[MIR] libu2f-host *UDEV RULES ONLY* bin:libu2f-udev

Bug #1757411 reported by Dimitri John Ledkov
10
This bug affects 1 person
Affects Status Importance Assigned to Milestone
libu2f-host (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

[Foreword]

U2F - "universal two factor" is a recent standard to provide two factor authentication using elliptic curve cryptography; with physical confirmation; and authentication of both server and client identities. This is therefore stronger than the usual 6-digit codes, and more user friendly - just touch a button. The devices that commonly support this are Yubikeys among other implementations. These rely on access to /dev/hidraw device by the user account, which is typically otherwise accessible by root only. The udev rules shipped, open up, and assign these devices to the user seats - effectively making them "USB memory stick" permissions wise (a local user/seat can access it, when plugging it in). Previously these udev rules were shipped in src:systemd, but now they have been removed upstream in favor of maintaining them in the src:libu2f-host. On the user systems, Firefox / Chrome / Chromium have support to use u2f devices to authenticate with Google Apps, Github, Salesforce, Etc.

This MIR is specifically about shipping the udev rules only. It is not about shipping the libu2f shared library that facilitates developing of u2f enabled apps and daemons.

[Availability]

Available in universe.

[Rationale]

All Ubuntu Desktop Flavours should be able to perform U2F authentication in a web-browser.

[Security]

udev rules only, as described in foreword, limited by vendor IDs and model numbers.

[Quality assurance]

The package is in good shape, and there is a binary package specifically to ship udev rules only.

[Dependencies]

none

[Standards compliance]

ok

[Maintenance]

At times, as more devices become available on the market, udev rules may need an update, and SRUs.

foundations bugs is subscribed.

seeded into desktop-common.

[Background information]

See foreword.

Revision history for this message
Dimitri John Ledkov (xnox) wrote :

The one and only file shipped by libu2f-udev for review.

description: updated
summary: - [MIR] libu2f-host *UDEV RULES ONLY*
+ [MIR] libu2f-host *UDEV RULES ONLY* bin:libu2f-udev
tags: added: id-5a096cad0b33afe7dc38a9c1
Changed in libu2f-host (Ubuntu):
assignee: nobody → Mathieu Trudel-Lapierre (cyphermox)
status: New → In Progress
Revision history for this message
Mathieu Trudel-Lapierre (cyphermox) wrote :

This is straightforward and obvious, same u2f rules as were previously in udev itself.

MIR approved for the binary only: libu2f-udev

Changed in libu2f-host (Ubuntu):
status: In Progress → Fix Committed
assignee: Mathieu Trudel-Lapierre (cyphermox) → nobody
Revision history for this message
Steve Langasek (vorlon) wrote :

Override component to main
libu2f-host 1.1.4-1 in bionic: universe/misc -> main
1 publication overridden.
Override component to main
libu2f-udev 1.1.4-1 in bionic amd64: universe/libs/optional/100% -> main
libu2f-udev 1.1.4-1 in bionic arm64: universe/libs/optional/100% -> main
libu2f-udev 1.1.4-1 in bionic armhf: universe/libs/optional/100% -> main
libu2f-udev 1.1.4-1 in bionic i386: universe/libs/optional/100% -> main
libu2f-udev 1.1.4-1 in bionic ppc64el: universe/libs/optional/100% -> main
libu2f-udev 1.1.4-1 in bionic s390x: universe/libs/optional/100% -> main
6 publications overridden.

Changed in libu2f-host (Ubuntu):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Bug attachments

Remote bug watches

Bug watches keep track of this bug in other bug trackers.