Bug 1753369 - U2F enablement package not available in EPEL8 for RHEL8
Summary: U2F enablement package not available in EPEL8 for RHEL8
Alias: None
Product: Red Hat Enterprise Linux 8
Classification: Red Hat
Component: systemd
Version: 8.0
Hardware: Unspecified
OS: Unspecified
Target Milestone: rc
: ---
Assignee: David Tardon
QA Contact: Frantisek Sumsal
Depends On:
TreeView+ depends on / blocked
Reported: 2019-09-18 17:57 UTC by David Templeton
Modified: 2020-03-03 13:32 UTC (History)
6 users (show)

Fixed In Version: systemd-239-19.el8
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Last Closed:
Type: Bug
Target Upstream Version:

Attachments (Terms of Use)

Description David Templeton 2019-09-18 17:57:49 UTC
Description of problem: u2f-hidraw-policy is not available in EPEL8 for RHEL8. It would increase platform security to make an easily-installable package to use U2F available to EPEL8 users on RHEL8.

Version-Release number of selected component (if applicable): RHEL 8

Steps to Reproduce:
1. `yum install u2f-hidraw-policy`

Actual results:
No match for argument: u2f-hidraw-policy
Error: Unable to find a match

Expected results:
It would install the package

Comment 1 Andy Lutomirski 2019-09-18 18:32:37 UTC
It turns out that a very recent upstream systemd commit obsoletes u2f-hidraw-policy entirely:

commit d45ee2f31a8358db0accde2e7c81777cedadc3c2
Author: Fabian Henneke <fabian@henneke.me>
Date:   Wed Aug 21 11:17:59 2019 +0200

    udev: Add id program and rule for FIDO security tokens

I would prefer for the new udev functionality to enter RHEL directly rather than creating a new EPEL branch for an otherwise obsolete helper.  I don't have the ability to change the component for this bug -- could one of you Red Hat folks ask the RHEL systemd maintainers if they can do this?

Comment 2 David Templeton 2019-09-18 18:50:32 UTC
Thanks Andy. Roughly how long would it take for that upstream systemd commit to enter RHEL8 stable?

Comment 3 Andy Lutomirski 2019-09-18 22:30:24 UTC
I have no clue, and I know basically nothing about RHEL development.  I'm reassigning the bug to RHEL8 systemd.  Systemd people, if you don't want to backport the commit above, feel free to reassign this to me and I can make an EPEL8 branch.

Comment 4 Michal Sekletar 2019-09-24 13:04:01 UTC
I see no problem incorporating fido_id to RHEL-8 udev distribution. David can you have a look at this a prepare the backport?

Comment 5 David Tardon 2019-09-24 16:30:56 UTC

Comment 6 David Tardon 2019-10-11 12:52:06 UTC
PR: https://github.com/systemd-rhel/rhel-8/pull/26

Comment 8 Lukáš Nykrýn 2019-10-23 12:35:49 UTC
fix merged to github master branch -> https://github.com/systemd-rhel/rhel-8/pull/26 -> post

Comment 10 Carl George 2020-01-23 22:38:11 UTC
This backport has been released in CentOS 8 Stream.


Please test this and provide feedback if you're able.

Note You need to log in before you can comment on or make changes to this bug.