On Mon, Jun 24, 2024 at 02:39:13PM GMT, Mattia Verga via devel wrote: > > Perhaps it's a stupid idea, but we already have ssh public keys stored > in fas, would it be possible for fkinit to use the private key as second > factor? That way, on a system which is considered secure (it has the > private key stored in it) we would only require the user to enter the > FAS password, while on a smartphone or a temporary device the > password+otp would still be required. No, it's not currently possible. Rememver that we are using IPA as a backend, so it would need support in IPA. How would it know you wanted to use a ssh key instead of otp? I suppose it would have to try all your keys and see if any worked? It likely would cause a lot of confusion also for those that didn't expect it. I personally don't see why entering a otp once a week is such a burden... but it does seem to be. ;( kevin
Attachment:
signature.asc
Description: PGP signature
-- _______________________________________________ devel mailing list -- devel@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to devel-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel@xxxxxxxxxxxxxxxxxxxxxxx Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue