What version of pam-u2f are you using?
pam-u2f 1.3.0
Official Extra repository on Arch Linux
What operating system are you using?
Arch
libfido2 1.14.0
What authenticator are you using?
$ fido2-token -I /dev/hidraw7
proto: 0x02
major: 0x01
minor: 0x00
build: 0x01
caps: 0x05 (wink, cbor, msg)
version strings: U2F_V2, FIDO_2_0, FIDO_2_1_PRE
extension strings: credBlob, credProtect, hmac-secret
transport strings: usb
algorithms: es256 (public-key), eddsa (public-key)
aaguid: e1a9618350164f24b55be3ae23614cc6
options: rk, up, uv, noplat, uvToken, credMgmt, bioEnroll, clientPin, platConfig, setMinPINLength, userVerificationMgmtPreview
fwversion: 0x1
maxmsgsiz: 2048
maxcredcntlst: 20
maxcredlen: 98
maxlargeblob: 1024
maxrpids in minpinlen: 10
minpinlen: 4
pin protocols: 1
pin retries: 7
pin change required: false
uv retries: 5
sensor type: 1 (touch)
max samples: 12
Problem description
When pam-u2f is configured with the device for 2FA with password, it takes two full minutes after entering the password for the device to ask me to touch it to authorize. I enabled debug and logged to a file, but there are no timestamps:
$ grep u2f /etc/pam.d/gdm-password
auth required pam_u2f.so nouserok origin=pam://r912 appid=pam://r912 debug debug_file=/var/log/pam_u2f_gdm.log
$ cat /var/log/pam_u2f_gdm.log
debug(pam_u2f): pam-u2f.c:95 (parse_cfg): called.
debug(pam_u2f): pam-u2f.c:96 (parse_cfg): flags 0 argc 5
debug(pam_u2f): pam-u2f.c:98 (parse_cfg): argv[0]=nouserok
debug(pam_u2f): pam-u2f.c:98 (parse_cfg): argv[1]=origin=pam://r912
debug(pam_u2f): pam-u2f.c:98 (parse_cfg): argv[2]=appid=pam://r912
debug(pam_u2f): pam-u2f.c:98 (parse_cfg): argv[3]=debug
debug(pam_u2f): pam-u2f.c:98 (parse_cfg): argv[4]=debug_file=/var/log/pam_u2f_gdm.log
debug(pam_u2f): pam-u2f.c:100 (parse_cfg): max_devices=0
debug(pam_u2f): pam-u2f.c:101 (parse_cfg): debug=1
debug(pam_u2f): pam-u2f.c:102 (parse_cfg): interactive=0
debug(pam_u2f): pam-u2f.c:103 (parse_cfg): cue=0
debug(pam_u2f): pam-u2f.c:104 (parse_cfg): nodetect=0
debug(pam_u2f): pam-u2f.c:105 (parse_cfg): userpresence=-1
debug(pam_u2f): pam-u2f.c:106 (parse_cfg): userverification=-1
debug(pam_u2f): pam-u2f.c:107 (parse_cfg): pinverification=-1
debug(pam_u2f): pam-u2f.c:108 (parse_cfg): manual=0
debug(pam_u2f): pam-u2f.c:109 (parse_cfg): nouserok=1
debug(pam_u2f): pam-u2f.c:110 (parse_cfg): openasuser=0
debug(pam_u2f): pam-u2f.c:111 (parse_cfg): alwaysok=0
debug(pam_u2f): pam-u2f.c:112 (parse_cfg): sshformat=0
debug(pam_u2f): pam-u2f.c:113 (parse_cfg): expand=0
debug(pam_u2f): pam-u2f.c:114 (parse_cfg): authfile=(null)
debug(pam_u2f): pam-u2f.c:115 (parse_cfg): authpending_file=(null)
debug(pam_u2f): pam-u2f.c:117 (parse_cfg): origin=pam://r912
debug(pam_u2f): pam-u2f.c:118 (parse_cfg): appid=pam://r912
debug(pam_u2f): pam-u2f.c:119 (parse_cfg): prompt=(null)
debug(pam_u2f): pam-u2f.c:227 (pam_sm_authenticate): Maximum devices number not set. Using default (24)
debug(pam_u2f): pam-u2f.c:250 (pam_sm_authenticate): Requesting authentication for user strykar
debug(pam_u2f): pam-u2f.c:261 (pam_sm_authenticate): Found user strykar
debug(pam_u2f): pam-u2f.c:262 (pam_sm_authenticate): Home directory for strykar is /home/strykar
debug(pam_u2f): pam-u2f.c:141 (resolve_authfile_path): Variable XDG_CONFIG_HOME is not set, using default
debug(pam_u2f): pam-u2f.c:288 (pam_sm_authenticate): Using authentication file /home/strykar/.config/Yubico/u2f_keys
debug(pam_u2f): pam-u2f.c:294 (pam_sm_authenticate): Dropping privileges
debug(pam_u2f): pam-u2f.c:300 (pam_sm_authenticate): Switched to uid 1000
debug(pam_u2f): util.c:227 (parse_native_format): Read 507 bytes
debug(pam_u2f): util.c:231 (parse_native_format): Matched user: strykar
debug(pam_u2f): util.c:254 (parse_native_format): KeyHandle for device number 1: XXXXX
debug(pam_u2f): util.c:256 (parse_native_format): publicKey for device number 1: XXXXX
debug(pam_u2f): util.c:258 (parse_native_format): COSE type for device number 1: es256
debug(pam_u2f): util.c:260 (parse_native_format): Attributes for device number 1: +presence
debug(pam_u2f): util.c:254 (parse_native_format): KeyHandle for device number 2: XXXXX
debug(pam_u2f): util.c:256 (parse_native_format): publicKey for device number 2: XXXXX
debug(pam_u2f): util.c:258 (parse_native_format): COSE type for device number 2: es256
debug(pam_u2f): util.c:260 (parse_native_format): Attributes for device number 2: +presence
debug(pam_u2f): util.c:753 (get_devices_from_authfile): Found 2 device(s) for user strykar
debug(pam_u2f): pam-u2f.c:310 (pam_sm_authenticate): Restored privileges
debug(pam_u2f): pam-u2f.c:360 (pam_sm_authenticate): Touch request notifications will be emitted via '/var/run/user/0/pam-u2f-authpending'
debug(pam_u2f): pam-u2f.c:369 (pam_sm_authenticate): Unable to emit 'authentication started' notification: No such file or directory
debug(pam_u2f): util.c:1172 (do_authentication): Device max index is 2
debug(pam_u2f): util.c:1188 (do_authentication): Attempting authentication with device number 1
debug(pam_u2f): util.c:991 (prepare_assert): Key handle: XXXXX
debug(pam_u2f): util.c:797 (get_authenticators): Working with 2 authenticator(s)
debug(pam_u2f): util.c:800 (get_authenticators): Checking whether key exists in authenticator 0
debug(pam_u2f): util.c:808 (get_authenticators): Authenticator path: /dev/hidraw3
debug(pam_u2f): util.c:835 (get_authenticators): Key not found in authenticator 0
debug(pam_u2f): util.c:800 (get_authenticators): Checking whether key exists in authenticator 1
debug(pam_u2f): util.c:808 (get_authenticators): Authenticator path: /dev/hidraw7
debug(pam_u2f): util.c:832 (get_authenticators): Found key in authenticator 1
debug(pam_u2f): pam-u2f.c:426 (pam_sm_authenticate): done. [Success]
Device is an AuthenTrend Technology Inc. ATKey.Pro
Should it be trying to emit via /var/run/user/0/pam-u2f-authpending instead of /var/run/user/1000/pam-u2f-authpending?
Is there a way to timestamp the debug log?
Any pointers to troubleshoot this would be much appreciated!
What version of pam-u2f are you using?
pam-u2f 1.3.0
Official Extra repository on Arch Linux
What operating system are you using?
Arch
libfido2 1.14.0
What authenticator are you using?
$ fido2-token -I /dev/hidraw7
proto: 0x02
major: 0x01
minor: 0x00
build: 0x01
caps: 0x05 (wink, cbor, msg)
version strings: U2F_V2, FIDO_2_0, FIDO_2_1_PRE
extension strings: credBlob, credProtect, hmac-secret
transport strings: usb
algorithms: es256 (public-key), eddsa (public-key)
aaguid: e1a9618350164f24b55be3ae23614cc6
options: rk, up, uv, noplat, uvToken, credMgmt, bioEnroll, clientPin, platConfig, setMinPINLength, userVerificationMgmtPreview
fwversion: 0x1
maxmsgsiz: 2048
maxcredcntlst: 20
maxcredlen: 98
maxlargeblob: 1024
maxrpids in minpinlen: 10
minpinlen: 4
pin protocols: 1
pin retries: 7
pin change required: false
uv retries: 5
sensor type: 1 (touch)
max samples: 12
Problem description
When pam-u2f is configured with the device for 2FA with password, it takes two full minutes after entering the password for the device to ask me to touch it to authorize. I enabled debug and logged to a file, but there are no timestamps:
Device is an AuthenTrend Technology Inc. ATKey.Pro
Should it be trying to emit via
/var/run/user/0/pam-u2f-authpendinginstead of/var/run/user/1000/pam-u2f-authpending?Is there a way to timestamp the debug log?
Any pointers to troubleshoot this would be much appreciated!