<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=23&amp;t=1693" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2015-01-05T12:17:24+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=23&amp;t=1693</id>
<entry>
<author><name><![CDATA[Alessio]]></name></author>
<updated>2015-01-05T12:17:24+01:00</updated>
<published>2015-01-05T12:17:24+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6676#p6676</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6676#p6676"/>
<title type="html"><![CDATA[Re: pam-u2f and no key plugged in]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6676#p6676"><![CDATA[
Hi Manuel,<br /><br />I have never encountered this behaviour during my tests. Are you using a real system or a virtual machine? Which distro?<br /><br />You can try some quick debugging by changing the authentication method of pam-u2f to <em>optional</em>. This should allow you to log in anyway.<br /><br />If that doesn't work you can enable system level debugging.<br /><br />To do that you have to edit the file /etc/syslog.conf (or rsyslog.conf if you are using rsyslog) and add the line<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">*.debug  /var/log/debug.log</div><br />After that you have to create the file /var/log/debug.log<br />And then create the file /etc/pam_debug<br />Restart (r)syslog and you should have debug messages inside debug.log<br /><br />I hope this helps<br />A.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3428">Alessio</a> — Mon Jan 05, 2015 12:17 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[aicahthohvip]]></name></author>
<updated>2015-01-03T11:23:24+01:00</updated>
<published>2015-01-03T11:23:24+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6668#p6668</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6668#p6668"/>
<title type="html"><![CDATA[Re: pam-u2f and no key plugged in]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6668#p6668"><![CDATA[
Hi Alessio,<br /><br />I've another problem with my system. When I enable pam-u2f after booting everything is working fine. I can lock my screen, change to console and so on. Login is working fine with pam-u2f<br />But when I reboot, I'm not able to login. Respectively I can login but get logged out immediately. The only way to use my system again is booting with a rescue Stick, disable pam-u2f. Then I can login, enable the module and use it fine.<br /><br />The logout is too fast to see any debug messages. And I can't find anything interesting in auth.log or syslog.<br /><br />Any ideas? Is there a way to write debug to file instead of stdout?<br /><br /><br />BR<br />Manuel<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3426">aicahthohvip</a> — Sat Jan 03, 2015 11:23 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Alessio]]></name></author>
<updated>2015-01-02T17:11:19+01:00</updated>
<published>2015-01-02T17:11:19+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6660#p6660</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6660#p6660"/>
<title type="html"><![CDATA[Re: pam-u2f and no key plugged in]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6660#p6660"><![CDATA[
Glad to help, and thank you for suggesting the improvement.<br /><br />A.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3428">Alessio</a> — Fri Jan 02, 2015 5:11 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[aicahthohvip]]></name></author>
<updated>2015-01-02T16:39:49+01:00</updated>
<published>2015-01-02T16:39:49+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6659#p6659</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6659#p6659"/>
<title type="html"><![CDATA[Re: pam-u2f and no key plugged in]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6659#p6659"><![CDATA[
Hi Alessio,<br /><br />you made my day. Many thanks, it work fine.<br /><br />--Manuel<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3426">aicahthohvip</a> — Fri Jan 02, 2015 4:39 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Alessio]]></name></author>
<updated>2015-01-02T16:02:51+01:00</updated>
<published>2015-01-02T16:02:51+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6658#p6658</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6658#p6658"/>
<title type="html"><![CDATA[Re: pam-u2f and no key plugged in]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6658#p6658"><![CDATA[
Hi Manuel,<br /><br />I have pushed a new version on github. Please check it out.<br /><br />You should now get a hard fail if anything within the authentication process gives an error.<br /><br />Furthermore, I have added a new configuration parameter called 'nouserok'. It defaults to unset, but if you set it, it will allow authentication requests to succeed even if the user is not present within the authentication file.<br /><br />I hope this helps.<br /><br />Let me know<br />A.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3428">Alessio</a> — Fri Jan 02, 2015 4:02 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[aicahthohvip]]></name></author>
<updated>2015-01-02T13:00:07+01:00</updated>
<published>2015-01-02T13:00:07+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6657#p6657</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6657#p6657"/>
<title type="html"><![CDATA[Re: pam-u2f and no key plugged in]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6657#p6657"><![CDATA[
Hi Alessio,<br /><br /><br />My pam config:<br /><br />auth    required        pam_u2f.so authfile=/etc/u2f_mappings appid=myappid debug<br />auth    required        pam_unix.so try_first_pass<br />auth    [success=1 default=ignore]      pam_unix.so nullok_secure try_first_pass<br />auth    requisite       pam_deny.so<br />auth    optional        pam_ecryptfs.so unwrap<br />auth    optional        pam_cap.so<br /><br /><br />Debug Log from success U2F auth:<br /><br />manuel@mamel:~$ sudo su<br />[pam-u2f.c:parse_cfg(39)] called.<br />[pam-u2f.c:parse_cfg(40)] flags 32768 argc 3<br />[pam-u2f.c:parse_cfg(42)] argv[0]=authfile=/etc/u2f_mappings<br />[pam-u2f.c:parse_cfg(42)] argv[1]=appid=myappid<br />[pam-u2f.c:parse_cfg(42)] argv[2]=debug<br />[pam-u2f.c:parse_cfg(43)] max_devices=0<br />[pam-u2f.c:parse_cfg(44)] debug=1<br />[pam-u2f.c:parse_cfg(45)] alwaysok=0<br />[pam-u2f.c:parse_cfg(46)] authfile=/etc/u2f_mappings<br />[pam-u2f.c:parse_cfg(47)] origin=(null)<br />[pam-u2f.c:parse_cfg(48)] appid=myappid<br />[pam-u2f.c:pam_sm_authenticate(87)] Origin not specified, using &quot;pam://mamel&quot;<br />[pam-u2f.c:pam_sm_authenticate(108)] Maximum devices number not set. Using default (24)<br />[pam-u2f.c:pam_sm_authenticate(124)] Requesting authentication for user manuel<br />[pam-u2f.c:pam_sm_authenticate(135)] Found user manuel<br />[pam-u2f.c:pam_sm_authenticate(136)] Home directory for manuel is /home/manuel<br />[pam-u2f.c:pam_sm_authenticate(162)] Using authentication file /etc/u2f_mappings<br />[util.c:get_devices_from_authfile(73)] Authorization line: manuel:****,****<br />[util.c:get_devices_from_authfile(78)] Matched user: manuel<br />[util.c:get_devices_from_authfile(104)] KeyHandle for device number 1: ****<br />[util.c:get_devices_from_authfile(127)] publicKey for device number 1: *****<br />[util.c:get_devices_from_authfile(140)] Length of key number 1 is 65<br />[util.c:get_devices_from_authfile(166)] Found 1 device(s) for user manuel<br />[util.c:do_authentication(219)] Device max index is 0<br />[util.c:do_authentication(242)] Attempting authentication with device number 1<br />[util.c:do_authentication(261)] Challenge: { &quot;keyHandle&quot;: &quot;*****&quot;, &quot;version&quot;: &quot;U2F_V2&quot;, &quot;challenge&quot;: &quot;*****&quot;, &quot;appId&quot;: &quot;myappid&quot; }<br />[util.c:do_authentication(267)] Response: { &quot;signatureData&quot;: &quot;***&quot;, &quot;clientData&quot;: &quot;***&quot;, &quot;keyHandle&quot;: &quot;****&quot; }<br />[pam-u2f.c:pam_sm_authenticate(192)] done. [Success]<br />[sudo] password for manuel: <br />root@mamel:/home/manuel#<br /><br /><br />Debug Log when no Yubikey is insert:<br /><br />manuel@mamel:~$ sudo su <br />[pam-u2f.c:parse_cfg(39)] called.<br />[pam-u2f.c:parse_cfg(40)] flags 32768 argc 3<br />[pam-u2f.c:parse_cfg(42)] argv[0]=authfile=/etc/u2f_mappings<br />[pam-u2f.c:parse_cfg(42)] argv[1]=appid=myappid<br />[pam-u2f.c:parse_cfg(42)] argv[2]=debug<br />[pam-u2f.c:parse_cfg(43)] max_devices=0<br />[pam-u2f.c:parse_cfg(44)] debug=1<br />[pam-u2f.c:parse_cfg(45)] alwaysok=0<br />[pam-u2f.c:parse_cfg(46)] authfile=/etc/u2f_mappings<br />[pam-u2f.c:parse_cfg(47)] origin=(null)<br />[pam-u2f.c:parse_cfg(48)] appid=myappid<br />[pam-u2f.c:pam_sm_authenticate(87)] Origin not specified, using &quot;pam://mamel&quot;<br />[pam-u2f.c:pam_sm_authenticate(108)] Maximum devices number not set. Using default (24)<br />[pam-u2f.c:pam_sm_authenticate(124)] Requesting authentication for user manuel<br />[pam-u2f.c:pam_sm_authenticate(135)] Found user manuel<br />[pam-u2f.c:pam_sm_authenticate(136)] Home directory for manuel is /home/manuel<br />[pam-u2f.c:pam_sm_authenticate(162)] Using authentication file /etc/u2f_mappings<br />[util.c:get_devices_from_authfile(73)] Authorization line: manuel:***,****<br />[util.c:get_devices_from_authfile(78)] Matched user: manuel<br />[util.c:get_devices_from_authfile(104)] KeyHandle for device number 1: ****<br />[util.c:get_devices_from_authfile(127)] publicKey for device number 1: ****<br />[util.c:get_devices_from_authfile(140)] Length of key number 1 is 65<br />[util.c:get_devices_from_authfile(166)] Found 1 device(s) for user manuel<br />[util.c:do_authentication(213)] Unable to discover device(s), cannot find U2F device<br />[pam-u2f.c:pam_sm_authenticate(175)] do_authentication returned -2<br />[pam-u2f.c:pam_sm_authenticate(192)] done. [The return value should be ignored by PAM dispatch]<br />[sudo] password for manuel: <br />root@mamel:/home/manuel# <br /><br /><br />The module say to me &quot;The return value should be ignored by PAM dispatch&quot; and this is that what PAM do, just ignore the return code -2 and going on the the next line.<br /><br /><br />I have a similar behavior when I try to authenticate a user without a config line in &quot;/etc/u2f_mappings&quot;:<br /><br />.... same as above ....<br />[util.c:get_devices_from_authfile(166)] Found 0 device(s) for user testuser<br />[pam-u2f.c:pam_sm_authenticate(175)] do_authentication returned -2<br />[pam-u2f.c:pam_sm_authenticate(192)] done. [The return value should be ignored by PAM dispatch]<br /><br /><br />This is good for me because I can have user which need a U2F device and user without the need of a U2F device. But it would be nicer if I can setup what happen when I user try to login and have no configuration file. The default action should be &quot;failed&quot;<br /><br /><br />BR<br />Manuel<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3426">aicahthohvip</a> — Fri Jan 02, 2015 1:00 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Alessio]]></name></author>
<updated>2015-01-02T12:37:55+01:00</updated>
<published>2015-01-02T12:37:55+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6656#p6656</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6656#p6656"/>
<title type="html"><![CDATA[Re: pam-u2f and no key plugged in]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6656#p6656"><![CDATA[
Hi,<br /><br />what you describe is not the intended behaviour. I suspect something is not right in the configuration files because the last line of three you have pasted will normally trigger a 'permission denied' error.<br /><br />Could you please paste the relevant lines of the configuration file in /etc/pam.d for the service you are using?<br /><br />Also a full dump of the debug information printed by the module would be helpful. Feel free to leave out the public key and the key handle, even tho they're not critical.<br /><br />Thanks<br />A.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3428">Alessio</a> — Fri Jan 02, 2015 12:37 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[aicahthohvip]]></name></author>
<updated>2015-01-02T00:06:00+01:00</updated>
<published>2015-01-02T00:06:00+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6649#p6649</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6649#p6649"/>
<title type="html"><![CDATA[pam-u2f and no key plugged in]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1693&amp;p=6649#p6649"><![CDATA[
Hi,<br /><br />I've successful setup pam-u2f. When my Yubico is plugged in, I need to press the button to get verified. But when I've unplugged my Yubico, pam-u2f seem to skip the auth process:<br /><br />####<br />[util.c:do_authentication(213)] Unable to discover device(s), cannot find U2F device<br />[pam-u2f.c:pam_sm_authenticate(175)] do_authentication returned -2<br />[pam-u2f.c:pam_sm_authenticate(192)] done. [The return value should be ignored by PAM dispatch]<br />####<br /><br />This is very bad because I just need to unplug any U2F Device to get verified and can login .... Is there any way to change this behavior? I expect an auth failure when no U2F Key is found.<br /><br />BR<br />Manuel<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=3426">aicahthohvip</a> — Fri Jan 02, 2015 12:06 am</p><hr />
]]></content>
</entry>
</feed>