on fedora sssd is the standard way to configure smartcards.
sudo dnf install pcsc-lite pcsc-lite-ccid opensc pcsc-tools
sudo systemctl enable --now pcscd
# ==============================================================================
# FEDORA KDE NITROKEY SMARTCARD LOGIN SETUP
# Run this entire block as your normal user.
# It will prompt for your sudo password and Nitrokey PIN when needed.
# ==============================================================================
# 1. Install necessary dependencies and configure services
sudo dnf install -y opensc pcsc-lite pcsc-tools authselect sssd-pkcs11 pamtester
sudo systemctl enable --now pcscd.socket
# 2. Build local certificate directories
mkdir -p ~/.config/Nitrokey && cd ~/.config/Nitrokey
# 3. Create OpenSSL configuration for your local username
cat > cert_config.cnf <<EOF
[ req ]
distinguished_name = req_distinguished_name
prompt = no
[ req_distinguished_name ]
CN = $(whoami)
EOF
# 4. Generate the X.509 certificate wrapper shell
openssl req -new -x509 -days 3650 -config cert_config.cnf -keyout dummy.key -out nitrokey_user.crt -nodes
# 5. Flash the certificate onto your Nitrokey (Enter your User/Admin PIN when prompted)
pkcs15-init --store-certificate nitrokey_user.crt --id 45 --auth-id 01
# 6. Apply system-wide smartcard authentication profiles
sudo authselect select sssd with-smartcard --force
# 7. Write the SSSD certificate local user account mapping rule
sudo tee /etc/sssd/conf.d/sssd_certmap.conf > /dev/null <<EOF
[domain/local]
id_provider = files
[certmap/local/$(whoami)]
matchrule = <SUBJECT>.*CN=$(whoami).*
EOF
# 8. Restart background authentication services
sudo systemctl restart sssd
# 9. Configure SDDM (KDE Login Manager) to unblock hardware tokens
if [ ! -f /etc/sddm.conf ]; then sudo touch /etc/sddm.conf; fi
sudo sed -i '/\[General\]/,/^\[/ { /InputMethod=/d }' /etc/sddm.conf
sudo sed -i 's/\[General\]/\[General\]\nInputMethod=/' /etc/sddm.conf
if ! grep -q "\[General\]" /etc/sddm.conf; then
echo -e "[General]\InputMethod=" | sudo tee -a /etc/sddm.conf > /dev/null
fi
# 10. Restart hardware communication sockets
sudo systemctl restart pcscd.socket pcscd.service
# ==============================================================================
# VERIFICATION (Run this final command to test your PIN login)
# ==============================================================================
echo "--- TESTING AUTHENTICATION ---"
pamtester login $(whoami) authenticate