Web Authentication , shortened as WebAuthn, is a standard method by which a web browser can authenticate to an application (Relying Party, in our case, this is LemonLDAP::NG) through the use of an Authenticator, which can be a hardware token (USB, NFC...) or provided by the user’s device itself (TPM).
Tip
If you want to use Webauthn as first factor (also called passwordless), see dedicated documentation.
Currently, we implement:
You need to install the Authen::WebAuthn CPAN module for WebAuthn to work on your LemonLDAP::NG installation.
For Debian:
apt install libauthen-webauthn-perl
For RHEL (>=8):
dnf install perl-Authen-WebAuthn
If there is no package for it in your distribution, you can install it with:
cpanm Authen::WebAuthn
Attention
If you want to use a custom rule for “activation” and want to keep self-registration, you must add the following condition to the custom activation rule:
and has2f('WebAuthn')
Without this condition, WebAuthn device will be asked even for users who didn’t register one. This is automatically done when “activation” is simply set to “on”.
If you don’t want to use self-registration, set public part of user’s yubikey in Second Factor Devices array (JSON) in your user-database. Then map it to the _2fDevices attribute (see exported variables):
[{"name" : "MyFIDO2" , "type" : "WebAuthn" , "epoch":"1524078936"}, ...]
WebAuthn is compatible with both FIDO and FIDO2 standards. Which means this module lets you use any U2F-compatible device you already own.
You can use the lemonldap-ng-sessions tool to migrate existing U2F devices to the WebAuthn plugin
# For one user
lemonldap-ng-sessions secondfactors migrateu2f dwho
# For all users
lemonldap-ng-sessions secondfactors migrateu2f --all
Once you are satisfied with WebAuthn, you can remove existing U2F devices and disable the U2F second factor module
# For one user
lemonldap-ng-sessions secondfactors delType dwho U2F
# For all users
lemonldap-ng-sessions secondfactors delType --all U2F