LUKS breaks When using fido key with pin
Alistair MacCallum <[email protected]> Thu, 29 Jan 2026 14:48:27 +0000
| Newsgroups | dev.linux.lists.cryptsetup |
|---|---|
| Message-ID | <ZRH2PF6D297230325546A167E9072E447698B9EA@ZRH2PF6D2972303.CHEP278.PROD.OUTLOOK.COM> |
Hi,=0A= =0A= I'm having an issue getting my fido key to work with LUKs, at boot it promp= ts me for the pin and user presence twice then fails instead of falling bac= k to the password that's available. I have the same issue across 3 differen= t laptops and 3 different Yubikeys. I'm also able to reproduce it on a clea= n install. If I set it up without the PIN it works as expected, it's only w= ith the PIN that it fails.=0A= =0A= System Details=0A= - Ubuntu Server 24.03=0A= - Using dracut instead of initramfs=A0=0A= - FIDO key is a Yubikey 5C NFC=0A= - Crypttab, udev rules and dracut conf I assume are correct as the fido key= works if enrolled without a PIN=0A= - cryptsetup v2.7.0=0A= - libfido2-1 v1.14.0=0A= =0A= =0A= The command used to enroll the key was=A0=0A= =0A= sudo systemd-cryptenroll /dev/nvme0n1p3 --fido2-device=3Dauto --fido2-with-= client-pin=3Dno --fido2-with-user-presence=3Dyes=0A= =0A= Any help would be greatly appreciated!=0A= =0A= =0A= Kind Regards,=0A= Alistair MacCallum=0A= =0A= =0A= =0A= =0A= =0A= =0A= =0A= =0A= =0A= =0A=