<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=23&amp;t=2152" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2016-01-15T23:56:23+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=23&amp;t=2152</id>
<entry>
<author><name><![CDATA[bmorgenthaler]]></name></author>
<updated>2016-01-15T23:56:23+01:00</updated>
<published>2016-01-15T23:56:23+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2152&amp;p=8180#p8180</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2152&amp;p=8180#p8180"/>
<title type="html"><![CDATA[Re: sudo command in OS X authorizes without key]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2152&amp;p=8180#p8180"><![CDATA[
Sudo has it's own pam configuration module.  I have pam_yubico configured in the following locations:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">$ grep yubi /etc/pam.d/*<br />/etc/pam.d/authorization:auth       required       pam_yubico.so mode=challenge-response<br />/etc/pam.d/screensaver:auth       required       pam_yubico.so mode=challenge-response<br />/etc/pam.d/sudo:auth       required       pam_yubico.so mode=challenge-response<br /></div><br /><br />This covers logins (not filevault), screensaver and sudo.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=315">bmorgenthaler</a> — Fri Jan 15, 2016 11:56 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[ZIm]]></name></author>
<updated>2016-01-07T22:28:42+01:00</updated>
<published>2016-01-07T22:28:42+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2152&amp;p=8126#p8126</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2152&amp;p=8126#p8126"/>
<title type="html"><![CDATA[sudo command in OS X authorizes without key]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2152&amp;p=8126#p8126"><![CDATA[
I have just configured my OS X El Capitan for 2 factor authentication. It works for logins and authenticating features that require to unlock the lock icon in system settings. What i did notice tho is that the sudo command authenticates without the yubikey in the usb port. Is there a special setting for this? Isn't adding yubico_pam.so in /etc/pam.d/authorization supposed to protect all authorization in OS X?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4126">ZIm</a> — Thu Jan 07, 2016 10:28 pm</p><hr />
]]></content>
</entry>
</feed>