Your message dated Fri, 5 Apr 2024 22:55:51 +0200
with message-id <[email protected]>
and subject line Please reconfigure your u2f file
has caused the Debian Bug report #1067090,
regarding libpam-u2f: Only first key is checked in authfile
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1067090: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067090
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: libpam-u2f
Version: 1.1.0-1.1+b1
Severity: normal
X-Debbugs-Cc: [email protected]

Dear Maintainer,

after enrolling multiple keys in my u2f_keys file only the first one is checked
by libpam-u2f.

> $ cat /etc/pam.d/sudo
> ...
> auth sufficient pam_u2f.so cue prompt authfile=.config/u2f/u2f_keys
> ...

> $ cat ~/.config/u2f/u2f_keys
> ms:aa...==,es256,+presence
> ms:bb...==,es256,+presence

If I exchange the entries, the corresponding other key works, i.e. its
definitively the first entry that works.
I would expect both keys to work


-- System Information:
Debian Release: trixie/sid
APT prefers testing
APT policy: (500, 'testing')
Architecture: amd64 (x86_64)

Kernel: Linux 6.6.15-amd64 (SMP w/12 CPU threads; PREEMPT)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE=en_US:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages libpam-u2f depends on:
ii libc6 2.37-15
ii libfido2-1 1.14.0-1
ii libpam0g 1.5.2-9.1+b1
ii libssl3 3.1.5-1

Versions of packages libpam-u2f recommends:
ii pamu2fcfg 1.1.0-1.1+b1

libpam-u2f suggests no packages.

-- no debconf information

--- End Message ---
--- Begin Message ---
Hello Maximilian,

please have a look at the documentation again - i did the same error initially, too:

According to your email this is your current setup:

> ms:aa...==,es256,+presence
> ms:bb...==,es256,+presence

Please switch to this layout:

ms:aa...==,es256,+presence:bb....==,es256,+presence

so basically there is just one line with both keys inside.

Please refer also to the upstream documentation here:
https://developers.yubico.com/pam-u2f/ (Section: Central Authorization Mapping).

With best regards
Patrick
--

 ⢀⣴⠾⠻⢶⣦⠀
 ⣾⠁⢠⠒⠀⣿⡁  [email protected]/[email protected]
 ⢿⡄⠘⠷⠚⠋⠀  OpenPGP: 8D208172388840811B85DA1CC6D50A4188C70E43
 ⠈⠳⣄

The people who refer to the pandemic in the past tense and climate change in
the future tense are the reason everything is going to shit.

--- End Message ---

Reply via email to