https://wiki.archlinux.org/api.php?action=feedcontributions&user=Danni140c&feedformat=atomArchWiki - User contributions [en]2024-03-28T13:31:59ZUser contributionsMediaWiki 1.41.0https://wiki.archlinux.org/index.php?title=Fprint&diff=558459Fprint2018-12-06T19:12:07Z<p>Danni140c: /* Login configuration */ fixed spelling mistake</p>
<hr />
<div>{{Lowercase title}}<br />
[[Category:Input devices]]<br />
[[bg:Fprint]]<br />
[[fa:Fprint]]<br />
[[ja:Fprint]]<br />
{{Related articles start}}<br />
{{Related|Fingerprint-gui}}<br />
{{Related|ThinkFinger}}<br />
{{Related articles end}}<br />
<br />
From [http://www.freedesktop.org/wiki/Software/fprint/ the fprint homepage]:<br />
<br />
:The fprint project aims to plug a gap in the Linux desktop: support for consumer fingerprint reader devices.<br />
<br />
The idea is to use the built-in fingerprint reader in some notebooks for login using [[PAM]]. This article will also explain how to use regular password for backup login method (solely fingerprint scanner is not recommended due to numerous reasons).<br />
<br />
== Prerequisites ==<br />
<br />
Make sure you have one of the supported finger scanners. You can check if your device is supported by checking [http://www.freedesktop.org/wiki/Software/fprint/libfprint/Supported_devices/ this] list of supported devices. To check which one you have, type<br />
# lsusb<br />
<br />
{{Note| The above list of supported devices is not updated regularly and is not complete. Its worth testing your device using the instructions on this page even if it does not appear on that list, prior to resorting to [[AUR]] packages.}}<br />
<br />
== Installation ==<br />
<br />
[[Install]] the {{Pkg|fprintd}} package. {{Pkg|imagemagick}} might also be needed.<br />
<br />
== Configuration ==<br />
<br />
=== Login configuration ===<br />
<br />
{{Note|If you use [[GDM]], the fingerprint-option is already available in the login menu (if not add yourself to the {{ic|input}} group). You can skip this section!}}<br />
<br />
Add {{ic|pam_fprintd.so}} as ''sufficient'' to the top of the auth section of {{ic|/etc/pam.d/system-local-login}}:<br />
<br />
{{hc|/etc/pam.d/system-local-login|<br />
'''auth sufficient pam_fprintd.so'''<br />
auth include system-login<br />
...<br />
}}<br />
<br />
This tries to use fingerprint login first, and if it fails or if it finds no fingerprint signatures in the given user's home directory, it proceeds to password login.<br />
<br />
You can also modify other files in {{ic|/etc/pam.d/}} in the same way, for example {{ic|/etc/pam.d/polkit-1}} for GNOME polkit authentication.<br />
<br />
=== Create fingerprint signature ===<br />
<br />
To add a signature for a finger, run<br />
$ fprintd-enroll<br />
or create a new signature for all fingers<br />
$ fprintd-delete "$USER"<br />
$ for finger in {left,right}-{thumb,{index,middle,ring,little}-finger}; do fprintd-enroll -f "$finger" "$USER"; done<br />
<br />
You will be asked to scan the given finger. Swipe your right index finger '''five times'''. After that, the signature is created in {{ic|/var/lib/fprint/}}.<br />
<br />
For more information, see {{man|1|fprintd}}.<br />
<br />
=== Restrict enrolling ===<br />
<br />
By default you are allowed to enroll new fingerprints without prompting for the password or the fingerprint. You can change this behavior using Polkit rules.<br />
<br />
In the following example only superuser can enroll fingerprints:<br />
<br />
{{hc|/etc/polkit-1/rules.d/50-net.reactivated.fprint.device.enroll.rules|<nowiki>polkit.addRule(function (action, subject) {<br />
if (action.id == "net.reactivated.fprint.device.enroll") {<br />
return subject.user == "root" ? polkit.Result.YES : polkit.result.NO<br />
}<br />
})</nowiki>}}</div>Danni140c