[Bug 1204518] New: security/pam_u2f: u2f stopped working
http://bugzilla.opensuse.org/show_bug.cgi?id=1204518 Bug ID: 1204518 Summary: security/pam_u2f: u2f stopped working Classification: openSUSE Product: openSUSE.org Version: unspecified Hardware: Other OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: 3rd party software Assignee: meissner@suse.com Reporter: opensuse_buildservice@ojkastl.de QA Contact: screening-team-bugs@suse.de Found By: --- Blocker: --- I have these lines in /etc/pam.d/kde and /etc/pam.d/sudo: # /etc/pam.d/kde auth sufficient pam_u2f.so openasuser # /etc/pam.d/sudo auth sufficient pam_u2f.so authfile=/etc/Yubico/u2f_keys cue Sometime in the last week pam_u2f stopped working. On any sudo commands, I need to confirm on my U2F device, but then I get asked for the password. Same on KDE session unlocking, I need to enter the password. In addition, the login prompt does no longer get replaced by an "unlock" button as soon as I confirm on my U2F device. As pam_u2f had the last update 5 months ago, I suspect changes in other packages (pam?) as the reason for the breakage. Did not have much time to go looking for logs, also not sure where pam logs to? Kind Regards, Johannes -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1204518 http://bugzilla.opensuse.org/show_bug.cgi?id=1204518#c1 Johannes Kastl <opensuse_buildservice@ojkastl.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |IN_PROGRESS --- Comment #1 from Johannes Kastl <opensuse_buildservice@ojkastl.de> --- OK, I had some time to debug this, and it seems that pam_u2f needs a new authfile syntax. I had to recreate the u2f_keys file by using "pamu2fcfg". Then it works, at least for "sudo" and "sudo -i" using the following line: auth sufficient pam_u2f.so authfile=/etc/Yubico/u2f_keys cue I will test the KDE/Plasma lock screen functionality and report back. Kind Regards, Johannes -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1204518 http://bugzilla.opensuse.org/show_bug.cgi?id=1204518#c2 Johannes Kastl <opensuse_buildservice@ojkastl.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|IN_PROGRESS |RESOLVED Resolution|--- |FIXED --- Comment #2 from Johannes Kastl <opensuse_buildservice@ojkastl.de> --- OK, Plasma lock screen seems to work, too. Closing this. -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com