Skip to content

Auth: Enroll CryptAuth user key for Workspace screenlock requirement - #3834

Open
shah-newaz wants to merge 1 commit into
microg:masterfrom
shah-newaz:cryptauth-enroll-user-key
Open

shah-newaz wants to merge 1 commit into
microg:masterfrom
shah-newaz:cryptauth-enroll-user-key

Conversation

@shah-newaz

Copy link
Copy Markdown

Related: #2847, #3561

Problem

Google Workspace accounts whose admin enabled basic mobile management fail token requests with Error=DeviceManagementScreenlockRequired. Gmail shows "Getting your messages" forever and Calendar keeps loading, while regular accounts work fine.

microG already resolves this error with a CryptAuth syncKeys + enrollKeys round trip. But enrollKeys is sent with an empty enrollSingleKeyRequests, even though the syncKeys response asks the client to create a P256 key:

"syncSingleKeyResponses": [{ "keyActions": ["ACTIVATE"], "keyCreation": "ACTIVE", "keyType": "P256", ... }]

The server returns {} for enrollKeys but keeps rejecting tokens. Every new token request from the apps then triggers another round trip (7 in 75 seconds in my logs), until the server rate limits it (HTTP 429 RESOURCE_EXHAUSTED, as seen in #2847).

Changes

  • Enroll a real user key. When syncKeys requests creation of the PublicKey key, microG creates a P256 key pair per account (stored in private shared preferences) and enrolls it:
    • keyMaterial: serialized SecureMessage GenericPublicKey (EC_P256, x/y big-endian two's complement)
    • keyProof: ECDSA SHA-256 (DER) signature over "CryptAuth Key Proof" || randomSessionId, as done by Chromium's CryptAuth v2 client (CryptAuthKeyProofComputerImpl)
    • newKeyHandle: SHA-256 of the key material. Later syncKeys requests send this handle instead of the placeholder device_key.
  • Retry cap. Cryptauth resolution is limited to 3 attempts per account per hour. This matches the retryAttempts: 3 returned by the server and prevents the 429 loop.
  • Metadata fixes. device_display_diagonal_mils was inch / 1000 (always 0) and is now inch * 1000. device_os_release now sends Build.VERSION.RELEASE, with the codename moved to device_os_codename.

Testing

Device: Huawei Pura 90 Pro Max, HarmonyOS (Android API 36), Workspace account with screen lock policy, device screen lock enabled.

  • Before (official 0.3.16.252432-hw): endless DeviceManagementScreenlockRequired, then CryptAuthSyncKeys, then an empty enroll, then a retry loop. Gmail and Calendar never load.
  • After (debug build of this branch):
    • The server requested key creation and the key was enrolled.
    • On later sign-ins of the Workspace account, no DeviceManagementScreenlockRequired appeared and no cryptauth round trip was needed.
    • Token requests (ac2dm, userinfo.profile, googlenow) for the Workspace account succeeded.

Limitation: on HarmonyOS, signature spoofing is only honored for allowlisted signing certificates. A locally built (debug-signed) APK therefore fails Google apps' signature check ("Device not compatible"), so I could not test Gmail/Calendar scopes end to end. For testing, I temporarily made microG report the GMS signature for its own token requests (not part of this PR).

Request: could a maintainer provide a signed -hw test build of this branch, so Huawei/HarmonyOS users in #3561 / #2847 can confirm that Gmail and Calendar sync with Workspace accounts?

Workspace accounts with basic mobile management fail token requests with
DeviceManagementScreenlockRequired. microG resolves this with a CryptAuth
SyncKeys/EnrollKeys round trip, but EnrollKeys was sent with no keys even
though the server asks for a P256 user key (keyCreation ACTIVE). The
server keeps rejecting tokens, and as apps keep retrying, the resolution
loops until it is rate limited (HTTP 429), leaving Gmail and Calendar
loading forever.

- Create a P256 user key per account when requested by SyncKeys and
  enroll it with a SecureMessage GenericPublicKey as key material and an
  ECDSA key proof over the random session id, as done by the CryptAuth v2
  client. Send the enrolled key's handle in subsequent SyncKeys requests.
- Limit cryptauth resolution to 3 attempts per account per hour.
- Fix display diagonal (inch * 1000 = mils) and OS release/codename in
  the client app metadata.

Related: microg#2847, microg#3561
@shah-newaz

Copy link
Copy Markdown
Author

Request: could a maintainer provide a signed -hw test build of this branch, so Huawei/HarmonyOS users in #3561 / #2847 can confirm that Gmail and Calendar sync with Workspace accounts?

@SahilSonar

Copy link
Copy Markdown

@shah-newaz I tried this with my workspace account it. It resolves Sign in with Google on apps (Chatgpt) and Google Maps forever loading Explore sheet.

@mar-v-in could you please look into this? Thanks!

@microtoy

microtoy commented Oct 7, 2026

Copy link
Copy Markdown

Hi @shah-newaz and @mar-v-in, could a maintainer provide an officially signed Huawei (-hw) test APK for this PR's current commit (6029b1b)?

I can test on a Huawei Mate 40 Pro+ (NOP-AN00), HarmonyOS 4.2 / Android API 31, currently running official microG Services 0.3.17.252432-hw.

On the current official build:

  • A Google Workspace account can be added, but stays marked as an account error in native Google sign-in pickers across apps. Personal Google accounts work.
  • The reproducible authentication error is DeviceManagementScreenlockRequired.
  • A secure screen lock is enabled, as are Google device registration and “Authenticate with device registration.” The reported secure-screenlock flag was verified as true. Re-adding the account did not resolve the problem.

Temporary browser workaround: On this phone, Chrome's “Use another account” handed the flow back to microG's add-account activity. Using Huawei Browser 17.0.8.310 instead kept the flow on Google's web sign-in pages, and the same Workspace account successfully signed into ChatGPT on the web. This restores web access only; it does not establish that the native account/token issue is fixed.

The native ChatGPT app also showed Preauth PlayIntegrity verification failed. I am treating that as a separate issue, not claiming this PR fixes it.

I have not installed or tested this PR's APK. Because locally signed builds have the Huawei signature-compatibility limitation described above, an officially signed -hw test build would allow a meaningful test without replacing the currently working framework with an incompatible package.

Thank you!

@shah-newaz

Copy link
Copy Markdown
Author

Hi @mar-v-in - can we please get someone on this PR? I think it's critical and disrupts day to day use for many users.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] Unable to sync Google Workspace (Work) account

3 participants