
The pam_pkcs11 module allows PAM supported systems to use X.509 certificates to authenticate logins. USB smart cards like Yubikey embed the reader, and work like regular PIV cards.Įach smart card is expected to contain an X.509 certificate and the corresponding private key to be used for authentication. $ sudo apt install opensc-pkcs11 libpam-pkcs11 pcscdĪny PIV or CAC smart card with the corresponding reader should be sufficient.

The following sections describe how to enable smart card authentication on Ubuntu. This provides a higher degree of security than single-factor authentication such as just using a password. To operate the owner must have the smart card and they must know the PIN to unlock the card.


Multi-node configuration with Docker-Composeĭistributed Replicated Block Device (DRBD)Īmong some of the popular uses for smart cards is the ability to control access to computer systems.
