A PAM module for authentication with Touch ID.
The module takes an optional parameter: "reason".
Its value will be shown in the dialog presented to the user.
If the argument is omitted, generic text is used.
Warning:
Do not procede unless you're 1,000,000% sure what you're doing.
If you're only 999,999% sure, then turn back now.
pam_touchid.so.2
to /usr/local/lib/pam/
and set:
/etc/pam.d/sudo
in your favourite text editorauth sufficient pam_touchid.so reason="execute a command as another user"
to the top of the fileThe procedure is pretty much the same for any other process, but you'd edit a different config file and probably change the reason too.
su
to put the config file back