Repository navigation
Auth: Enroll CryptAuth user key for Workspace screenlock requirement - #3834
shah-newaz wants to merge 1 commit into
Conversation
Workspace accounts with basic mobile management fail token requests with DeviceManagementScreenlockRequired. microG resolves this with a CryptAuth SyncKeys/EnrollKeys round trip, but EnrollKeys was sent with no keys even though the server asks for a P256 user key (keyCreation ACTIVE). The server keeps rejecting tokens, and as apps keep retrying, the resolution loops until it is rate limited (HTTP 429), leaving Gmail and Calendar loading forever. - Create a P256 user key per account when requested by SyncKeys and enroll it with a SecureMessage GenericPublicKey as key material and an ECDSA key proof over the random session id, as done by the CryptAuth v2 client. Send the enrolled key's handle in subsequent SyncKeys requests. - Limit cryptauth resolution to 3 attempts per account per hour. - Fix display diagonal (inch * 1000 = mils) and OS release/codename in the client app metadata. Related: microg#2847, microg#3561
|
@shah-newaz I tried this with my workspace account it. It resolves Sign in with Google on apps (Chatgpt) and Google Maps forever loading Explore sheet. @mar-v-in could you please look into this? Thanks! |
|
Hi @shah-newaz and @mar-v-in, could a maintainer provide an officially signed Huawei ( I can test on a Huawei Mate 40 Pro+ (NOP-AN00), HarmonyOS 4.2 / Android API 31, currently running official microG Services 0.3.17.252432-hw. On the current official build:
Temporary browser workaround: On this phone, Chrome's “Use another account” handed the flow back to microG's add-account activity. Using Huawei Browser 17.0.8.310 instead kept the flow on Google's web sign-in pages, and the same Workspace account successfully signed into ChatGPT on the web. This restores web access only; it does not establish that the native account/token issue is fixed. The native ChatGPT app also showed I have not installed or tested this PR's APK. Because locally signed builds have the Huawei signature-compatibility limitation described above, an officially signed Thank you! |
|
Hi @mar-v-in - can we please get someone on this PR? I think it's critical and disrupts day to day use for many users. |
Related: #2847, #3561
Problem
Google Workspace accounts whose admin enabled basic mobile management fail token requests with
Error=DeviceManagementScreenlockRequired. Gmail shows "Getting your messages" forever and Calendar keeps loading, while regular accounts work fine.microG already resolves this error with a CryptAuth
syncKeys+enrollKeysround trip. ButenrollKeysis sent with an emptyenrollSingleKeyRequests, even though thesyncKeysresponse asks the client to create a P256 key:The server returns
{}forenrollKeysbut keeps rejecting tokens. Every new token request from the apps then triggers another round trip (7 in 75 seconds in my logs), until the server rate limits it (HTTP 429RESOURCE_EXHAUSTED, as seen in #2847).Changes
syncKeysrequests creation of thePublicKeykey, microG creates a P256 key pair per account (stored in private shared preferences) and enrolls it:keyMaterial: serialized SecureMessageGenericPublicKey(EC_P256, x/y big-endian two's complement)keyProof: ECDSA SHA-256 (DER) signature over"CryptAuth Key Proof" || randomSessionId, as done by Chromium's CryptAuth v2 client (CryptAuthKeyProofComputerImpl)newKeyHandle: SHA-256 of the key material. LatersyncKeysrequests send this handle instead of the placeholderdevice_key.retryAttempts: 3returned by the server and prevents the 429 loop.device_display_diagonal_milswasinch / 1000(always 0) and is nowinch * 1000.device_os_releasenow sendsBuild.VERSION.RELEASE, with the codename moved todevice_os_codename.Testing
Device: Huawei Pura 90 Pro Max, HarmonyOS (Android API 36), Workspace account with screen lock policy, device screen lock enabled.
DeviceManagementScreenlockRequired, thenCryptAuthSyncKeys, then an empty enroll, then a retry loop. Gmail and Calendar never load.DeviceManagementScreenlockRequiredappeared and no cryptauth round trip was needed.ac2dm,userinfo.profile,googlenow) for the Workspace account succeeded.Limitation: on HarmonyOS, signature spoofing is only honored for allowlisted signing certificates. A locally built (debug-signed) APK therefore fails Google apps' signature check ("Device not compatible"), so I could not test Gmail/Calendar scopes end to end. For testing, I temporarily made microG report the GMS signature for its own token requests (not part of this PR).
Request: could a maintainer provide a signed
-hwtest build of this branch, so Huawei/HarmonyOS users in #3561 / #2847 can confirm that Gmail and Calendar sync with Workspace accounts?