Tiny Core Linux

Tiny Core Base => TCB Talk => Topic started by: Rich on October 05, 2026, 10:06:02 PM

Title: Yubikey not working with Firefox 140.15.0esr 64-bit
Post by: Rich on October 05, 2026, 10:06:02 PM
As the title states, I can't get a Yubikey to work with Firefox 140.15.0esr 64-bit.

I'm testing this on TC14 x86_64.

This is the device I'm trying to use:
https://www.yubico.com/product/security-key-series/security-key-nfc-by-yubico-black/

I'm using this udev rules file:
Code: [Select]
tc@HP-G62:~$ cat 70-old-u2f.rules
# 70-old-u2f.rules
# sudo cp -a 70-old-u2f.rules /etc/udev/rules.d/
# sudo udevadm control --reload-rules
# sudo udevadm trigger
# https://www.yubico.com/genuine/

ACTION!="add|change", GOTO="u2f_end"

# Yubico YubiKey
KERNEL=="hidraw*", SUBSYSTEM=="hidraw", ATTRS{idVendor}=="1050", ATTRS{idProduct}=="0402", OWNER="tc", GROUP="staff", MODE="0666"
#KERNEL=="hidraw*", SUBSYSTEM=="hidraw", ATTRS{idVendor}=="1050", ATTRS{idProduct}=="0113|0114|0115|0116|0120|0200|0402|0403|0406|0407|0410", MODE="0666", GROUP="plugdev", ENV{ID_SECURITY_TOKEN}="1"
LABEL="u2f_end"

I then ran:
Code: [Select]
tc@HP-G62:~$ sudo cp -a 70-old-u2f.rules /etc/udev/rules.d/
tc@HP-G62:~$ sudo udevadm control --reload-rules
tc@HP-G62:~$ sudo udevadm trigger

The device is assigned to /dev/hidraw1:
Code: [Select]
tc@HP-G62:~$ ls -l /dev/hidraw*
crw------- 1 root root  241, 0 Oct  5 14:22 /dev/hidraw0
crw-rw-rw- 1 tc   staff 241, 1 Oct  5 14:22 /dev/hidraw1
crw------- 1 root root  241, 2 Oct  5 14:22 /dev/hidraw2

These are my Firefox webauth settings:
Code: [Select]
security.webauth.u2f true
security.webauth.webauthn true
security.webauth.webauthn_enable_softtoken false
security.webauth.webauthn_enable_usbtoken true
security.webauthn.always_allow_direct_attestation false
security.webauthn.ctap2 true
security.webauthn.enable_conditional_mediation true
security.webauthn.enable_json_serialization_methods true
security.webauthn.enable_macos_passkeys false
security.webauthn.show_ms_settings_link false
security.webauthn.webauthn_enable_android_fido2.residentkey true

When I go to  https://www.yubico.com/genuine/  the page loads, but when I
click the  Verify Device  button I get a message stating:
Quote
The request is not allowed by the user agent or the platform in the current
context, possibly because the user denied permission.
as seen here:

(https://forum.tinycorelinux.net/index.php?action=dlattach;topic=28302.0;attach=7306)

The  Browser Console  was open but displayed no error or warning messages.

When using the Brave browser, clicking the  Verify Device  button at
https://www.yubico.com/genuine/  resulted in:
1. A popup requesting I touch the key which was now blinking.
2. After touching the key, a popup asking if I should allow access to it.
3. After allowing access, it verified my key.
As can be seen below:

(https://forum.tinycorelinux.net/index.php?action=dlattach;topic=28302.0;attach=7307)

I really don't want to change browsers if I don't have to.
Title: Re: Yubikey not working with Firefox 140.15.0esr 64-bit
Post by: patrikg on October 06, 2026, 03:01:02 AM
Hi @Rich

I'm happy to see that you are using a YubiKey as a Swede.
Does the Yubico Authenticator work for you?

Sorry for asking:
Do you get any errors with open up firefox from the command line, like we are saying to all new Linux users. It's easy to forget. :)

https://www.yubico.com/products/yubico-authenticator/ (https://www.yubico.com/products/yubico-authenticator/)
https://developers.yubico.com/yubioath-flutter/Releases/yubico-authenticator-latest-linux.tar.gz (https://developers.yubico.com/yubioath-flutter/Releases/yubico-authenticator-latest-linux.tar.gz)

https://developers.yubico.com/yubico-piv-tool/YKCS11/Supported_applications/firefox.html (https://developers.yubico.com/yubico-piv-tool/YKCS11/Supported_applications/firefox.html)
Title: Re: Yubikey not working with Firefox 140.15.0esr 64-bit
Post by: ctor on October 06, 2026, 09:26:08 AM
Rich,

I was able to get a Yubikey with the same subsystem( hidraw) and ATTRS{idVendor}( 1050) under TC 15.0 x86_64 and 16.2 x86_64 with Firefox.
It was a struggle -- I'll try to explain:

1) missing libraries
2) permission issues that exhibited different behavior between 15.0 and 16.2.

The missing libraries were libcbor.so.0.10.2, libfido2.so.1.14.0, and libudev.so.1.7.8. I got these from either the Debian or Ubuntu repository. I only found a hint on the internet that they were needed -- sorry but I cannot find that hint again.

The permission issue drove me crazy. I compiled and used the program from this link to be sure that the Yubikey worked without root permissions
before trying to use the key with Firefox:

https://stackoverflow.com/questions/32552853/open-function-in-c-says-unable-to-open-device-permission-denied

In the 70-old-u2f.rules file, I only changed the MODE attribute to 0666:

Code: [Select]
KERNEL=="hidraw*", SUBSYSTEM=="hidraw", ATTRS{idVendor}=="1050", ATTRS{idProduct}=="0120", TAG+="uaccess", GROUP="plugdev", MODE="0666"
Now the behavior difference -- TC 15.0 x86_64 worked with just the 70-old-u2f.rules file; TC 16.2 x86_64 did not. To use the Yubikey with Firefox
I had to manually change the permissions of the hidraw devices.

Code: [Select]
sudo chmod 666 /dev/hidraw*
I did not have to change any Firefox webauth settings -- to be honest, I didn't know about them.

I bundled the missing libraries, 70-u2f.rules rules file, and the test.cc program, binary, and Makefile into an extension that loads at boot time.

Hope this helps. I really do appreciate all you and the admins do to support me using Tiny Core.

regards,
ctor



Title: Re: Yubikey not working with Firefox 140.15.0esr 64-bit
Post by: Rich on October 06, 2026, 09:54:44 AM
Hi patrikg
... Does the Yubico Authenticator work for you? ...
I already had yubico-authenticator-7.4.1-linux.tar.gz downloaded and it worked.
I had also cobbled together fido2-tools and its dependencies into a directory:
Code: [Select]
fido2-tools_1.6.0-2_amd64.deb
libcbor0_0.5.0+dfsg-2_amd64.deb
libfido2-1_1.6.0-2_amd64.deb
libudev1_247.3-7+deb11u8_amd64.deb

and was able to set and change the pin on my device like this:
Code: [Select]
# Set PIN in security key.
tc@HP-G62:~/Fido$ LD_PRELOAD=usr/lib/libfido2.so.1:usr/lib/libcbor.so.0:usr/lib/libudev.so.1 ./usr/bin/fido2-token -S /dev/hidraw2

# Change PIN in security key.
tc@HP-G62:~/Fido$ LD_PRELOAD=usr/lib/libfido2.so.1:usr/lib/libcbor.so.0:usr/lib/libudev.so.1 ./usr/bin/fido2-token -C /dev/hidraw2

Quote
... Do you get any errors with open up firefox from the command line, like we are saying to all new Linux users. It's easy to forget. :) ...
On startup I got this:
Code: [Select]
tc@HP-G62:~$ firefox
[Parent 30449, Main Thread] WARNING: Failed to create DBus proxy for org.freedesktop.UPower: Could not connect: No such file or directory
: 'glib warning', file /builds/worker/checkouts/gecko/toolkit/xre/nsSigHandlers.cpp:201

** (firefox-esr:30449): WARNING **: 06:22:10.641: Failed to create DBus proxy for org.freedesktop.UPower: Could not connect: No such file or directory

[Parent 30449, Main Thread] WARNING: Failed to create DBus proxy for org.freedesktop.UPower: Could not connect: No such file or directory
: 'glib warning', file /builds/worker/checkouts/gecko/toolkit/xre/nsSigHandlers.cpp:201

** (firefox-esr:30449): WARNING **: 06:22:22.256: Failed to create DBus proxy for org.freedesktop.UPower: Could not connect: No such file or directory

ATTENTION: default value of option mesa_glthread overridden by environment.
Then I went to  https://www.yubico.com/genuine/  and clicked the  Verify Device  button.
No new messages appeared in the terminal.
Title: Re: Yubikey not working with Firefox 140.15.0esr 64-bit
Post by: Rich on October 06, 2026, 10:50:58 AM
Hi ctor
... It was a struggle ...
I've been fighting with this on and off for about 3 weeks.
I kept finding statements like "works with Firefox right out of the box" and
"no extra libraries required".

Quote
... The missing libraries were libcbor.so.0.10.2, libfido2.so.1.14.0, and libudev.so.1.7.8. ...
Thank you so much. ;D  I packaged the programs and libraries from fido2-tools
mentioned in my previous post and installed it. Restarted Firefox and
the  Verify Device  button at  https://www.yubico.com/genuine/  now works
as it should.

Quote
... In the 70-old-u2f.rules file, I only changed the MODE attribute to 0666:

Code: [Select]
KERNEL=="hidraw*", SUBSYSTEM=="hidraw", ATTRS{idVendor}=="1050", ATTRS{idProduct}=="0120", TAG+="uaccess", GROUP="plugdev", MODE="0666" ...
I think MODE 0666 only bypassed the TAG+ and GROUP requirements.
I changed my MODE back to 0660 and it still works.
I think this should work for you too:
Code: [Select]
KERNEL=="hidraw*", SUBSYSTEM=="hidraw", ATTRS{idVendor}=="1050", ATTRS{idProduct}=="0120", OWNER="tc", GROUP="staff", MODE="0660"
Quote
... I did not have to change any Firefox webauth settings -- to be honest, I didn't know about them. ...
The only thing I did was add  "security.webauth.u2f        true". Not because it was needed, but
because that "solution' ranked pretty high on the Google answer list. I didn't want someone
suggesting that as a possible fix here. That setting is obsolete and I've since removed it.

Quote
... Hope this helps. ...
Yes it does. Thank you again.