Hello,
After upgrading to macOS 10.12 Sierra I wanted to enable the challenge-response method again. As I noticed the availability of PIV, I gave it a try only to discover that it is not enforcable as login requirement, so I setup the PAM method.
Unfortunately enabling both methods created an incompatiblity. I'm unable to use the HMAC-SHA1 Challenge-Response functionality as inserting the stick will switch to the PIN entry input field. Specifying the PIN won't help much as the PAM method was added to /etc/pam.d/authorization as requirered.
Of course I created a Time-Machine backup before following the procedure, however the backup seems to be corrupt as I can't successfully mount the backup even on a vanilla Sierra installation. (I'm currently in contact with Apple's support)
I hope there is some way to resolve this without losing all data. If not, please add some word of warning to the guides.
Best, Luca
ps. I will try to deconfigure one of my keys PIV - if possible - and see if this helps.
|