pam_tid.so asks for password instead of requesting for fingerprint

I used to use auth sufficient pam_tid.so in the /private/etc/pam.d/sudo file to allow fingerprint authentification when using sudo command.

Suddenly, this stopped working. Instead of asking for fingerprint, it asks me for password in the GUI (not in the terminal).


Before:


Now:


Is there a solution?


Thank you


MacBook Pro 14″, macOS 14.0

Posted on Oct 5, 2023 5:12 PM

Reply
Question marked as Top-ranking reply

Posted on Oct 5, 2023 6:22 PM

That modification as described will not survive even an incremental macOS update.


However...


  • Touch ID can be allowed for sudo with a configuration that persists across software updates using /etc/pam.d/sudo_local. See /etc/pam.d/sudo_local.template for details.


What's new for enterprise in macOS Sonoma - Apple Support

9 replies

Oct 20, 2023 9:55 PM in response to zero__0

It’s happening on everything I try to sign into. There’s never the opportunity to use my fingerprint. I have to keep entering my Mac login password. I disabled it for Autofilling passwords. It’s easier to just click on my login email that pops up and have it autofill the password to get in. Touch ID works to unlock my Mac but nothing else works with it.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

pam_tid.so asks for password instead of requesting for fingerprint

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.