08-03-2021 01:24 PM
I have had Duo setup for a long time successfully on Gnome 3 and GDM. The GDM login works properly and all the polkit prompts work properly as well.
I recently setup a KDE Plasma machine. I configured my /etc/pam.d/common-auth the same way that I have my Gnome machine setup. Everything in the terminal works as expected. When starting from a fresh reboot though, the SDDM login screen never prompts me for Duo after I enter my password, login then fails. I setup fail safe so I disconnect my network and login because it can’t hit the duo server. After that, whenever something needs sudo access from the GUI, the polkit prompt fails. I enter my password, and I see the message about entering a Duo code, but there is never any text field for me to enter anything in to.
I’ve found very little about this online. Does no one here use KDE Plasma?
08-06-2021 09:32 AM
Hi there, and welcome to the Duo Community! Thanks for sharing your question here. I am not familiar with KDE Plasma myself, and I am not seeing anything in my internal searches of our help resources or past support tickets that would help with this. Your best bet would be to work with the Duo Support team. Sorry I can’t be of more assistance!
01-10-2023 09:49 AM
Having same issue. Did you get this resolved with support?
01-10-2023 10:07 AM
Nope. Unfortunately duo didn’t have any answers, and neither did the KDE devs.
01-10-2023 11:35 AM
Well, I did finally get it working…There were several issues but mainly from my installation. The auth.log was very helpful. My distro (Kubuntu) did not put the library where the example was. Also, the permissions were incorrect on pam_duo.conf. Pretty much after I cleared all the errors in auth.log, it worked.
01-10-2023 11:56 AM
That sounds just like getting Duo working with pam.
Do you actually get polkit prompts that have an appropriate text box and text for the second factor auth after password?
01-10-2023 12:44 PM
I was thinking that was the issue you had because of the part that was talking about the login fail, but I see that you were more concerned with the prompt. I also did not get a prompt on this (and it did work on gdm), but it does do a push and authenticates me.
The biggest issue is that the pushes repeat, so if I were to deny the request, or not respond, it would keep pushing until my user was locked out. Not ideal, but it is good enough for me to be able to use this machine at work.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide