Using a FIDO2 Security Key for Login on Linux
You don't need a YubiKey to log in to Linux with a hardware key. Any FIDO2/U2F key works with pam_u2f, including cheaper options like the Thetis Nano-A (USB-A, FIDO certified, 200 passkey slots). This post covers the setup for login, sudo and the lock screen. For this example I will utilise Linux Mint, a Debian based distribution, but the same will be true for all Linux variants, just the install commands will differ.
1. Install and register the key
sudo apt install libpam-u2f libu2f-udev
mkdir -p ~/.config/Yubico
pamu2fcfg > ~/.config/Yubico/u2f_keys
Touch the key when it blinks. If pamu2fcfg prints a line of output, the key works and you can carry on. If it can't see the key, replug it after installing libu2f-udev.
Register a second key as a backup. Losing your only key can lock you out:
pamu2fcfg -n >> ~/.config/Yubico/u2f_keys
2. Enable it in PAM
Back up first, and keep a root terminal open while testing:
sudo cp /etc/pam.d/common-auth /etc/pam.d/common-auth.bak
sudo nano /etc/pam.d/common-auth
Add this line at the top:
auth sufficient pam_u2f.so cue
sufficient: touching the key logs you in, and your password still works as a fallback.required, placed after thepam_unix.soline: password and key, which is true 2FA.
common-auth covers login, sudo and the lock screen. To limit it to one thing, edit /etc/pam.d/sudo or /etc/pam.d/lightdm instead.
Caveats
- LUKS disk unlock: this doesn't unlock an encrypted disk at boot. That needs
systemd-cryptenrollwith FIDO2, which is a separate setup. - Nano keys: a key that stays plugged in all day gives little protection against someone with physical access. Unplug it when you walk away.
- USB-A only: if your laptop only has USB-C you'll need an adapter.
Encrypted home directory: the key file in ~/.config isn't readable before login. Store it centrally instead:
sudo mkdir -p /etc/Yubico
pamu2fcfg | sudo tee /etc/Yubico/u2f_keys
Then use auth sufficient pam_u2f.so cue authfile=/etc/Yubico/u2f_keys.
Buy two keys, test in a spare terminal before you log out, and keep the .bak file handy.
I use this method to have a quick, easy method to authorise sudo required auth and screen lock access, not for full security as my desktop doesn't use encrypted drives. However if I was using Linux on the road, on a laptop, I would for sure use two factor authentication...a strong password and a FIDO2 key for authentication and security isolation.