Re: LUKS breaks When using fido key with pin
Alistair MacCallum <[email protected]> Thu, 29 Jan 2026 15:40:05 +0000
| Newsgroups | dev.linux.lists.cryptsetup |
|---|---|
| Message-ID | <ZRH2PF6D29723036834E04BED292E18C5EC8B9EA@ZRH2PF6D2972303.CHEP278.PROD.OUTLOOK.COM> |
Ok, thanks for pointing me in the right direction, I'll try and ask over at= systemd.=0A= =0A= Kind Regards,=0A= Alistair MacCallum=0A= =0A= =0A= =0A= =0A= =0A= =0A= =0A= =0A= =0A= =0A= =0A= =0A= ________________________________________=0A= From:=A0Milan Broz <[email protected]>=0A= Sent:=A029 January 2026 15:21=0A= To:=A0Alistair MacCallum <[email protected]>; [email protected]= .dev <[email protected]>=0A= Subject:=A0Re: LUKS breaks When using fido key with pin=0A= =A0=0A= [You don't often get email from [email protected]. Learn why this is impo= rtant at https://aka.ms/LearnAboutSenderIdentification=A0]=0A= =0A= On 1/29/26 3:48 PM, Alistair MacCallum wrote:=0A= > I'm having an issue getting my fido key to work with LUKs, at boot it pro= mpts me for the pin and user presence twice then fails instead of falling b= ack to the password that's available. I have the same issue across 3 differ= ent laptops and 3 different Yubikeys. I'm also able to reproduce it on a cl= ean install. If I set it up without the PIN it works as expected, it's only= with the PIN that it fails.=0A= =0A= This activation logic is run by systemd utils (or other wrappers above cryp= tsetup), so the best would be to ask in systemd forum or list.=0A= =0A= Also, 2.7.0 is old versions we no longer support upstream, so it would be b= etter reporting this to Ubuntu (if they still support it).=0A= =0A= Milan=0A= =0A= >=0A= > System Details=0A= > - Ubuntu Server 24.03=0A= > - Using dracut instead of initramfs=0A= > - FIDO key is a Yubikey 5C NFC=0A= > - Crypttab, udev rules and dracut conf I assume are correct as the fido k= ey works if enrolled without a PIN=0A= > - cryptsetup v2.7.0=0A= > - libfido2-1 v1.14.0=0A= >=0A= >=0A= > The command used to enroll the key was=0A= >=0A= > sudo systemd-cryptenroll /dev/nvme0n1p3 --fido2-device=3Dauto --fido2-wit= h-client-pin=3Dno --fido2-with-user-presence=3Dyes=0A= >=0A= > Any help would be greatly appreciated!=0A= >=0A= >=0A= > Kind Regards,=0A= > Alistair MacCallum=0A= >=0A= >=0A= >=0A= >=0A= >=0A= >=0A= >=0A= >=0A= >=0A= >=0A= >=0A=