Created attachment 510960 [details] Login output from tty1 Description of problem: The packaged version of this pam module leaks debug information even when debug mode is disabled. This leaks all yubikey IDs associated to a successful matched user. Version-Release number of selected component (if applicable): pam_yubico-2.4-2.fc15 How reproducible: Always Steps to Reproduce: 1. Edit /etc/pam.d/login to add before system-auth: auth required pam_yubico.so id=16 authfile=/etc/yubikeys 2. Login from console Actual results: Debug output emitted Expected results: Debug output not emitted Additional info: This is already fixed upstream in 2.5.
Package update request submitted.
Here are the updated packages: Spec URL: http://repo.fuzzie.sg/fedora/specs/pam_yubico.spec SRPM URL: http://repo.fuzzie.sg/fedora/srpm/pam_yubico-2.7-1.fc15.src.rpm Spec URL: http://repo.fuzzie.sg/fedora/specs/ykclient.spec SRPM URL: http://repo.fuzzie.sg/fedora/srpm/ykclient-2.6-1.fc15.src.rpm Spec URL: http://repo.fuzzie.sg/fedora/specs/ykpers.spec SRPM URL: http://repo.fuzzie.sg/fedora/srpm/ykpers-1.5.2-1.fc15.src.rpm