-
Story
-
Resolution: Unresolved
-
Undefined
-
None
-
rhel-cle-nucleus
-
-
-
The described way of adding U2F yubikeys to PAM is outdated and results in the login screens not giving any indication that the Yubikey should be used on Fedora 43 KDE (No "Please touch the authenticator" on the login screen or "Yubikey for [user]" in the terminal).
I'm sure there are other ways to do it, but I think the best way is to just enable U2F in PAM by using authselect, for example:
sudo authselect select local with-pam-u2f
That way, all the prompts work properly.
This guide has a good description of it: https://fedoramagazine.org/use-fido-u2f-security-keys-with-fedora-linux/