# U2F broken on QubesOS : any way to disable U2F personality?

**URL:** <https://onlykey.discourse.group/t/u2f-broken-on-qubesos-any-way-to-disable-u2f-personality/505>\
**Category:** Two Factor Authentication\
**Created:** [September 13, 2021, 9:17am UTC](https://onlykey.discourse.group/t/u2f-broken-on-qubesos-any-way-to-disable-u2f-personality/505 "2021-09-13T09:17:40Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![eiz](https://avatars.discourse-cdn.com/v4/letter/e/9e8a1a/32.png) [@eiz](https://onlykey.discourse.group/u/eiz)\
**Post date:** [September 13, 2021, 9:17am UTC](https://onlykey.discourse.group/t/u2f-broken-on-qubesos-any-way-to-disable-u2f-personality/505/1 "2021-09-13T09:17:40Z")

</div>

Hello,

Currently U2F does not work with QubesOS : [Support for USB composite (HID/U2F) devices via sys-usb · Issue #5287 · QubesOS/qubes-issues · GitHub](https://github.com/QubesOS/qubes-issues/issues/5287)

Is there any way (udev rule maybe) to disable the U2F personality and only keep the keyboard input one ?

THX

---

<div class="post-metadata">

**Author:** ![t11](https://avatars.discourse-cdn.com/v4/letter/t/8e7dd6/32.png) [@t11](https://onlykey.discourse.group/u/t11)\
**Post date:** [September 13, 2021, 3:15pm UTC](https://onlykey.discourse.group/t/u2f-broken-on-qubesos-any-way-to-disable-u2f-personality/505/2 "2021-09-13T15:15:24Z")

</div>

It looks like this issue is from 2019. Are you running the latest v2.1.1 OnlyKey firmware?

Have you tried the steps listed here - [Using OnlyKey with Qubes OS | Docs](https://docs.crp.to/qubes.html)

---

<div class="post-metadata">

**Author:** ![eiz](https://avatars.discourse-cdn.com/v4/letter/e/9e8a1a/32.png) [@eiz](https://onlykey.discourse.group/u/eiz)\
**Post date:** [September 13, 2021, 3:41pm UTC](https://onlykey.discourse.group/t/u2f-broken-on-qubesos-any-way-to-disable-u2f-personality/505/3 "2021-09-13T15:41:59Z")

</div>

Just tested with latest Firmware. Still not working but symptoms are a bit different than with previous beta fw : the key flashes blue once then green immediately with no time to touch it.

And yes I followed the instruction and the key works for the keyboard input part.

---

<div class="post-metadata">

**Author:** ![t11](https://avatars.discourse-cdn.com/v4/letter/t/8e7dd6/32.png) [@t11](https://onlykey.discourse.group/u/t11)\
**Post date:** [September 13, 2021, 5:39pm UTC](https://onlykey.discourse.group/t/u2f-broken-on-qubesos-any-way-to-disable-u2f-personality/505/4 "2021-09-13T17:39:04Z")

</div>

So for the steps listed here - [Using OnlyKey with Qubes OS | Docs](https://docs.crp.to/qubes.html)

What are the results of trying these steps? For example the steps include running this command which should work if your device is configured correctly.

```auto
onlykey-cli settime

```

If this works then USB communication works. The next thing to check would be if you are running an older browser that doesn’t support FIDO2.

---

<div class="post-metadata">

**Author:** ![eiz](https://avatars.discourse-cdn.com/v4/letter/e/9e8a1a/32.png) [@eiz](https://onlykey.discourse.group/u/eiz)\
**Post date:** [September 13, 2021, 6:14pm UTC](https://onlykey.discourse.group/t/u2f-broken-on-qubesos-any-way-to-disable-u2f-personality/505/5 "2021-09-13T18:14:25Z")

</div>

Qubes uses a u2f-proxy system.

Using the OnlyKey directly attached to the VM running the browser works but this is not the intented flow. The OnlyKey app works when the key is attached to the app VM .

Other Fido keys works with the u2f proxy.

Thanks for helping.

---

<div class="post-metadata">

**Author:** ![t11](https://avatars.discourse-cdn.com/v4/letter/t/8e7dd6/32.png) [@t11](https://onlykey.discourse.group/u/t11)\
**Post date:** [September 14, 2021, 12:20pm UTC](https://onlykey.discourse.group/t/u2f-broken-on-qubesos-any-way-to-disable-u2f-personality/505/7 "2021-09-14T12:20:53Z")

</div>

I did find an issue here that looks related - [U2F support for Trezor · Issue #16 · QubesOS/qubes-app-u2f · GitHub](https://github.com/QubesOS/qubes-app-u2f/issues/16)

It seems Trezor and Yubikey were also not working with u2f-proxy back in 2019 and this issue has still not been resolved. Also u2f-proxy has not been updated in 4 years and uses an old discontinued yubico u2f library, so u2f-proxy does not support FIDO2. The only option to support FIDO2 security key would be if the maintainers add support or to not use u2f-proxy and instead use an alternative like described in our document here [Using OnlyKey with Qubes OS | Docs](https://docs.crp.to/qubes.html)

The issue seems to be that the u2f-proxy only polls once for the user to press button on device. So unless you press the button immediately u2f-proxy just stops polling. That is why you only see your device flash blue for a short time and then stop.

---

<div class="post-metadata">

**Author:** ![eiz](https://avatars.discourse-cdn.com/v4/letter/e/9e8a1a/32.png) [@eiz](https://onlykey.discourse.group/u/eiz)\
**Post date:** [September 14, 2021, 1:14pm UTC](https://onlykey.discourse.group/t/u2f-broken-on-qubesos-any-way-to-disable-u2f-personality/505/8 "2021-09-14T13:14:24Z")

</div>

Looking at the sequence of events with a Solokey I see multiple polls of u2f-proxy until key pressed.

If implementations are similar between Solokey and Onlykey I would expect same result. I will dig into the code of the proxy and check if there are some exclusions.

---

<div class="post-metadata">

**Author:** ![eiz](https://avatars.discourse-cdn.com/v4/letter/e/9e8a1a/32.png) [@eiz](https://onlykey.discourse.group/u/eiz)\
**Post date:** [September 14, 2021, 2:27pm UTC](https://onlykey.discourse.group/t/u2f-broken-on-qubesos-any-way-to-disable-u2f-personality/505/9 "2021-09-14T14:27:44Z")

</div>

Check on my QUbes 4.0 install :

hid\_transport.py explicitly manages OnlyKey :

Line 58 : (0x1d50, 0x60fc), # OnlyKey U2F

---

<div class="post-metadata">

**Author:** ![eiz](https://avatars.discourse-cdn.com/v4/letter/e/9e8a1a/32.png) [@eiz](https://onlykey.discourse.group/u/eiz)\
**Post date:** [September 14, 2021, 2:38pm UTC](https://onlykey.discourse.group/t/u2f-broken-on-qubesos-any-way-to-disable-u2f-personality/505/10 "2021-09-14T14:38:50Z")

</div>

I managed to get it working partially : in fact the key will blink blue multiple times but :

- It takes up to 18s to see the first blue flash (sometimes it occurs immediately)
- the next flash can take up to 10s to appears  
Being ready for the second blue flash allows me to register. Next I tried to login (on [token2.com](http://token2.com)) but got now answer from the key (no blue flash).

---

<div class="post-metadata">

**Author:** ![eiz](https://avatars.discourse-cdn.com/v4/letter/e/9e8a1a/32.png) [@eiz](https://onlykey.discourse.group/u/eiz)\
**Post date:** [July 29, 2022, 3:07pm UTC](https://onlykey.discourse.group/t/u2f-broken-on-qubesos-any-way-to-disable-u2f-personality/505/11 "2022-07-29T15:07:00Z")

</div>

While everything ended working as expected with fedora-35 based qubes (thanks to undetermined update), the U2F proxy stopped working again for Only key after upgrading dom0 to QUbes 4.1.

When U2F register is send from a qubes VM nothing happens anymore on the onlykey (not even blue blinking). I checked the udev rules, reinstalled every involed u2f packages with no success.  
With a solokey no issue.

Anyone else having the same issue?

---

<div class="post-metadata">

**Author:** ![eiz](https://avatars.discourse-cdn.com/v4/letter/e/9e8a1a/32.png) [@eiz](https://onlykey.discourse.group/u/eiz)\
**Post date:** [July 29, 2022, 4:28pm UTC](https://onlykey.discourse.group/t/u2f-broken-on-qubesos-any-way-to-disable-u2f-personality/505/12 "2022-07-29T16:28:50Z")

</div>

Here’s the trace :

```auto

Jul 29 18:11:24 sys-usb u2f.Register+-work[2233]: File "/usr/lib/python3.10/site-packages/u2flib_host/hid_transport.py", line 214, in _read_resp
Jul 29 18:11:24 sys-usb u2f.Register+-work[2233]: raise exc.DeviceError("Invalid response from device!")
Jul 29 18:11:24 sys-usb u2f.Register+-work[2233]: u2flib_host.exc.DeviceError: Invalid 

```
