<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=23&amp;t=2514" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2017-01-02T14:46:41+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=23&amp;t=2514</id>
<entry>
<author><name><![CDATA[plum]]></name></author>
<updated>2017-01-02T14:46:41+01:00</updated>
<published>2017-01-02T14:46:41+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2514&amp;p=9248#p9248</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2514&amp;p=9248#p9248"/>
<title type="html"><![CDATA[PAM + Dovecot problem]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2514&amp;p=9248#p9248"><![CDATA[
I have set up pam SSH authentication using yubikey-pam lib and for SSH it works fine (and for sudo too). Since pam module is called by pam-common, yunikey auth is also required for accessing IMAP account and I can't get this to work. The IMAP server is dovecot (debian) and pam-yubikey logs show that there's curl error:<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Jan  2 14:33:36 vps dovecot: auth-worker: Error: &#91;../pam_yubico.c:pam_sm_authenticate(990)&#93; Skipping first 9 bytes. Length is 53, token_id set to 12 and token OTP always 32.<br />Jan  2 14:33:36 vps dovecot: auth-worker: Error: &#91;../pam_yubico.c:pam_sm_authenticate(997)&#93; OTP: REDACTED ID: REDACTED<br />Jan  2 14:33:36 vps dovecot: auth-worker: Error: &#91;../pam_yubico.c:pam_sm_authenticate(1012)&#93; Extracted a probable system password entered before the OTP - setting item PAM_AUTHTOK<br />Jan  2 14:33:36 vps dovecot: auth-worker: Error: &#91;../pam_yubico.c:pam_sm_authenticate(1028)&#93; ykclient return value (109): Error performing curl<br />Jan  2 14:33:36 vps dovecot: auth-worker: Error: &#91;../pam_yubico.c:pam_sm_authenticate(1091)&#93; done. &#91;Authentication service cannot retrieve authentication info&#93;<br /></div><br /><br />I tried giving both dovecot users real shell (system dovecot accounts have /bin/false as shell) but it doesn't work. I'm out of ideas.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4581">plum</a> — Mon Jan 02, 2017 2:46 pm</p><hr />
]]></content>
</entry>
</feed>