Conversation
There was a problem hiding this comment.
Code Review
This pull request introduces a new option, with-pam-u2f-priority, to prioritize U2F authentication over fingerprint authentication when both are enabled. This option is documented in the README and REQUIREMENTS files, and implemented in the system-auth PAM configuration. A review comment correctly points out that when both with-pam-u2f and with-pam-u2f-priority are enabled, pam_u2f.so will be included twice in the PAM stack. To avoid this duplicate entry, the second pam_u2f.so line should be updated to only be included if with-pam-u2f-priority is not enabled.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
| auth [success=done ignore=ignore default=die] pam_sss.so require_cert_auth ignore_authinfo_unavail {include if "with-smartcard-required"} | ||
| auth sufficient pam_u2f.so cue {include if "with-pam-u2f" and "with-pam-u2f-priority"} | ||
| auth sufficient pam_fprintd.so {include if "with-fingerprint"} | ||
| auth sufficient pam_u2f.so cue {include if "with-pam-u2f"} |
There was a problem hiding this comment.
When both with-pam-u2f and with-pam-u2f-priority are enabled, pam_u2f.so will be included twice in the PAM stack (at line 7 and line 9). To prevent this duplicate entry, line 9 should only be included if with-pam-u2f is enabled and with-pam-u2f-priority is not enabled.
auth sufficient pam_u2f.so cue {include if "with-pam-u2f" and not "with-pam-u2f-priority"}
There was a problem hiding this comment.
I didn't notice this issue yet during my tests on RHEL 9.6.
This patch adds a new optional feature 'with-pam-u2f-priority' that allows users to prioritize U2F hardware token authentication before fingerprint authentication i.e. pam_u2f.so module will be added before pam_fprintd.so module in system-auth file for supported authselect profiles. Fixes: authselect#335 Signed-off-by: Akshay Sakure <asakure@redhat.com>
cb7f31f to
216a89e
Compare
This patch adds a new optional feature 'with-pam-u2f-priority' that allows users to prioritize U2F hardware token authentication before fingerprint authentication i.e. pam_u2f.so module will be added before pam_fprintd.so module in system-auth file.
Fixes: #335