Skip to content

Pinpad card reader for login authentication yet you are asked also enter pin on pc keyboard #5371

Description

@ngpsteen

Hello Folks!

This is simply and announcement about one issue regarding pinpad smartcard reader where you are asked also to enter pin on the pc keyboard, mostly so it don't fall between chairs. I can arrange pinpad reader and smartcard if needed to solve this issue. It is okey to remove this issue if you like since it is also filed at bugzilla.redhat.com!

The opened bugzilla about the issue, with exact details on how it was setup step by step:
https://bugzilla.redhat.com/show_bug.cgi?id=1886841 and

Originally filed about the issue:
https://lists.fedorahosted.org/archives/list/[email protected]/thread/FLLIA5RLHT3MO4NI2F3MJNMBBNGGZA4Z/

Summary:
We are working on getting smart card authentication working using pinpad card readers for improved security.

To do this we use:
FreeIPA Server is running on Fedora 32 with latest updates.
FreeIPA Clients is Fedora 32 Workstation installed on pc with latest updates with connected usb card reader.

The card reader is Gemalto CT700 with pinpad, we use several user individual SmartCard HSM 4K with FreeIPA signed certificates on them. We have tested also other pinpads and smart cards on different PC:s and also laptops with builtin smartcard reader, with the same result, pinpad is working but you are asked to enter pin by PC keyboard as well, then you are logged in. Disabling pinpad in opensc.conf results you are logged in directly after entering pincode on pc keyboard.

FreeIPA Clients run OpenSC and are configured to use smartcard certificate based authentication, setup per Smart HSM best practice. All per default setup, no additional settings.

Further clients are using SSSD and not PAM_PKCS#11.
As a parentheses it is worth mentioning we used also centos7 and centos8 with same result as Fedora32, we have not tested Fedora33 or compiled SSSD from source, yet.

As even more distant parentheses and annoyingly enough, Ubuntu 20.04LTS actually works, but that uses PAM_PKCS#11 which is another technologies that does not live up to our needs.

Again, it is off-course perfectly okey to remove this report if you feel it is enough with the errata at redhat!

Thank you in advance!

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions