+{ ... }:
+{
+ security.pam = {
+ u2f = {
+ enable = true;
+ cue = true;
+ # interactive = true;
+ control = "sufficient";
+ # appId = "pam://${config.networking.fqdn}";
+ };
+ services = {
+ login.u2fAuth = true;
+ sudo.u2fAuth = true;
+ kde.u2fAuth = true;
+ kdewallet.u2fAuth = true;
+ sddm.u2fAuth = true;
+ };
+ };
+}