Bug 1753369

Summary: U2F enablement package not available in EPEL8 for RHEL8
Product: Red Hat Enterprise Linux 8 Reporter: David Templeton <dtemplet>
Component: systemdAssignee: David Tardon <dtardon>
Status: CLOSED ERRATA QA Contact: Frantisek Sumsal <fsumsal>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 8.0CC: carl, dtardon, luto, msekleta, systemd-maint-list, vcojot
Target Milestone: rc   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: systemd-239-19.el8 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-04-28 16:45:06 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description David Templeton 2019-09-18 17:57:49 UTC
Description of problem: u2f-hidraw-policy is not available in EPEL8 for RHEL8. It would increase platform security to make an easily-installable package to use U2F available to EPEL8 users on RHEL8.


Version-Release number of selected component (if applicable): RHEL 8


Steps to Reproduce:
1. `yum install u2f-hidraw-policy`

Actual results:
No match for argument: u2f-hidraw-policy
Error: Unable to find a match

Expected results:
It would install the package

Comment 1 Andy Lutomirski 2019-09-18 18:32:37 UTC
It turns out that a very recent upstream systemd commit obsoletes u2f-hidraw-policy entirely:

commit d45ee2f31a8358db0accde2e7c81777cedadc3c2
Author: Fabian Henneke <fabian>
Date:   Wed Aug 21 11:17:59 2019 +0200

    udev: Add id program and rule for FIDO security tokens

I would prefer for the new udev functionality to enter RHEL directly rather than creating a new EPEL branch for an otherwise obsolete helper.  I don't have the ability to change the component for this bug -- could one of you Red Hat folks ask the RHEL systemd maintainers if they can do this?

Comment 2 David Templeton 2019-09-18 18:50:32 UTC
Thanks Andy. Roughly how long would it take for that upstream systemd commit to enter RHEL8 stable?

Comment 3 Andy Lutomirski 2019-09-18 22:30:24 UTC
I have no clue, and I know basically nothing about RHEL development.  I'm reassigning the bug to RHEL8 systemd.  Systemd people, if you don't want to backport the commit above, feel free to reassign this to me and I can make an EPEL8 branch.

Comment 4 Michal Sekletar 2019-09-24 13:04:01 UTC
I see no problem incorporating fido_id to RHEL-8 udev distribution. David can you have a look at this a prepare the backport?

Comment 5 David Tardon 2019-09-24 16:30:56 UTC
Sure.

Comment 6 David Tardon 2019-10-11 12:52:06 UTC
PR: https://github.com/systemd-rhel/rhel-8/pull/26

Comment 8 Lukáš Nykrýn 2019-10-23 12:35:49 UTC
fix merged to github master branch -> https://github.com/systemd-rhel/rhel-8/pull/26 -> post

Comment 10 Carl George 🤠 2020-01-23 22:38:11 UTC
This backport has been released in CentOS 8 Stream.

https://lists.centos.org/pipermail/centos-devel/2020-January/036500.html

Please test this and provide feedback if you're able.

Comment 13 errata-xmlrpc 2020-04-28 16:45:06 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2020:1794