Sitelet https://github.com/authselect/authselect/pull/455/files
Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions profiles/local/README
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,11 @@ with-pam-u2f::
with-pam-u2f-2fa::
Enable 2nd factor authentication via u2f dongle through *pam_u2f*.

with-pam-u2f-priority::
Prioritize U2F authentication before fingerprint when both
with-fingerprint and with-pam-u2f are enabled. This avoids delays
when a U2F hardware token is already connected.

without-pam-u2f-nouserok::
Module argument nouserok is omitted if also with-pam-u2f-2fa is used.
*WARNING*: Omitting nouserok argument means that users without pam-u2f
Expand Down
3 changes: 3 additions & 0 deletions profiles/local/REQUIREMENTS
Original file line number Diff line number Diff line change
Expand Up @@ -19,3 +19,6 @@
{include if "with-pam-u2f-2fa"}
- with-pam-u2f-2fa is selected, make sure that the pam u2f module is installed {include if "with-pam-u2f-2fa"}
- users can then configure keys using the pamu2fcfg tool {include if "with-pam-u2f-2fa"}
{include if "with-pam-u2f-priority"}
- with-pam-u2f-priority is selected, pam_u2f.so module will take preference over {include if "with-pam-u2f-priority"}
pam_fprintd.so module in system-auth file. {include if "with-pam-u2f-priority"}
1 change: 1 addition & 0 deletions profiles/local/system-auth
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@ auth required pam_env.so
auth required pam_faildelay.so delay=2000000
auth required pam_faillock.so preauth silent {include if "with-faillock"}
auth sufficient pam_fprintd.so {include if "with-fingerprint"}
auth sufficient pam_u2f.so cue {include if "with-pam-u2f" and "with-pam-u2f-priority"}
auth sufficient pam_u2f.so cue {include if "with-pam-u2f"}
auth required pam_u2f.so cue {if not "without-pam-u2f-nouserok":nouserok} {include if "with-pam-u2f-2fa"}
-auth [success=done authtok_err=bad perm_denied=bad maxtries=bad default=ignore] pam_systemd_home.so {include if "with-systemd-homed"}
Expand Down
5 changes: 5 additions & 0 deletions profiles/nis/README
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,11 @@ with-pam-u2f::
with-pam-u2f-2fa::
Enable 2nd factor authentication via u2f dongle through *pam_u2f*.

with-pam-u2f-priority::
Prioritize U2F authentication before fingerprint when both
with-fingerprint and with-pam-u2f are enabled. This avoids delays
when a U2F hardware token is already connected.

without-pam-u2f-nouserok::
Module argument nouserok is omitted if also with-pam-u2f-2fa is used.
*WARNING*: Omitting nouserok argument means that users without pam-u2f
Expand Down
3 changes: 3 additions & 0 deletions profiles/nis/REQUIREMENTS
Original file line number Diff line number Diff line change
Expand Up @@ -19,3 +19,6 @@ Make sure that NIS service is configured and enabled. See NIS documentation for
{include if "with-systemd-homed"}
- with-systemd-homed is selected, make sure that the system-homed service is enabled {include if "with-systemd-homed"}
- systemctl enable --now systemd-homed.service {include if "with-systemd-homed"}
{include if "with-pam-u2f-priority"}
- with-pam-u2f-priority is selected, pam_u2f.so module will take preference over {include if "with-pam-u2f-priority"}
pam_fprintd.so module in system-auth file. {include if "with-pam-u2f-priority"}
1 change: 1 addition & 0 deletions profiles/nis/system-auth
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@ auth required pam_env.so
auth required pam_faildelay.so delay=2000000
auth required pam_faillock.so preauth silent {include if "with-faillock"}
auth sufficient pam_fprintd.so {include if "with-fingerprint"}
auth sufficient pam_u2f.so cue {include if "with-pam-u2f" and "with-pam-u2f-priority"}
auth sufficient pam_u2f.so cue {include if "with-pam-u2f"}
auth required pam_u2f.so cue {if not "without-pam-u2f-nouserok":nouserok} {include if "with-pam-u2f-2fa"}
-auth [success=done authtok_err=bad perm_denied=bad maxtries=bad default=ignore] pam_systemd_home.so {include if "with-systemd-homed"}
Expand Down
5 changes: 5 additions & 0 deletions profiles/sssd/README
Original file line number Diff line number Diff line change
Expand Up @@ -62,6 +62,11 @@ with-pam-u2f::
with-pam-u2f-2fa::
Enable 2nd factor authentication via u2f dongle through *pam_u2f*.

with-pam-u2f-priority::
Prioritize U2F authentication before fingerprint when both
with-fingerprint and with-pam-u2f are enabled. This avoids delays
when a U2F hardware token is already connected.

without-pam-u2f-nouserok::
Module argument nouserok is omitted if also with-pam-u2f-2fa is used.
*WARNING*: Omitting nouserok argument means that users without pam-u2f
Expand Down
3 changes: 3 additions & 0 deletions profiles/sssd/REQUIREMENTS
Original file line number Diff line number Diff line change
Expand Up @@ -35,3 +35,6 @@ Make sure that SSSD service is configured and enabled. See SSSD documentation fo
- with-gpupdate is selected, make sure pam_oddjob_gpupdate module {include if "with-gpupdate"}
and samba-gpupdate are present and oddjobd service is enabled and active {include if "with-gpupdate"}
- systemctl enable --now oddjobd.service {include if "with-gpupdate"}
{include if "with-pam-u2f-priority"}
- with-pam-u2f-priority is selected, pam_u2f.so module will take preference over {include if "with-pam-u2f-priority"}
pam_fprintd.so module in system-auth file. {include if "with-pam-u2f-priority"}
1 change: 1 addition & 0 deletions profiles/sssd/system-auth
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@ auth required pam_faildelay.so delay=
auth required pam_faillock.so preauth silent {include if "with-faillock"}
auth [success=1 default=ignore] pam_succeed_if.so service notin login:gdm:xdm:kdm:kde:xscreensaver:gnome-screensaver:kscreensaver quiet use_uid {include if "with-smartcard-required"}
auth [success=done ignore=ignore default=die] pam_sss.so require_cert_auth ignore_authinfo_unavail {include if "with-smartcard-required"}
auth sufficient pam_u2f.so cue {include if "with-pam-u2f" and "with-pam-u2f-priority"}
auth sufficient pam_fprintd.so {include if "with-fingerprint"}
auth sufficient pam_u2f.so cue {include if "with-pam-u2f"}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

When both with-pam-u2f and with-pam-u2f-priority are enabled, pam_u2f.so will be included twice in the PAM stack (at line 7 and line 9). To prevent this duplicate entry, line 9 should only be included if with-pam-u2f is enabled and with-pam-u2f-priority is not enabled.

auth        sufficient                                   pam_u2f.so cue                                         {include if "with-pam-u2f" and not "with-pam-u2f-priority"}

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I didn't notice this issue yet during my tests on RHEL 9.6.

auth required pam_u2f.so cue {if not "without-pam-u2f-nouserok":nouserok} {include if "with-pam-u2f-2fa"}
Expand Down
5 changes: 5 additions & 0 deletions profiles/winbind/README
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,11 @@ with-pam-u2f::
with-pam-u2f-2fa::
Enable 2nd factor authentication via u2f dongle through *pam_u2f*.

with-pam-u2f-priority::
Prioritize U2F authentication before fingerprint when both
with-fingerprint and with-pam-u2f are enabled. This avoids delays
when a U2F hardware token is already connected.

without-pam-u2f-nouserok::
Module argument nouserok is omitted if also with-pam-u2f-2fa is used.
*WARNING*: Omitting nouserok argument means that users without pam-u2f
Expand Down
3 changes: 3 additions & 0 deletions profiles/winbind/REQUIREMENTS
Original file line number Diff line number Diff line change
Expand Up @@ -19,3 +19,6 @@ Make sure that winbind service is configured and enabled. See winbind documentat
{include if "with-systemd-homed"}
- with-systemd-homed is selected, make sure that the system-homed service is enabled {include if "with-systemd-homed"}
- systemctl enable --now systemd-homed.service {include if "with-systemd-homed"}
{include if "with-pam-u2f-priority"}
- with-pam-u2f-priority is selected, pam_u2f.so module will take preference over {include if "with-pam-u2f-priority"}
pam_fprintd.so module in system-auth file. {include if "with-pam-u2f-priority"}
1 change: 1 addition & 0 deletions profiles/winbind/system-auth
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@ auth required pam_env.so
auth required pam_faildelay.so delay=2000000
auth required pam_faillock.so preauth silent {include if "with-faillock"}
auth sufficient pam_fprintd.so {include if "with-fingerprint"}
auth sufficient pam_u2f.so cue {include if "with-pam-u2f" and "with-pam-u2f-priority"}
auth sufficient pam_u2f.so cue {include if "with-pam-u2f"}
auth required pam_u2f.so cue {if not "without-pam-u2f-nouserok":nouserok} {include if "with-pam-u2f-2fa"}
-auth [success=done authtok_err=bad perm_denied=bad maxtries=bad default=ignore] pam_systemd_home.so {include if "with-systemd-homed"}
Expand Down