Score:0

How to enable Yubikey 2FA using pam_u2f, for gnome desktop privilege elevation?

mx flag

Yubico's own docs do a pretty great job of documenting the process for enabling 2FA for pretty much every privilege escalation scenario (sudo from a terminal, gdm login, etc.):

https://support.yubico.com/hc/en-us/articles/360016649099-Ubuntu-Linux-Login-Guide-U2F

However, they don't cover the full-screen privilege escalation overlay that appears when you do something on the desktop that requires higher privileges. This is a glaring omission for the application of system-wide 2FA from their docs. I'm hoping someone here might know how to enable 2FA using pam_u2f for this use case? Thanks in advance. :-)

David avatar
cn flag
Seems like that is a question you should be asking yubico support.
Score:0
tm flag

The file you want to edit is /etc/pam.d/polkit-1

Adding your auth statement in this file will allow Yubikey prompts on auth dialogs such as using the package manager or partition manager for example.

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.