

If you do not have a backup device available at this time, you can add one later using the steps below as long as you still have access to your account. If you have backup devices, use the steps below to associate them with your account.

For more information on the issue, please see the Yubico security advisory here. Most Linux users will want to update via their distribution's package manager (APT, in the case of Ubuntu), but the source code for 1.1.1 is also available on. It is recommended that all users of pam-u2f update to version 1.1.1, which addresses this issue. Note: Although this guide does not cover configuring pam-u2f to require PIN authentication, note that there is a logic issue in pam-u2f 1.1.0 that, depending on the configuration and the application used, could lead to a local PIN bypass.
