<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=23&amp;t=2470" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2017-05-19T19:38:17+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=23&amp;t=2470</id>
<entry>
<author><name><![CDATA[Sevo]]></name></author>
<updated>2017-05-19T19:38:17+01:00</updated>
<published>2017-05-19T19:38:17+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2470&amp;p=9586#p9586</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2470&amp;p=9586#p9586"/>
<title type="html"><![CDATA[Re: [Q] Yubi SSH login AND Yubi Local Log On Possible?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2470&amp;p=9586#p9586"><![CDATA[
AND or OR? As far as I know, Yubikey local log on is indeed local - workarounds to plug the stick into the remote end by USB-over-VPN would not be entirely impossible, but are hardly practicable.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4736">Sevo</a> — Fri May 19, 2017 7:38 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[MD500Pilot]]></name></author>
<updated>2017-05-17T04:31:23+01:00</updated>
<published>2017-05-17T04:31:23+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2470&amp;p=9581#p9581</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2470&amp;p=9581#p9581"/>
<title type="html"><![CDATA[Re: [Q] Yubi SSH login AND Yubi Local Log On Possible?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2470&amp;p=9581#p9581"><![CDATA[
HELP....anyone...anyone...?<br /><br />New machine, still trying to make this work....<br /><br />Thanks<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4524">MD500Pilot</a> — Wed May 17, 2017 4:31 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[MD500Pilot]]></name></author>
<updated>2016-10-28T15:41:07+01:00</updated>
<published>2016-10-28T15:41:07+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2470&amp;p=9126#p9126</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2470&amp;p=9126#p9126"/>
<title type="html"><![CDATA[[Q] Yubi SSH login AND Yubi Local Log On Possible?]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2470&amp;p=9126#p9126"><![CDATA[
OK, I think I might be losing my mind here a little bit. Hopefully, I can make this work, but I think I am too close to the problem at this point.<br /><br />I am trying to get Yubikey SSH and Yubikey local log on working together. Or more specifically working correctly together.<br /><br />Right now, I have the local log on working fantastic. It required my Yubikey anytime I want to login locally to the machine, or the screen saver kicks in, exactly how I would like it.<br /><br />Then I moved on to getting SSH working with the yubikey. Initially following the PAM/ssh instructions it would not work at all unless I inserted the Yubikey into the machine I wanted to ssh INTO as opposed to the machine I was sshing FROM. I thought that was very weird, but then I figured out that within the pam ssh config file it was calling @include common-auth and once I commented that out, I was able to use my yubikey as intended to ssh into the computer. Insert the yubikiy into the local machine that I am on, ssh into the machine I want to access, enter my password followed by pressing the button on the yubikey and I was in!<br /><br />I though I was a happy camper but when I attempt to sudo (or su for that matter) my passwords were failing. So back to the logs I went and found out that in order to su or sudo via ssh, the yubikey had to be reinserted into the computer I was sshing INTO again. <br /><br />I think that it has to do with how (or in what order) PAM is looking for passwords or auths, but I am not sure and one thing I have learned is that it is very easy to lock yourself out of a box by messing around with PAM. <br /><br />Has someone got this working and would you be willing to share how...?<br /><br />Many Thanks<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4524">MD500Pilot</a> — Fri Oct 28, 2016 3:41 pm</p><hr />
]]></content>
</entry>
</feed>