/wp-content/uploa ... -Login.pdf</a><!-- m --><br /><br />I have not, however, figured out if there is a way to selectively enable the PAM requirement on certain accounts (i.e. configuring this will require the YubiKey for all accounts, assuming you also ran ykpamcfg -2 on each of the user accounts, otherwise you will be unable to log into those accounts.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3140">ChrisHalos</a> — Wed Jul 22, 2015 12:28 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[CypherCookie]]></name></author>
<updated>2015-07-21T13:37:19+01:00</updated>
<published>2015-07-21T13:37:19+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1656&amp;p=7621#p7621</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1656&amp;p=7621#p7621"/>
<title type="html"><![CDATA[Re: potential issue with OS X 10.10 Yosemite and smartcards]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1656&amp;p=7621#p7621"><![CDATA[
I've managed to follow the guide Yubico have produced, to install the yubico-pam module, generate the key and set screen saver &amp; login requiring the yubikey to be present to unlock the device all on a OS X 10.9 Mac. <br /><br />The problem i have is that this doesn't work on OS X 10.10. I have followed the exact same steps and screensaver lock works but login 2fa doesn't.<br /><br />I've had a look at the suggestions already given and none of them have helped me to get around this.<br /><br />Any thoughts on how to get around this would be most appreciated! <br /><br />Cypher.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3807">CypherCookie</a> — Tue Jul 21, 2015 1:37 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[megatraveller2]]></name></author>
<updated>2015-02-04T21:33:09+01:00</updated>
<published>2015-02-04T21:33:09+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1656&amp;p=6818#p6818</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1656&amp;p=6818#p6818"/>
<title type="html"><![CDATA[Re: potential issue with OS X 10.10 Yosemite and smartcards]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1656&amp;p=6818#p6818"><![CDATA[
Thanks for that Info Darco. The Setup works just well with the Workaround that FlorinAndrei describes.<br /><br />Do any of you guys use the PAM Module on OS X 10.10 to unlock Screensaver or Sudo with the Yubikey?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3508">megatraveller2</a> — Wed Feb 04, 2015 9:33 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[darco]]></name></author>
<updated>2015-01-20T20:28:08+01:00</updated>
<published>2015-01-20T20:28:08+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1656&amp;p=6755#p6755</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1656&amp;p=6755#p6755"/>
<title type="html"><![CDATA[Re: potential issue with OS X 10.10 Yosemite and smartcards]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1656&amp;p=6755#p6755"><![CDATA[
I've got some patches to GnuPG which seem to improve the situation for me:<br /><br /><!-- m --><a class="postlink" href="https://github.com/darconeous/GnuPG/tree/scdaemon-behave">https://github.com/darconeous/GnuPG/tre ... mon-behave</a><!-- m --><br /><br />These patches allow me to get OS X keychain integration along with GnuPG. The integration isn't perfect, and the patches could use some love, but it does work for me.<br /><br />Just make sure you add a line with &quot;card-timeout 2&quot; to &quot;~/.gnupg/scdaemon.conf&quot;.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3288">darco</a> — Tue Jan 20, 2015 8:28 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[mrsteveman1]]></name></author>
<updated>2015-01-18T18:22:36+01:00</updated>
<published>2015-01-18T18:22:36+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1656&amp;p=6745#p6745</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1656&amp;p=6745#p6745"/>
<title type="html"><![CDATA[Re: potential issue with OS X 10.10 Yosemite and smartcards]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1656&amp;p=6745#p6745"><![CDATA[
For anyone who is still struggling with this issue on Yosemite (it's because of bugs in Apple's new PCSC implementation), I've come up with a temporary, simple and easily reversible workaround and posted instructions on the GPGTools support forum[1]. It works very well, no need to kill gpg-agent or remove and reinsert the NEO anymore.<br /><br />There are some downsides, but some users will be totally unaffected by them (for instance those with NEO models without the PIV applet, or who aren't using it) and others may find them acceptable tradeoffs anyway to ensure GPG works reliably.<br /><br />[1] details here: <a href="http://support.gpgtools.org/discussions/problems/28634-gpg-agent-stops-working-after-osx-upgrade-to-yosemite#comment_35808149" class="postlink">http://support.gpgtools.org/discussions/problems/28634-gpg-agent-stops-working-after-osx-upgrade-to-yosemite#comment_35808149</a><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1048">mrsteveman1</a> — Sun Jan 18, 2015 6:22 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[FlorinAndrei]]></name></author>
<updated>2014-12-11T00:41:08+01:00</updated>
<published>2014-12-11T00:41:08+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1656&amp;p=6488#p6488</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1656&amp;p=6488#p6488"/>
<title type="html"><![CDATA[potential issue with OS X 10.10 Yosemite and smartcards]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1656&amp;p=6488#p6488"><![CDATA[
If you're a Mac user and you're using the NEO tokens as smartcards for ssh authentication, you may want to refrain from &quot;upgrading&quot; to 10.10, due to this issue:<br /><br /><!-- m --><a class="postlink" href="http://support.gpgtools.org/discussions/problems/30646-gpg-agent-gets-stuck-when-used-with-smartcards-in-ssh-agent-mode">http://support.gpgtools.org/discussions ... agent-mode</a><!-- m --><br /><br />Basically, your ssh sessions may get stuck in authentication, randomly. Or authentication may fail, as if you're not using the right ssh key.<br /><br />What seems to be a workable temporary fix is to run &quot;pkill gpg-agent&quot; a few times, then manually do &quot;gpg-agent --daemon&quot; once, in a terminal. Sometimes you may have to unplug / replug the NEO token, too. That usually fixes your ssh authentication with the NEO token.<br /><br />OS X 10.9 seems to work just fine.<br /><br />For context, this is a setup similar to the one described and discussed in this thread:<br /><br /><a href="http://forum.yubico.com/viewtopic.php?f=26&amp;t=1171" class="postlink">[HOW-TO] - Yubikey NEO, OpenPGP, OpenSSH authentication</a><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2986">FlorinAndrei</a> — Thu Dec 11, 2014 12:41 am</p><hr />
]]></content>
</entry>
</feed>