Your message dated Fri, 5 Apr 2024 22:55:51 +0200
with message-id <[email protected]>
and subject line Please reconfigure your u2f file
has caused the Debian Bug report #1067090,
regarding libpam-u2f: Only first key is checked in authfile
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1067090: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067090
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: libpam-u2f
Version: 1.1.0-1.1+b1
Severity: normal
X-Debbugs-Cc: [email protected]
Dear Maintainer,
after enrolling multiple keys in my u2f_keys file only the first one is
checked
by libpam-u2f.
> $ cat /etc/pam.d/sudo
> ...
> auth sufficient pam_u2f.so cue prompt authfile=.config/u2f/u2f_keys
> ...
> $ cat ~/.config/u2f/u2f_keys
> ms:aa...==,es256,+presence
> ms:bb...==,es256,+presence
If I exchange the entries, the corresponding other key works, i.e. its
definitively the first entry that works.
I would expect both keys to work
-- System Information:
Debian Release: trixie/sid
APT prefers testing
APT policy: (500, 'testing')
Architecture: amd64 (x86_64)
Kernel: Linux 6.6.15-amd64 (SMP w/12 CPU threads; PREEMPT)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8),
LANGUAGE=en_US:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
Versions of packages libpam-u2f depends on:
ii libc6 2.37-15
ii libfido2-1 1.14.0-1
ii libpam0g 1.5.2-9.1+b1
ii libssl3 3.1.5-1
Versions of packages libpam-u2f recommends:
ii pamu2fcfg 1.1.0-1.1+b1
libpam-u2f suggests no packages.
-- no debconf information
--- End Message ---
--- Begin Message ---
Hello Maximilian,
please have a look at the documentation again - i did the same error
initially, too:
According to your email this is your current setup:
> ms:aa...==,es256,+presence
> ms:bb...==,es256,+presence
Please switch to this layout:
ms:aa...==,es256,+presence:bb....==,es256,+presence
so basically there is just one line with both keys inside.
Please refer also to the upstream documentation here:
https://developers.yubico.com/pam-u2f/ (Section: Central Authorization
Mapping).
With best regards
Patrick
--
⢀⣴⠾⠻⢶⣦⠀
⣾⠁⢠⠒⠀⣿⡁ [email protected]/[email protected]
⢿⡄⠘⠷⠚⠋⠀ OpenPGP: 8D208172388840811B85DA1CC6D50A4188C70E43
⠈⠳⣄
The people who refer to the pandemic in the past tense and climate change in
the future tense are the reason everything is going to shit.
--- End Message ---