Re: LUKS breaks When using fido key with pin

Alistair MacCallum <[email protected]> Thu, 29 Jan 2026 15:40:05 +0000
Newsgroups dev.linux.lists.cryptsetup
Message-ID <ZRH2PF6D29723036834E04BED292E18C5EC8B9EA@ZRH2PF6D2972303.CHEP278.PROD.OUTLOOK.COM>
Ok, thanks for pointing me in the right direction, I'll try and ask over at=
 systemd.=0A=
=0A=
Kind Regards,=0A=
Alistair MacCallum=0A=
=0A=
=0A=
=0A=
=0A=
=0A=
=0A=
=0A=
=0A=
=0A=
=0A=
=0A=
=0A=
________________________________________=0A=
From:=A0Milan Broz <[email protected]>=0A=
Sent:=A029 January 2026 15:21=0A=
To:=A0Alistair MacCallum <[email protected]>; [email protected]=
.dev <[email protected]>=0A=
Subject:=A0Re: LUKS breaks When using fido key with pin=0A=
=A0=0A=
[You don't often get email from [email protected]. Learn why this is impo=
rtant at https://aka.ms/LearnAboutSenderIdentification=A0]=0A=
=0A=
On 1/29/26 3:48 PM, Alistair MacCallum wrote:=0A=
> I'm having an issue getting my fido key to work with LUKs, at boot it pro=
mpts me for the pin and user presence twice then fails instead of falling b=
ack to the password that's available. I have the same issue across 3 differ=
ent laptops and 3 different Yubikeys. I'm also able to reproduce it on a cl=
ean install. If I set it up without the PIN it works as expected, it's only=
 with the PIN that it fails.=0A=
=0A=
This activation logic is run by systemd utils (or other wrappers above cryp=
tsetup), so the best would be to ask in systemd forum or list.=0A=
=0A=
Also, 2.7.0 is old versions we no longer support upstream, so it would be b=
etter reporting this to Ubuntu (if they still support it).=0A=
=0A=
Milan=0A=
=0A=
>=0A=
> System Details=0A=
> - Ubuntu Server 24.03=0A=
> - Using dracut instead of initramfs=0A=
> - FIDO key is a Yubikey 5C NFC=0A=
> - Crypttab, udev rules and dracut conf I assume are correct as the fido k=
ey works if enrolled without a PIN=0A=
> - cryptsetup v2.7.0=0A=
> - libfido2-1 v1.14.0=0A=
>=0A=
>=0A=
> The command used to enroll the key was=0A=
>=0A=
> sudo systemd-cryptenroll /dev/nvme0n1p3 --fido2-device=3Dauto --fido2-wit=
h-client-pin=3Dno --fido2-with-user-presence=3Dyes=0A=
>=0A=
> Any help would be greatly appreciated!=0A=
>=0A=
>=0A=
> Kind Regards,=0A=
> Alistair MacCallum=0A=
>=0A=
>=0A=
>=0A=
>=0A=
>=0A=
>=0A=
>=0A=
>=0A=
>=0A=
>=0A=
>=0A=