libpam-duo need to be upgraded before Feb 2 2026

Bug #2137605 reported by Kevin Swab
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
duo-unix (Debian)
New
Unknown
duo-unix (Ubuntu)
New
Undecided
Unassigned

Bug Description

Duo announced the expiration of a certificate bundle by Feb 2nd, 2026. All systems must be upgraded to at least version 2.1.0 by then or authentication may fail. Current version provided by libpam-duo package is 1.11.3 on 24.04 LTS and 22.04 LTS.

Can be worked around by using Duo's package repo, but packages have different names and the config file is in a different directory.

Link to Advisory:

https://help.duo.com/s/article/9451?language=en_US#duounix

# lsb_release -rd
Description: Ubuntu 22.04.5 LTS
Release: 22.04

# apt-cache policy libpam-duo
libpam-duo:
  Installed: 1.11.3-1build1
  Candidate: 1.11.3-1build1

ProblemType: Bug
DistroRelease: Ubuntu 24.04
Package: libpam-duo 1.11.3-1.1build2
ProcVersionSignature: Ubuntu 6.8.0-57.59-generic 6.8.12
Uname: Linux 6.8.0-57-generic x86_64
ApportVersion: 2.28.1-0ubuntu3.5
Architecture: amd64
CasperMD5CheckResult: pass
Date: Tue Jan 6 16:31:26 2026
InstallationDate: Installed on 2025-01-28 (343 days ago)
InstallationMedia: Ubuntu-Server 24.04.1 LTS "Noble Numbat" - Release amd64 (20240827)
ProcEnviron:
 LANG=en_US.UTF-8
 PATH=(custom, no user)
 SHELL=/bin/bash
 TERM=xterm
SourcePackage: duo-unix
UpgradeStatus: No upgrade log present (probably fresh install)
modified.conffile..etc.security.pam_duo.conf: [modified]
mtime.conffile..etc.security.pam_duo.conf: 2025-04-09T14:29:52.644999

Revision history for this message
Kevin Swab (kevinscsu) wrote :
Changed in duo-unix (Debian):
status: Unknown → New
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.