Sitelet https://github.com/authselect/authselect/pull/455
Skip to content

Add feature to prioritise pam_u2f over pam_fprintd - #455

Open
asakure wants to merge 1 commit into
authselect:masterfrom
asakure:change_pam_u2f_order
Open

asakure wants to merge 1 commit into
authselect:masterfrom
asakure:change_pam_u2f_order

Conversation

@asakure

@asakure asakure commented Jun 3, 2026

Copy link
Copy Markdown
Contributor

This patch adds a new optional feature 'with-pam-u2f-priority' that allows users to prioritize U2F hardware token authentication before fingerprint authentication i.e. pam_u2f.so module will be added before pam_fprintd.so module in system-auth file.

Fixes: #335

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a new option, with-pam-u2f-priority, to prioritize U2F authentication over fingerprint authentication when both are enabled. This option is documented in the README and REQUIREMENTS files, and implemented in the system-auth PAM configuration. A review comment correctly points out that when both with-pam-u2f and with-pam-u2f-priority are enabled, pam_u2f.so will be included twice in the PAM stack. To avoid this duplicate entry, the second pam_u2f.so line should be updated to only be included if with-pam-u2f-priority is not enabled.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread profiles/sssd/system-auth
auth [success=done ignore=ignore default=die] pam_sss.so require_cert_auth ignore_authinfo_unavail {include if "with-smartcard-required"}
auth sufficient pam_u2f.so cue {include if "with-pam-u2f" and "with-pam-u2f-priority"}
auth sufficient pam_fprintd.so {include if "with-fingerprint"}
auth sufficient pam_u2f.so cue {include if "with-pam-u2f"}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

When both with-pam-u2f and with-pam-u2f-priority are enabled, pam_u2f.so will be included twice in the PAM stack (at line 7 and line 9). To prevent this duplicate entry, line 9 should only be included if with-pam-u2f is enabled and with-pam-u2f-priority is not enabled.

auth        sufficient                                   pam_u2f.so cue                                         {include if "with-pam-u2f" and not "with-pam-u2f-priority"}

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I didn't notice this issue yet during my tests on RHEL 9.6.

@asakure asakure changed the title Add feature to priortise pam_u2f over pam_fprintd Add feature to prioritise pam_u2f over pam_fprintd Jun 3, 2026
This patch adds a new optional feature 'with-pam-u2f-priority'
that allows users to prioritize U2F hardware token authentication
before fingerprint authentication i.e. pam_u2f.so module will be
added before pam_fprintd.so module in system-auth file for
supported authselect profiles.

Fixes: authselect#335
Signed-off-by: Akshay Sakure <asakure@redhat.com>
@asakure
asakure force-pushed the change_pam_u2f_order branch from cb7f31f to 216a89e Compare June 26, 2026 11:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Control the order of auth sufficient in pam

1 participant