From Fedora Project Wiki


Check if the System handles Key's blocking (8 incorrect attempts)


  1. Add a LDAP, IPA and AD user with passkey_mapping
  2. Setup SSSD client with FIDO2/passkey.

How to test

  1. When authenticating (using su), provide incorrect pin 8 times in a row (with re-inserting after every 3rd attempt)

Expected Results

  1. The System should prompt rebooting the FIDO key (removing and reinserting)
  2. The System should not hang
  3. After 8th incorrect attempt, the system should prompt to reset the FIDO2 key