Skip to content

Cant add mac touchid as mfa for tsh #45485

Answered by webvictim
anfedoro asked this question in Q&A
Discussion options

You must be logged in to vote

Unfortunately Touch ID being separate between the browser and the command line is a MacOS security limitation, and there's nothing we can do about it.

Here's an explanation of a workaround: #32051 (comment)

Essentially to have Touch ID registered in both the browser and at the command line, you should be able to:

  • set up your Teleport user and add Touch ID in the browser - don't register a passwordless user, make sure to use a password with Touch ID as MFA
  • use Touch ID in the browser to add an OTP device (scan QR code with an app like Authy, Google Authenticator etc) - you can verify this operation with Touch ID in the browser
  • log in at the command line with tsh login --proxy teleport.exa…

Replies: 2 comments 7 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
7 replies
@webvictim
Comment options

Answer selected by benarent
@webvictim
Comment options

@anfedoro
Comment options

@webvictim
Comment options

@anfedoro
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants