Yubico Forum

...visit our web-store at store.yubico.com
It is currently Tue Jan 30, 2018 2:11 pm

All times are UTC + 1 hour




Post new topic Reply to topic  [ 4 posts ] 
Author Message
PostPosted: Thu Sep 22, 2016 3:33 pm 
Offline

Joined: Thu Sep 22, 2016 1:58 pm
Posts: 1
Hello,

I have been testing the new feature in Sierra to leverage PIV token login for authentication. I have wiped the token several times, therefore I am assuming that there are references to the prior tokens somewhere in the keychain.

I cannot locate where the linkage is between the Yubikey token and the authentication chain on Sierra so I may delete the old tokens.

Can someone point me in the right direction?


Top
 Profile  
Reply with quote  

Share On:

Share on Facebook FacebookShare on Twitter TwitterShare on Tumblr TumblrShare on Google+ Google+

PostPosted: Fri Sep 23, 2016 7:19 am 
Offline
Yubico Team
Yubico Team

Joined: Thu Oct 16, 2014 3:44 pm
Posts: 349
To unpair users from smartcards on macOS Sierra, the sc_auth command line tool should be used.

Examples:

To list all smartcard hashes for user:

sc_auth list [username]

To unpair a smart card for user:

sc_auth unpair -h [hash]

To unpair all smartcards for user:

sc_auth unpair [username]

For full documentation:
man sc_auth


Top
 Profile  
Reply with quote  
PostPosted: Wed Oct 19, 2016 2:33 am 
Offline

Joined: Mon Aug 15, 2016 5:37 am
Posts: 5
Can this be added to the GUI tool?


Top
 Profile  
Reply with quote  
PostPosted: Wed Oct 19, 2016 4:38 pm 
Offline
Yubico Team
Yubico Team

Joined: Thu Oct 16, 2014 3:44 pm
Posts: 349
No, the PIV Manager is only used for editing the NEO or YubiKey 4. We have no interest in trying to integrate it to handle managing Apple applications.

There are also other alternatives to this. If you don't want Sierra to prompt you to pair a smart card at all (this will work for ANY smart card inserted that contains a valid certificate), you can simply run:

sc_auth pairing_ui -s disable (can be re-enabled at any time with sc_auth pairing_ui -s enable)


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

All times are UTC + 1 hour


Who is online

Users browsing this forum: Google [Bot] and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group