-
Notifications
You must be signed in to change notification settings - Fork 81
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update to libpam_u2f-1.3.1 has broken PAM functionality for Yubikey 5 #330
Comments
Hi, First of all, sincerest apologies for the inconvenience. As part of this update we hardened ownership checks of the If not, could you please provide debug output? |
YES!!! |
Glad to hear that worked. We'll try to see if we can make this change more obvious for our users. |
I was too eager to close, but I guess having it open for a while will make the issue and its resolution more visible to those who'll face it too |
For those who have your chmod g-w,o-w $HOME/.config/Yubico/u2f_keys |
FYI: We have released pam-u2f 1.3.2 to revert this breaking change; pam-u2f will instead log a warning message to |
Thank you, guys, and keep up the good work! |
What version of pam-u2f are you using?
libpam-u2f (1.3.1-1~ppa3~jammy1)
as per/var/log/apt/term.log
Obtained it with today's routine apt update
What operating system are you using?
Ubuntu 22.04.5
libfido2-1/jammy,now 1.15.0~ppa~jammy1 amd64
What authenticator are you using?
Yubikey 5c nano
fido2-token -I
:Problem description
After today's routine software update I'm unable to log in and sudo using my Yubikey as 2nd factor auth. I was asked for my password, and then I expected to see the prompt to touch the authenticator, which failed to display. The login form hanged and didn't respond.
I had to enter recovery console and comment out all
@include common-yubikey
lines from/etc/pam.d/sudo
,/etc/pam.d/login
and other Yubikey-enabled entries, wherecommon-yubikey
file looks like this:I'd like to emphasize the fact that it all worked fine before the update. FIDO2 web auth still works alright, I was able to log in to GitHub with my Yubikey.
Here's my
/etc/pam.d/login
:/etc/pam.d/gdm-password
:/etc/pam.d/sudo
:The text was updated successfully, but these errors were encountered: