Skip to content

Use Touch ID for sudo on macOS Sonoma and newer

On macOS Sonoma and newer, you can enable Touch ID for sudo with a local PAM file that survives system updates.

I type sudo several times a day, and my Mac has a fingerprint reader right next to the keyboard. For years, getting sudo to use it meant editing /etc/pam.d/sudo, and every macOS update quietly put the file back. I re-applied the same edit after every single update.

Short version: since macOS Sonoma, /etc/pam.d/sudo includes a file called sudo_local that updates leave alone. Copy it from the template Apple ships, uncomment the pam_tid.so line, and sudo asks for your fingerprint.

How the local file works

sudo authenticates through PAM, a stack of modules listed in /etc/pam.d/sudo. That file is owned by the system, so updates overwrite it. On Sonoma, its first line pulls in sudo_local, which only exists if you create it. Apple ships sudo_local.template next to it as the starting point.

The module that talks to Touch ID is pam_tid.so. It’s marked sufficient, so a fingerprint is enough on its own, and if Touch ID isn’t available or you cancel the prompt, PAM moves on to the password as before.

Enable Touch ID for sudo

Check that the template is there:

Terminal window
$ cd /etc/pam.d
$ ls -l sudo*
.r--r--r-- 283 root 16 Sep 15:28 sudo
.r--r--r-- 179 root 16 Sep 15:28 sudo_local.template

Copy it and open the copy. The -n keeps an existing sudo_local, in case you’ve set one up before:

Terminal window
sudo cp -n sudo_local.template sudo_local
sudo -e sudo_local

Uncomment the pam_tid.so line so the file reads:

/etc/pam.d/sudo_local
# sudo_local: local config file which survives system update and is included for sudo
# uncomment following line to enable Touch ID for sudo
auth sufficient pam_tid.so

Open a new terminal and run any sudo command. You get the Touch ID prompt instead of the password prompt.

Where it doesn’t work

The prompt needs the GUI session, so it falls back to the password in a few places: over SSH, with the lid closed and no external Touch ID keyboard, and inside tmux. I use tmux, so the last one is the one I needed fixed.

pam_reattach fixes it by moving sudo back into your GUI session before pam_tid.so runs. Install it with Homebrew:

Terminal window
brew install pam-reattach

Then add it above the Touch ID line, as the pam_reattach README describes. On Apple silicon, Homebrew installs into /opt/homebrew, where PAM doesn’t look, so the module needs its full path. On an Intel Mac it lands in /usr/local/lib/pam, and plain pam_reattach.so is enough. brew --prefix tells you which one you have.

/etc/pam.d/sudo_local
# sudo_local: local config file which survives system update and is included for sudo
auth optional /opt/homebrew/lib/pam/pam_reattach.so ignore_ssh
auth sufficient pam_tid.so

ignore_ssh keeps it from offering Touch ID in a tmux session you attached to over SSH, where nobody is sitting at the fingerprint reader.

To undo it, comment out the pam_tid.so line again, or delete sudo_local.

References

Published
Updated
Reading
2 min