Skip to content

GDM login takes two minutes for U2F cue to appear on device after password entry #310

Description

@Strykar

What version of pam-u2f are you using?

pam-u2f 1.3.0

Official Extra repository on Arch Linux

What operating system are you using?

Arch

libfido2 1.14.0

What authenticator are you using?

$ fido2-token -I /dev/hidraw7
proto: 0x02
major: 0x01
minor: 0x00
build: 0x01
caps: 0x05 (wink, cbor, msg)
version strings: U2F_V2, FIDO_2_0, FIDO_2_1_PRE
extension strings: credBlob, credProtect, hmac-secret
transport strings: usb
algorithms: es256 (public-key), eddsa (public-key)
aaguid: e1a9618350164f24b55be3ae23614cc6
options: rk, up, uv, noplat, uvToken, credMgmt, bioEnroll, clientPin, platConfig, setMinPINLength, userVerificationMgmtPreview
fwversion: 0x1
maxmsgsiz: 2048
maxcredcntlst: 20
maxcredlen: 98
maxlargeblob: 1024
maxrpids in minpinlen: 10
minpinlen: 4
pin protocols: 1
pin retries: 7
pin change required: false
uv retries: 5
sensor type: 1 (touch)
max samples: 12

Problem description

When pam-u2f is configured with the device for 2FA with password, it takes two full minutes after entering the password for the device to ask me to touch it to authorize. I enabled debug and logged to a file, but there are no timestamps:

$ grep u2f /etc/pam.d/gdm-password 
auth  required  pam_u2f.so nouserok origin=pam://r912 appid=pam://r912 debug debug_file=/var/log/pam_u2f_gdm.log

$ cat /var/log/pam_u2f_gdm.log 
debug(pam_u2f): pam-u2f.c:95 (parse_cfg): called.
debug(pam_u2f): pam-u2f.c:96 (parse_cfg): flags 0 argc 5
debug(pam_u2f): pam-u2f.c:98 (parse_cfg): argv[0]=nouserok
debug(pam_u2f): pam-u2f.c:98 (parse_cfg): argv[1]=origin=pam://r912
debug(pam_u2f): pam-u2f.c:98 (parse_cfg): argv[2]=appid=pam://r912
debug(pam_u2f): pam-u2f.c:98 (parse_cfg): argv[3]=debug
debug(pam_u2f): pam-u2f.c:98 (parse_cfg): argv[4]=debug_file=/var/log/pam_u2f_gdm.log
debug(pam_u2f): pam-u2f.c:100 (parse_cfg): max_devices=0
debug(pam_u2f): pam-u2f.c:101 (parse_cfg): debug=1
debug(pam_u2f): pam-u2f.c:102 (parse_cfg): interactive=0
debug(pam_u2f): pam-u2f.c:103 (parse_cfg): cue=0
debug(pam_u2f): pam-u2f.c:104 (parse_cfg): nodetect=0
debug(pam_u2f): pam-u2f.c:105 (parse_cfg): userpresence=-1
debug(pam_u2f): pam-u2f.c:106 (parse_cfg): userverification=-1
debug(pam_u2f): pam-u2f.c:107 (parse_cfg): pinverification=-1
debug(pam_u2f): pam-u2f.c:108 (parse_cfg): manual=0
debug(pam_u2f): pam-u2f.c:109 (parse_cfg): nouserok=1
debug(pam_u2f): pam-u2f.c:110 (parse_cfg): openasuser=0
debug(pam_u2f): pam-u2f.c:111 (parse_cfg): alwaysok=0
debug(pam_u2f): pam-u2f.c:112 (parse_cfg): sshformat=0
debug(pam_u2f): pam-u2f.c:113 (parse_cfg): expand=0
debug(pam_u2f): pam-u2f.c:114 (parse_cfg): authfile=(null)
debug(pam_u2f): pam-u2f.c:115 (parse_cfg): authpending_file=(null)
debug(pam_u2f): pam-u2f.c:117 (parse_cfg): origin=pam://r912
debug(pam_u2f): pam-u2f.c:118 (parse_cfg): appid=pam://r912
debug(pam_u2f): pam-u2f.c:119 (parse_cfg): prompt=(null)
debug(pam_u2f): pam-u2f.c:227 (pam_sm_authenticate): Maximum devices number not set. Using default (24)
debug(pam_u2f): pam-u2f.c:250 (pam_sm_authenticate): Requesting authentication for user strykar
debug(pam_u2f): pam-u2f.c:261 (pam_sm_authenticate): Found user strykar
debug(pam_u2f): pam-u2f.c:262 (pam_sm_authenticate): Home directory for strykar is /home/strykar
debug(pam_u2f): pam-u2f.c:141 (resolve_authfile_path): Variable XDG_CONFIG_HOME is not set, using default
debug(pam_u2f): pam-u2f.c:288 (pam_sm_authenticate): Using authentication file /home/strykar/.config/Yubico/u2f_keys
debug(pam_u2f): pam-u2f.c:294 (pam_sm_authenticate): Dropping privileges
debug(pam_u2f): pam-u2f.c:300 (pam_sm_authenticate): Switched to uid 1000
debug(pam_u2f): util.c:227 (parse_native_format): Read 507 bytes
debug(pam_u2f): util.c:231 (parse_native_format): Matched user: strykar
debug(pam_u2f): util.c:254 (parse_native_format): KeyHandle for device number 1: XXXXX
debug(pam_u2f): util.c:256 (parse_native_format): publicKey for device number 1: XXXXX
debug(pam_u2f): util.c:258 (parse_native_format): COSE type for device number 1: es256
debug(pam_u2f): util.c:260 (parse_native_format): Attributes for device number 1: +presence
debug(pam_u2f): util.c:254 (parse_native_format): KeyHandle for device number 2: XXXXX
debug(pam_u2f): util.c:256 (parse_native_format): publicKey for device number 2: XXXXX
debug(pam_u2f): util.c:258 (parse_native_format): COSE type for device number 2: es256
debug(pam_u2f): util.c:260 (parse_native_format): Attributes for device number 2: +presence
debug(pam_u2f): util.c:753 (get_devices_from_authfile): Found 2 device(s) for user strykar
debug(pam_u2f): pam-u2f.c:310 (pam_sm_authenticate): Restored privileges
debug(pam_u2f): pam-u2f.c:360 (pam_sm_authenticate): Touch request notifications will be emitted via '/var/run/user/0/pam-u2f-authpending'
debug(pam_u2f): pam-u2f.c:369 (pam_sm_authenticate): Unable to emit 'authentication started' notification: No such file or directory
debug(pam_u2f): util.c:1172 (do_authentication): Device max index is 2
debug(pam_u2f): util.c:1188 (do_authentication): Attempting authentication with device number 1
debug(pam_u2f): util.c:991 (prepare_assert): Key handle: XXXXX
debug(pam_u2f): util.c:797 (get_authenticators): Working with 2 authenticator(s)
debug(pam_u2f): util.c:800 (get_authenticators): Checking whether key exists in authenticator 0
debug(pam_u2f): util.c:808 (get_authenticators): Authenticator path: /dev/hidraw3
debug(pam_u2f): util.c:835 (get_authenticators): Key not found in authenticator 0
debug(pam_u2f): util.c:800 (get_authenticators): Checking whether key exists in authenticator 1
debug(pam_u2f): util.c:808 (get_authenticators): Authenticator path: /dev/hidraw7
debug(pam_u2f): util.c:832 (get_authenticators): Found key in authenticator 1
debug(pam_u2f): pam-u2f.c:426 (pam_sm_authenticate): done. [Success]

Device is an AuthenTrend Technology Inc. ATKey.Pro
Should it be trying to emit via /var/run/user/0/pam-u2f-authpending instead of /var/run/user/1000/pam-u2f-authpending?
Is there a way to timestamp the debug log?

Any pointers to troubleshoot this would be much appreciated!

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions