Skip to content

PlusMagi's Blog By Pitt Phunsanit

Plus emotional magic to the knowledge of logic.

  • About’s Pitt
Close Button
PlusMagi's Blog By Pitt Phunsanit API,architecture,Authentication,computer science,Cryptography,Cybersecurity,Linux,Operating Systems,Security คู่มือการใช้งาน Passkey บน Linux

คู่มือการใช้งาน Passkey บน Linux

2024-01-042024-01-04| phunsanitphunsanit| 0 Comment | 10:00
Categories:
  • API
  • architecture
  • Authentication
  • computer science
  • Cryptography
  • Cybersecurity
  • Linux
  • Operating Systems
  • Security

แม้ว่า Linux จะไม่มีระบบชีวภาพกลางแบบ iCloud Keychain หรือ Windows Hello ในระดับระบบปฏิบัติการดั้งเดิม แต่การใช้งาน Passkey บน Linux สามารถทำได้อย่างสมบูรณ์ผ่าน WebAuthn API บนเว็บเบราว์เซอร์สมัยใหม่ และการทำงานร่วมกับ External Authenticators (เช่น สมาร์ทโฟน หรือ ฮาร์ดแวร์ Security Key)


สถาปัตยกรรมและการทำงานบน Linux

การประมวลผล Passkey บน Linux ถูกขับเคลื่อนผ่านชั้นซอฟต์แวร์ดังนี้

  • Browser-Level Cryptography: เบราว์เซอร์อย่าง Google Chrome, Chromium และ Mozilla Firefox จัดการการสร้างและตรวจสอบกุญแจส่วนตัวโดยตรง
  • Cross-Device Authentication (ctap2 / FIDO2): ใช้โปรโตคอล CTAP2 ผ่านการเชื่อมต่อ Bluetooth และ QR Code เพื่อดึงการยืนยันตัวตนจากระบบชีวภาพของ iOS/Android
  • Hardware Security Keys: รองรับฮาร์ดแวร์กุญแจความปลอดภัยภายนอก เช่น YubiKey ผ่านไลบรารี libfido2 และระบบ udev rules
  • Third-Party Managers: รองรับแอปพลิเคชันอย่าง Bitwarden, 1Password หรือ KeepassXC ที่มีส่วนขยาย (Extension) สำหรับ Linux

วิธีการตั้งค่าเริ่มต้น (Prerequisites)

  1. เว็บเบราว์เซอร์: Google Chrome, Chromium, Brave หรือ Mozilla Firefox (เวอร์ชันล่าสุด)
  2. แพ็กเกจระบบที่แนะนำ (สำหรับ Hardware Key): ติดตั้ง libfido2 เพื่อให้ระบบจดจำอุปกรณ์ FIDO2 USB
    • Debian/Ubuntu: sudo apt install libfido2-1
    • Arch Linux: sudo pacman -S libfido2
  3. เปิดใช้งาน Bluetooth: หากต้องการเชื่อมต่อ Passkey จากสมาร์ทโฟนเข้ากับเบราว์เซอร์บน Linux
  4. ส่วนขยาย (Optional): ติดตั้งส่วนขยายผู้ให้บริการ Passkey เช่น Bitwarden หรือ 1Password หากไม่ต้องการใช้การซิงก์ของ Google

ขั้นตอนการสร้าง Passkey บน Linux


รูปแบบที่ 1: บันทึกลงใน Google Password Manager (ผ่าน Chrome)

  1. เปิด Google Chrome บน Linux (พร้อมลงชื่อเข้าใช้ Google Account)
  2. ไปยังเว็บไซต์ที่ต้องการสร้าง Passkey
  3. ในหน้าตั้งค่าบัญชี เลือก Create a Passkey
  4. เบราว์เซอร์จะแสดงตัวเลือกการจัดเก็บ ให้เลือก Google Password Manager
  5. กดยืนยันเพื่อบันทึก Passkey ลงในบัญชี Google

รูปแบบที่ 2: ใช้ฮาร์ดแวร์ Security Key (เช่น YubiKey)

  1. เสียบฮาร์ดแวร์ Security Key เข้าช่อง USB ของเครื่อง Linux
  2. ในหน้าสร้าง Passkey บนเว็บไซต์ ให้เลือก “Use a security key”
  3. เบราว์เซอร์จะขอให้คุณแตะปุ่มสัมผัสบนตัว USB หรือใส่ PIN ของฮาร์ดแวร์กุญแจ
  4. กุญแจส่วนตัวจะถูกสร้างและเก็บไว้อย่างปลอดภัยในชิปฮาร์ดแวร์นั้น

ขั้นตอนการลงชื่อเข้าใช้ (Sign-In) ด้วย Passkey


การเข้าสู่ระบบด้วยสมาร์ทโฟน (Cross-Device Auth)

เนื่องจากคอมพิวเตอร์ Linux ส่วนใหญ่ไม่มีกล้องสแกนใบหน้าหรือสแกนนิ้วมือที่ผูกกับ PAM ในระดับเบราว์เซอร์ การใช้สมาร์ทโฟนจึงเป็นวิธีที่นิยมที่สุด

  1. คลิกปุ่ม Sign in with Passkey บนเว็บไซต์
  2. เบราว์เซอร์บน Linux จะแสดงหน้าต่างป๊อบอัพพร้อม QR Code
  3. เปิดกล้องบนสมาร์ทโฟน (iOS หรือ Android) แล้วสแกน QR Code
  4. ตรวจสอบให้แน่ใจว่าได้เปิด Bluetooth ทั้งบนเครื่อง Linux และสมาร์ทโฟนไว้
  5. ยืนยันตัวตนด้วย Face ID/สแกนนิ้ว บนมือถือ
  6. หน้าเว็บบน Linux จะล็อกอินให้โดยอัตโนมัติ

การใช้ Passkey ร่วมกับ Password Manager บน Linux

สำหรับผู้ใช้ Linux ที่ต้องการความอิสระและไม่ต้องการผูกติดกับ Google หรือ Apple การใช้ Password Manager ภายนอกเป็นโซลูชันที่มีประสิทธิภาพที่สุด

  1. ติดตั้งแอปพลิเคชันและ Browser Extension ของ Bitwarden หรือ 1Password บน Linux
  2. เมื่อเว็บไซต์ขอให้สร้าง Passkey ตัว Extension ของ Bitwarden/1Password จะแสดงป๊อบอัพแทรกขึ้นมาแทนเบราว์เซอร์
  3. กดปุ่ม Save Passkey
  4. เมื่อต้องการเข้าสู่ระบบในครั้งถัดไป ตัว Extension จะทำการเติม (Autofill) และยืนยัน Passkey ให้ทันทีผ่านการใส่ Master Password หรือ PIN ของ Password Manager นั้น ๆ

ข้อจำกัดและการแก้ไขปัญหาบน Linux (Troubleshooting)

  • Bluetooth ไม่จับคู่: หากไม่สามารถสแกน QR Code เพื่อเชื่อมโยงสมาร์ทโฟนได้ ให้ตรวจสอบการทำงานของ BlueZ daemon บน Linux โดยใช้คำสั่ง systemctl status bluetooth
  • การอนุญาตสิทธิ์ USB (udev rules): หากเบราว์เซอร์มองไม่เห็นฮาร์ดแวร์ YubiKey ให้ติดตั้งแพ็กเกจ plugdev หรือเพิ่ม udev rules สำหรับ FIDO devices เพื่อให้ผู้ใช้ทั่วไปมีสิทธิ์เข้าถึงพอร์ต USB ดังกล่าว

อ่านเพิ่มเติม

  • คู่มือการใช้งาน Passkey ร่วมกับ Bitwarden ในทุก ๆ เครื่อง
  • ทำไมองค์กรยักษ์ใหญ่ทั่วโลก ถึงพร้อมใจกันทิ้ง Password แล้วเปลี่ยนมาใช้ Passkey?
  • คู่มือการใช้งาน Passkey บน (iOS / iPadOS / macOS)
Tags: 1Password, Account, Android, Arch, Auth, Linux, Passkey, Security Key, Smartphone, Web Browser, WebAuthn

แนะแนวเรื่อง

PREVIOUS Previous post: API: Postman, Postwoman, Hoppscotch ย้ายสลับกันไปมา
NEXT Next post: สแกน Source Code หาช่องโหว่ด้วย SAST (Static Application Security Testing): ค้นหา Bug Security ตั้งแต่ตอนเขียน Code

Projects

  • Statement Columns Mapping Helper
  • PlusMagi Blocks
  • PlusMagi Site Search
  • PlusMagi Tags Reindex
  • jQuery Plus Repeater

Recent Posts

  • Apple แต่งตั้ง จอห์น เทอร์นัส (John Ternus) ขึ้นเป็น CEO โดยไม่ใช่ โจนี ไอฟ์ (Jony Ive)
  • Microsoft Coreutils for Windows: เมื่อคำสั่ง Linux ยอดฮิตพร้อมใช้งานแบบ Native บน Windows
  • AI: Ollama วิธีรัน AI บนเครื่องตัวเอง
  • 10 ปีที่ผ่านมา IT เปลี่ยนไปแค่ไหน? สรุปเทคโนโลยีและสถาปัตยกรรมยุคใหม่ที่สาย Dev & Infra ต้องอัปเดตด่วน
  • Legacy Modernization Checklist: เทคนิคถอด Business Logic จาก PowerBuilder 8 สู่ C# .NET Core / Java Web API

Archives

Categories

  • .net core (7)
  • Action Genre (1)
  • Archaeology (1)
  • art (77)
  • Artificial Intelligence (1)
  • Astronomy (2)
  • Automotive History (1)
  • Bioengineering (1)
  • business (880)
    • Business Analysis (322)
    • Finance (32)
    • Real Estate (24)
  • cd (40)
  • chemistry (1)
  • ci (40)
  • CMS (21)
  • collaboration (1)
  • Comics (1)
  • Command Line Interface (1)
  • Communication (96)
  • Computer Hardware (44)
  • computer science (1,843)
    • AI (390)
    • Biology (60)
      • Environment (34)
    • Cloud Computing (318)
    • Data Visualization (45)
    • Mathematics (44)
  • container (28)
  • Cosmology (2)
  • Culture (147)
  • data engineering (1)
  • data management (1)
  • Data Privacy (29)
  • Data Transformation (67)
  • Defense Technology (1)
  • Design (332)
    • UX/UI (45)
  • development (1)
  • devops (6)
  • Digital Electronics (1)
  • digital marketing (1)
  • e-learning (1)
  • Earth Science (1)
  • Ecology (1)
  • Education (3)
  • engineering (818)
    • architecture (709)
    • Building Engineering (50)
  • Entertainment (1)
  • Environmental Science (1)
  • Environmentalism (1)
  • Fantasy Literature (1)
  • Film (2)
  • film studies (2)
  • Forensic Science (1)
  • Geology (1)
  • Grammar (1)
  • graph theory (1)
  • Hardware (2)
  • Health (159)
    • Safety (127)
  • Health Science (1)
  • Humanities (395)
    • Academia (161)
    • history (113)
    • Linguistics (16)
    • Literature (98)
  • information retrieval (1)
  • Information Science (3)
  • International Relations (1)
  • Language Arts (1)
  • Law (302)
  • library science (1)
  • Life (1,500)
    • Cartoon (41)
    • D.I.Y (57)
    • Mindset (311)
    • Movies (57)
    • Philosophy (229)
    • Psychology (1,071)
      • Behavioral Science (294)
      • Cognitive Science (257)
    • Sci-Fi (66)
    • Tips and Tricks (32)
    • พุทธ (7)
  • logistics (1)
  • management (889)
    • knowledge management (294)
      • Documentation (98)
    • productivity (5)
    • Project Management (13)
    • strategy (3)
  • Marketing (1)
  • Markup Languages (1)
  • Mechanical Engineering (2)
  • Media (1)
  • media studies (3)
  • military history (1)
  • Military Technology (1)
  • Mystery (1)
  • Mythology (1)
  • Network (388)
    • IOT (24)
    • Nginx (26)
  • networking (17)
  • operating system (15)
  • Operating Systems (574)
    • Linux (207)
    • macOS (141)
      • Homebrew (25)
    • Shell Script (38)
      • Oh My ZSH (5)
    • Windows (99)
      • PowerShell (26)
  • physics (1)
  • Pop Culture (1)
  • popular culture (1)
  • Process Management (1)
  • Process Modeling (1)
  • Programming (2,154)
    • .NET (115)
      • .NET Core EF (9)
      • C# (74)
    • API (432)
      • REST (8)
    • Database (662)
      • MariaDB (38)
      • MySql (69)
      • Oracle Database (24)
      • PostgreSQL (14)
      • RDBMS (55)
      • SQL Server (76)
        • T-SQL (26)
    • Programming Languages (366)
      • Java (95)
      • PHP (216)
      • Python (13)
      • Rust (31)
    • Software Architecture (7)
    • Software Engineering (48)
    • System Analyst (SA) (56)
    • Testing (122)
      • Automated Testing (108)
    • Web (1,403)
      • Apache HTTP Server (34)
      • Backend (1,112)
        • Laravel (54)
        • Spring Boot (15)
      • Frontend (302)
        • Angular (9)
        • CSS (50)
        • JavaScript (187)
        • jQuery (57)
        • Tabulator (24)
        • Tailwind CSS (4)
        • Vue.js (6)
      • WordPress (31)
  • Programming Language (3)
  • Religion (1)
  • Science (1)
  • Science Fiction (9)
  • SecDevOps (781)
    • automation (238)
    • CI/CD (137)
    • Docker (89)
    • GIT (56)
    • SVN (6)
    • system (229)
      • System Administration (20)
  • Security (417)
    • Authentication (80)
    • Cryptography (41)
    • Cybersecurity (210)
  • Sensory Technology (1)
  • Server Infrastructure (1)
  • Sociology (2)
  • Software Design (1)
  • Software Development (4)
  • software development lifecycle (1)
  • Software Development Practices (1)
  • Software Testing (1)
  • Space Exploration (1)
  • Spirituality (1)
  • sports (1)
  • SQL (1)
  • Storage Systems (1)
  • Storytelling (1)
  • Supply Chain Management (1)
  • system architecture (1)
  • system design (3)
  • System Modeling (3)
  • Systems Modeling (1)
  • Systems Programming (1)
  • Technical Support (1)
  • technology (3)
  • Technology History (1)
  • Uncategorized (660)
  • user experience (2)
  • User Experience Design (1)
  • Version Control (3)
  • visualization (1)
  • Web Design (1)
  • web development (25)
  • web technology (1)
  • wellness (2)
  • นวนิยายสืบสวน (1)
  • วรรณกรรม (1)
  • เรื่องเล่า (1)

Sirat WordPress Theme By VWThemes

Scroll Up
Go to mobile version