LUKS breaks When using fido key with pin

Alistair MacCallum <[email protected]> Thu, 29 Jan 2026 14:48:27 +0000
Newsgroups dev.linux.lists.cryptsetup
Message-ID <ZRH2PF6D297230325546A167E9072E447698B9EA@ZRH2PF6D2972303.CHEP278.PROD.OUTLOOK.COM>
Hi,=0A=
=0A=
I'm having an issue getting my fido key to work with LUKs, at boot it promp=
ts me for the pin and user presence twice then fails instead of falling bac=
k to the password that's available. I have the same issue across 3 differen=
t laptops and 3 different Yubikeys. I'm also able to reproduce it on a clea=
n install. If I set it up without the PIN it works as expected, it's only w=
ith the PIN that it fails.=0A=
=0A=
System Details=0A=
- Ubuntu Server 24.03=0A=
- Using dracut instead of initramfs=A0=0A=
- FIDO key is a Yubikey 5C NFC=0A=
- Crypttab, udev rules and dracut conf I assume are correct as the fido key=
 works if enrolled without a PIN=0A=
- cryptsetup v2.7.0=0A=
- libfido2-1 v1.14.0=0A=
=0A=
=0A=
The command used to enroll the key was=A0=0A=
=0A=
sudo systemd-cryptenroll /dev/nvme0n1p3 --fido2-device=3Dauto --fido2-with-=
client-pin=3Dno --fido2-with-user-presence=3Dyes=0A=
=0A=
Any help would be greatly appreciated!=0A=
=0A=
=0A=
Kind Regards,=0A=
Alistair MacCallum=0A=
=0A=
=0A=
=0A=
=0A=
=0A=
=0A=
=0A=
=0A=
=0A=
=0A=