Fedora Account System
Red Hat Associate
Red Hat Customer
The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256, sk-ssh-ed25519) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:67450 https://access.redhat.com/errata/RHSA-2026:67450
This issue has been addressed in the following products: RHEM 1.1 for RHEL 10 RHEM 1.1 for RHEL 9 Via RHSA-2026:68334 https://access.redhat.com/errata/RHSA-2026:68334