22653ff4ff099b929dcb305a00fe92d42e710b44
x..y is correctly NOT rejected by the slash/dot/empty/NUL guard; the recipe now documents this as an intentional regression test against over-rejection. Frames canonicalize-then-verify as Phase 17 follow-up hardening.
authforge
Turnkey U2F / FIDO2 passkey / TOTP MFA for Linux desktops. v1 ships on Ubuntu LTS + GNOME; Debian and KDE Plasma are on the roadmap.
Install (end users)
sudo add-apt-repository ppa:dangerousthings/authforge
sudo apt install authforge
Build from source
See docs/BUILDING.md.
Status
Pre-alpha. Phases 0–8, 15, 16 code complete (workspace scaffold, D-Bus daemon,
storage layer, FIDO2 backend, policy apply via pam-auth-update with lockout
simulation, PAM pending-flag backstop, authforgectl CLI, GUI Security Keys
tab, gnome-control-center overlay, Ansible role for fleet deployment).
Phase 9 (GUI Policy tab) and Phase 12 (recovery flow) are the next single-lane
bundles. See docs/plans/ for design, roadmap, and per-phase
implementation plans.
Copyright 2026 Dangerous Things, LLC. Licensed under the Apache License, Version 2.0.
Description
Languages
Rust
95.9%
C
3.6%
Jinja
0.3%
Makefile
0.2%