Real fixes:
- authforge-daemon Depends: policykit-1 -> polkitd | policykit-1
(policykit-1 was renamed; old name is obsolete on noble).
- debian/rules: drop manual install of authforge-daemon.service to
/lib/systemd/system/ — dh_installsystemd auto-installs to
/usr/lib/systemd/system/, the manual line caused a file-in-root-and-usr
duplicate flagged by usrmerge.
- authforge-pam.{postinst,prerm}: replace [ -x /usr/sbin/pam-auth-update ]
with command -v pam-auth-update — lintian flags hard-coded paths in
test syntax; command -v is the portable idiom.
Overrides (with rationale in each file):
- no-manual-page on the three binaries — manpages deferred to Phase 18.
- desktop-command-not-in-package authforge in gnome-integration —
command lives in authforge-gui (cross-package Depends).
- initial-upload-closes-no-bugs on every package — AuthForge ships
via PPA, not the Debian archive, so there is no ITP to close.
After fixes, lintian on the five binary debs is silent (zero W/E).
authforge
Turnkey U2F / FIDO2 passkey / TOTP MFA for Linux desktops. v1 ships on Ubuntu LTS + GNOME; Debian and KDE Plasma are on the roadmap.
Install (end users)
sudo add-apt-repository ppa:dangerousthings/authforge
sudo apt install authforge
Build from source
See docs/BUILDING.md.
Status
Pre-alpha. Phases 0–12, 15, 16 code complete (workspace scaffold, D-Bus
daemon, storage layer, FIDO2 backend, policy apply via pam-auth-update
with lockout simulation, PAM pending-flag backstop with Argon2id recovery
codes, authforgectl CLI, GUI shell with Security Keys / Policy /
Recovery / TOTP tabs, fullscreen first-run enrollment modal,
pam_google_authenticator-delegated TOTP, gnome-control-center
overlay, Ansible role for fleet deployment). Remaining work for v1.0:
Debian packaging finalization (Phase 13), Launchpad PPA + VM smoke
(Phase 14), integration test harness (Phase 17), user docs (Phase 18).
See docs/plans/ for design, roadmap, and per-phase
implementation plans.
Copyright 2026 Dangerous Things, LLC. Licensed under the Apache License, Version 2.0.