Using a FIDO2 Security Key for Login on Linux

Using a FIDO2 Security Key for Login on Linux

You don't need a YubiKey to log in to Linux with a hardware key. Any FIDO2/U2F key works with pam_u2f, including cheaper options like the Thetis Nano-A (USB-A, FIDO certified, 200 passkey slots). This post covers the setup for login, sudo and the lock screen. For this example I will utilise Linux Mint, a Debian based distribution, but the same will be true for all Linux variants, just the install commands will differ.

1. Install and register the key

sudo apt install libpam-u2f libu2f-udev

mkdir -p ~/.config/Yubico
pamu2fcfg > ~/.config/Yubico/u2f_keys

Touch the key when it blinks. If pamu2fcfg prints a line of output, the key works and you can carry on. If it can't see the key, replug it after installing libu2f-udev.

Register a second key as a backup. Losing your only key can lock you out:

pamu2fcfg -n >> ~/.config/Yubico/u2f_keys

2. Enable it in PAM

Back up first, and keep a root terminal open while testing:

sudo cp /etc/pam.d/common-auth /etc/pam.d/common-auth.bak
sudo nano /etc/pam.d/common-auth

Add this line at the top:

auth sufficient pam_u2f.so cue
  • sufficient: touching the key logs you in, and your password still works as a fallback.
  • required, placed after the pam_unix.so line: password and key, which is true 2FA.

common-auth covers login, sudo and the lock screen. To limit it to one thing, edit /etc/pam.d/sudo or /etc/pam.d/lightdm instead.

Caveats

  • LUKS disk unlock: this doesn't unlock an encrypted disk at boot. That needs systemd-cryptenroll with FIDO2, which is a separate setup.
  • Nano keys: a key that stays plugged in all day gives little protection against someone with physical access. Unplug it when you walk away.
  • USB-A only: if your laptop only has USB-C you'll need an adapter.

Encrypted home directory: the key file in ~/.config isn't readable before login. Store it centrally instead:

sudo mkdir -p /etc/Yubico
pamu2fcfg | sudo tee /etc/Yubico/u2f_keys

Then use auth sufficient pam_u2f.so cue authfile=/etc/Yubico/u2f_keys.

Buy two keys, test in a spare terminal before you log out, and keep the .bak file handy.

I use this method to have a quick, easy method to authorise sudo required auth and screen lock access, not for full security as my desktop doesn't use encrypted drives. However if I was using Linux on the road, on a laptop, I would for sure use two factor authentication...a strong password and a FIDO2 key for authentication and security isolation.