New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fingerprint auth should not be enabled for sudo #207
Comments
|
I've definitely used it for sudo. Much better than |
|
It is a bad idea. It completely breaks e.g. remoting in through ssh and it also doesn't really proof as much as a password does. |
|
Seems like we need a pam module to detect local console auth vs remote |
|
@benzea Do you use fprintd for other services? Or you don't use it at all? |
|
I don't use fingerprint authentication at all ;-) But, if I used it, I would expect it to only work from my graphical session. And, really, I would want policy to only allow unlock if other conditions are met (such policy does not exist obviously). |
|
@benzea You can call I discussed this with @t8m and it looks like best option will be to modify |
That's already fixed, we check for local systemd sessions since the sd-bus port. |
|
Sweet! @hadess Is it already released? |
|
Since January this year. It's in Fedora 32 now. |
|
Thank you. Therefore I'm inclining to close this thread since for me the issue was that sudo is delayed by fingerprint on ssh sessions. @benzea If you feel that sudo-fingerprint support should be optional with fingerprint enabled, can you please open a thread on fedora-devel and see what the community has to say about it? |
Fingerprint auth really doesn't make any sense for sudo (it is pretty harmful there). I doubt it should be enabled for anything but graphical logins.
The text was updated successfully, but these errors were encountered: