LoginLess WebAuthn: Don't have to type in username nor password when using WebAuthn with Windows Hello or Security Key

Viewed 341

I want to achieve a truly login-less (not password-less) authentication using Keycloak and Windows Hello (or a supported security key). This means, that I don't want to type in my username nor password. (Keycloak should extract the username automatically from my security key/Windows Hello)

As far as I understand the documentation 0 correctly, that should work. Not every security key is supported (because it must be able to store the user credentials on the key itself), but Windows Hello should be supported, see 1.

In order to make WebAuthn working with Windows Hello, I added the Signature Algorithm RS256, like stated in 2:

  • Authentication -> WebAuthn Passwordless Policy -> Signature Algorithms -> ES256 & RS256 (selecting both using the ctr-key)

Additionally I set user verification=yes and resident key=yes, 3:

  • Authentication -> WebAuthn Passwordless Policy -> Require Resident Key -> Yes
  • Authentication -> WebAuthn Passwordless Policy -> User Verification Requirement -> required

WebAuthn Passwordless Policy

Like in 3, my Authentication Flow now only consists of a single line: WebAuthn Passwordless Authenticator, required.

Authentication Flows

I already registered a user (before changing the authentication flow) with username, password and security key.

But when I change the authentication flow to my login-less one, I get this error message, when clicking on type-in: We are sorry... Invalid username or password.

Error Message

Can anyone help me?

Additionally, is there a way to register a new user without a password, i.e. only security key? Currently, after switching to the login-less authentication flow, I cannot register a new user anymore (because I always get the error message).

I also asked the same question on Keycloak Github

1 Answers

Note my addendum at the end!


Original Answer:

I, partly, managed to solve my problem. But there are still some open questions. Here are my configurations and steps:

Keycloak Configuration

  • Realm Settings
    • Login
      • User registration -> OFF
  • Authentication
    • Flows
      • Created new "Custom Browser Login"
        • Cookie -> Alternative
        • WebAuthn Passwordless Authenticator -> Alternative
    • Bindings
      • Browser Flow -> "Custom Browser Login"
    • Required Actions
      • Webautn Register Passwordless -> Enabled & Default Action
    • WebAuthn Passwordless Policy
      • Signature Algorithms -> ES256 & RS256
      • Require Resident Key -> Yes
      • User Verification Requirement -> required

Register User incl. Security-Key

  • Note:
    • Registration can only be done by Admin in the Admin Console, i.e. there is no Register option at the login-page
    • Admin has to register the (first) Security-Key for the user
  • Users
    • Add User
      • Enter username: myuser1
      • Save
      • Note: Automatically added Required User Actions -> Webauthn Register Passwordless
    • myuser1
      • Impersonate -> opens Account Console
  • Account Console
    • Click Sign in
    • Register -> Register new Security-Key
  • Note: For some reason, this only works, if because we activated the Cookie in the Authentication flow

Add Security Key

  • Note: maybe the user lost the Security-Key, or an additional one should be added
  • Users
    • myuser1
      • Add Required User Action -> Webauthn Register Passwordless
      • Save
      • Impersonate -> opens Account Console
  • Account Console
    • Click Sign in
    • Register -> Register new Security-Key
  • Note: For some reason, this only works, if because we activated the Cookie in the Authentication flow

Sign In

  • Open Application, e.g. Account Console
    • Click Sign In
    • Note: The only option to sign in is: "Sign in with Security Key"
    • Click "Sign in with Security Key"
    • In Case of Windows Hello with PIN: Click OK and enter PIN
    • Note: Because we activated the Cookie in the Authentication flow, the user has to sign out manually (at least as long as the cookie is valid)

Open Questions:

  • Why do I have to activate Cookies, in order to be able to impersonate?
  • Is there a way to add a Security Key, without impersonate? Note, I do not have any other credentials set.

2022-09-15 Addendum:

I recently tried exactly the configuration of my original answer on another Keycloak Instance and it, again, did not work.

New Assumption

So my current assumption is, that it depends on the Keycloak version, i.e. it has to be at least version 18.0.0, because:

  • In my original answer, I ran a local (Keycloak in Podman in WSL2 on Windows) Keycloak instance in Version 18.0.2, and both Windows Hello with PIN and a Yubikey 5c NFC Security key worked like intended.
  • But then, I tried the same on two remote servers, like I did at the time when writing the original question. One server with a keycloak Version 12.0.1, and the second with 16.1.1. There, only the passwordless-flow worked, but not the loginless-flow. I.e. I got the same error as in the question:

We are sorry... Invalid username or password.

This assumption would also match the Keycloak 18.0.0 release notes, see section WebAuthn improvements. Note, they call the "login-less" flow "id-less".

Keycloak now supports WebAuthn id-less authentication. This feature allows that WebAuthn Security Key will identify the user during authentication as long as the security key supports Resident Keys

Additionally

Additionally, I found on the internet, that if one wants to authenticate loginless on a remote sever (i.e. not locally), one

  1. has to use a real domain name, and not just an IP adress
  2. has to have a secure connection using HTTPS

Summary

In order to authenticate loginless, one has to:

  • use at least version 18.0.0 of Keycloak
  • use a real domain name
  • use HTTPS
  • (use the configuration in my original answer)

Note

This is just an assumption, which I was able to test only partially yet. Currently I don't have access to a Server with the latest Keycloak (i.e. at least 18.0.0) installed.

Related