Setting Up a Nitrokey FIDO2 for sudo, su, and Linux Login - TUXEDO Computers

  • Notebooks
    • Notebooks/Laptops with preinstalled and configured Linux and more. TUXEDO Computers are individually built computers and PCs being fully Linux-suitable, custom tailored Linux hardware so to say. We deliver all TUXEDOs ready to go so you only ha...
    • 10-14 inch
    • 15-16 inch
    • 17 inch
    • Immediate shipping
    • Business notebooks
    • Gaming-Notebooks
    • Mobility notebooks
    • Deep Learning AI
    • All Notebooks
  • Computers / PCs
    • Computers / PCs with Linux preinstalled & more TUXEDO Computers are individually built computers and PCs being fully Linux-suitable, custom tailored Linux hardware so to say :) We deliver all TUXEDOs ready to go so you only have to unwrap,...
    • Mini Systems
    • Midi Systems
    • Maxi Systems
    • AMD Systems
    • Intel Systems
    • All Systems
  • Accessories
    • Here you will find accessories, components and peripherals for your TUXEDO system. Nothing suitable found here? Get in touch with us directly!
    • Batteries
    • Displays
    • Dockingstations
    • Books
    • Input Devices & Peripherals
    • Bags & Sleeves
    • Notebook Power Supplies & Cords
    • Components & Complements
      • Cables
      • Drives
      • Hard Disk Drives 2.5"
      • PC Power Supplies
      • SSDs 2.5"
      • SSDs m.2 (SATAIII and NVMe)
      • WiFi, LAN & Mobile Network
      • Licenses
  • B2B
    • In this category you can find equipment for your company, office, school, university or educational institution and servers and solutions. Appliances with CRM, ERP and merchandise management, cloud storage, cloud server for self-hosting, services...
    • Business notebooks
    • Business computers
  • Novelties
  •  
    • Notebooks
      • 10-14 inch
      • 15-16 inch
      • 17 inch
      • Immediate shipping
      • Business notebooks
      • Gaming-Notebooks
      • Mobility notebooks
      • Deep Learning AI
      • All Notebooks
    • Computers / PCs
      • Mini Systems
      • Midi Systems
      • Maxi Systems
      • AMD Systems
      • Intel Systems
      • All Systems
    • Accessories
      • Batteries
      • Displays
      • Dockingstations
      • Books
      • Input Devices & Peripherals
      • Bags & Sleeves
      • Notebook Power Supplies & Cords
      • Components & Complements
        • Cables
        • Drives
        • Hard Disk Drives 2.5"
        • PC Power Supplies
        • SSDs 2.5"
        • SSDs m.2 (SATAIII and NVMe)
        • WiFi, LAN & Mobile Network
        • Licenses
    • B2B
      • Business notebooks
      • Business computers
    • Novelties
  • Settings

  • Deutsch
  • English

  • Customer Account

  • Log in
  ATTENTION: To use our store you have to activate JavaScript and deactivate script blockers!  
Thank you for your understanding!

Setting Up a Nitrokey FIDO2 for sudo, su, and Linux Login

2026-09-23 15:41:25

A FIDO2 security key is good for more than web services such as GitHub, Google or other passkey-compatible offerings. Through the PAM module pam-u2f you can tie a FIDO2 key straight into the authentication of your Linux system.

The security key then covers sudo, su or the graphical login. Instead of typing a password, you plug in the key and confirm the request with a touch. The key thereby takes on a central role in signing in.

This guide applies to the Nitrokey FIDO2, to YubiKeys and to other compatible U2F and FIDO2 authenticators. Alongside YubiKeys, pam-u2f expressly supports other devices that speak the U2F or FIDO2 standard.

Note: We tested the configuration described here with a Nitrokey FIDO2 under TUXEDO OS 24.04 only. With other FIDO2 keys, with Ubuntu or Debian derivatives and with other display managers, individual steps or configuration files may differ.

In this guide you set up the FIDO2 key for three cases:

  • authentication with sudo
  • switching users with su
  • graphical login through SDDM

The examples use the Linux user tux. At the end of the article you will also find a digression on why a FIDO2 key cannot readily unlock LUKS at boot under TUXEDO OS at present.

  • PAM and pam-u2f under Linux
  • Installing the required packages
  • Registering the FIDO2 key
  • Creating the credential file
  • Configuring FIDO2 for sudo
    • Testing sudo
  • Configuring FIDO2 for su
    • Configuring FIDO2 for root
  • Configuring FIDO2 for the graphical login
  • Why a central file pays off
  • Nitrokey, YubiKey or password?
  • PIN and user verification
  • Notes and tips
    • What happens if you lose the Nitrokey?
    • Keep a second root session open
    • What to do when the login stops working
    • Do not carry the configuration over blindly
  • Beyond the login: FIDO2 for unlocking LUKS at boot

PAM and pam-u2f under Linux

PAM stands for „Pluggable Authentication Modules“. It is a Linux infrastructure through which programs hand authentication over to separate modules. Applications therefore do not have to build the individual authentication methods themselves.

Rather than checking on its own whether a password, a smartcard or a FIDO2 key comes into play, a program passes authentication to PAM. Different applications can thus share the same authentication methods without each having to provide them separately.

For authentication with a FIDO2 key, the module pam_u2f does the work. It comes from Yubico’s pam-u2f project. Despite the name, the module supports modern FIDO2 authenticators alongside the older U2F standard.

Installing the required packages

Under TUXEDO OS you install pam-u2f straight from the package sources. Open a terminal and install the required packages:

sudo apt update
sudo apt install libpam-u2f pamu2fcfg

The package libpam-u2f contains the PAM module itself. pamu2fcfg registers a FIDO2 key and generates the configuration needed for it. The official pam-u2f documentation names both packages for Ubuntu as well.

You can install the FIDO2 tools on top of that. Among other things, they help you spot connected security keys and check their properties:

sudo apt install fido2-tools

fido2-token -L then shows whether the system recognises the connected key:

fido2-token -L
(out)/dev/hidraw1: vendor=0x20a0, product=0x42b1 (Nitrokey Nitrokey FIDO2 2.4.0)

As an alternative, lsusb tells you whether the security key turns up on the USB bus:

lsusb
(out)[...]
(out)Bus 003 Device 007: ID 20a0:42b1 Clay Logic Nitrokey FIDO2 2.4.0

Registering the FIDO2 key

Next you register the FIDO2 key for your Linux user. Plug in the Nitrokey and run the following command as the user tux:

pamu2fcfg -u $USER

The program then asks you to touch the security key. After a successful registration, pamu2fcfg prints a configuration line. Among other things, it holds the cryptographic credential of the FIDO2 key:

tux:3...d/5FA==,es256,+presence

The real line is a good deal longer. The entry +presence means that authentication checks the physical presence of the user. You therefore have to operate the security key yourself, as a rule by touching it.

pamu2fcfg applies this check by default. -P, or --no-user-presence, switches it off. For a physical security key you should normally leave the option alone, since it drops an additional safeguard.

Creating the credential file

pam-u2f needs a mapping between the Linux user and the registered FIDO2 credential. By default it can live in the user’s home directory under ~/.config/Yubico/u2f_keys.

For several PAM services, however, a central file is handier. This guide uses /etc/u2f_mappings for that purpose. sudo, su and the display manager can then share the file.

First create the file with suitable ownership and permissions:

sudo install -o root -g root -m 600 /dev/null /etc/u2f_mappings

Then write the registration you created earlier straight into the file:

pamu2fcfg -u $USER | { cat; printf '\n'; } | sudo tee -a /etc/u2f_mappings

The Nitrokey has to be connected and touched when prompted. The file then holds a line along these lines:

tux:3...d/5FA==,es256,+presence

The real credential line should neither be published nor passed on to others. /etc/u2f_mappings therefore carries permissions 600 and is readable by root alone.

pam-u2f also supports several FIDO2 authenticators. You can therefore register a second security key as a spare later on. The additional credentials go into the same mapping file.

Configuring FIDO2 for sudo

Now you switch on the Nitrokey for sudo. The matching PAM configuration sits in /etc/pam.d/sudo.

Warning: Before you change anything in PAM, keep a second root shell open, or at least one other working login. A faulty PAM configuration can cut off access to user accounts or root privileges.

Open the file, for instance with:

sudoedit /etc/pam.d/sudo

Look for the existing line:

@include common-auth

Add the following line above it:

auth sufficient pam_u2f.so authfile=/etc/u2f_mappings

The relevant section then reads:

auth sufficient pam_u2f.so authfile=/etc/u2f_mappings
@include common-auth

sudo can now try the FIDO2 key first. One successful authentication is enough. If the key is missing or FIDO2 authentication fails, the normal authentication through common-auth takes over.

That gives you two routes: Nitrokey connected » touch the Nitrokey » authentication succeeds, or Nitrokey unavailable » type the password » authentication succeeds. You can therefore run a command such as the following without typing your user password:

sudo apt update

The prerequisite is a connected Nitrokey and a touch to confirm the request.

Testing sudo

After the change, test sudo on its own first. sudo -k clears any cached authentication:

sudo -k
sudo -v

sudo should now recognise the FIDO2 key and ask for a touch. Confirm the request by touching the Nitrokey.

Check the password fallback afterwards. Unplug the Nitrokey, run sudo -k again and then start a sudo command. The usual password prompt should appear.

Both routes should work before you move on to the next PAM configurations.

Configuring FIDO2 for su

su goes through PAM as well and can therefore authenticate through pam_u2f. The matching configuration sits in /etc/pam.d/su. Add the following line to the auth section there too:

auth sufficient pam_u2f.so authfile=/etc/u2f_mappings

A typical configuration can look like this:

# This allows root to su without passwords (normal operation)
auth       sufficient pam_rootok.so
auth sufficient pam_u2f.so authfile=/etc/u2f_mappings

Leave the existing pam_rootok.so line in place. It lets root switch users through su without further authentication.

Note as well that the credential of the user tux does not carry over to root. If the Nitrokey is to serve for a switch to root, then root needs a credential of its own.

Configuring FIDO2 for root

The following command switches you to the user root. For the login you type the dedicated root password, which you set under TUXEDO OS with sudo passwd root.

su -

If the FIDO2 key is to handle authentication here, first register a credential for root:

pamu2fcfg -u root | { cat; printf '\n'; } | tee -a /etc/u2f_mappings

The printed line lands in /etc/u2f_mappings as an additional credential. The file then holds:

cat /etc/u2f_mappings
(out)tux:rL...0Q==,es256,+presence
(out)root:43...Dg==,es256,+presence

The FIDO2 key can now authenticate you as root as well. In day-to-day work, though, you should weigh whether you need su at all. On Ubuntu and systems derived from it, sudo is the customary route for administrative tasks.

Configuring FIDO2 for the graphical login

Next you can put the FIDO2 key to work for the graphical login. TUXEDO OS with KDE Plasma uses SDDM (Simple Desktop Display Manager) for that by default. SDDM draws on PAM for authentication as well. The matching settings sit in /etc/pam.d/sddm.

Here too, add the following line to the auth section above @include common-auth:

auth sufficient pam_u2f.so authfile=/etc/u2f_mappings

Do not replace the whole existing PAM configuration while doing so. The entries already there stay. Add the FIDO2 line at a suitable spot in the authentication section and nothing else. After the edit, the head of the file should read roughly like this:

#%PAM-1.0

# Block login if they are globally disabled
auth    requisite       pam_nologin.so
auth    required        pam_succeed_if.so user != root quiet_success

# auth    sufficient      pam_succeed_if.so user ingroup nopasswdlogin

auth sufficient pam_u2f.so authfile=/etc/u2f_mappings
@include common-auth
# gnome_keyring breaks QProcess
-auth   optional        pam_gnome_keyring.so
-auth   optional        pam_kwallet5.so
[...]

The resulting sequence runs like this: SDDM » pick your user » plug in the Nitrokey » touch the Nitrokey » press Enter » KDE Plasma starts. Since common-auth remains as a fallback, you can still sign in with your normal user password whenever the Nitrokey is out of reach.

Why a central file pays off

For sudo, a credential file in the user’s home directory can do the job. For the graphical login it is less practical, because the display manager handles authentication before the user session starts.

A central file such as /etc/u2f_mappings therefore suits this case. It stands available to the various PAM services independently of the home directory and can be shared by sudo, su and SDDM.

The central file also eases the handling of several security keys. If you want a second FIDO2 authenticator as a spare, you can store its credential in the same file.

Nitrokey, YubiKey or password?

The configuration described here deliberately uses the PAM control flag sufficient:

auth sufficient pam_u2f.so authfile=/etc/u2f_mappings

One successful FIDO2 authentication is therefore enough. If it fails, or if the key is out of reach, the password authentication that follows through common-auth can take over.

This is not classic two-factor authentication. Instead, two alternative routes stand side by side: Nitrokey plus touch, or the familiar password prompt.

A true two-factor setup would ask for the password first and the FIDO2 key afterwards. That is possible as well, but calls for a different PAM configuration.

PIN and user verification

Besides user presence, FIDO2 can call for a PIN, also known as „user verification (UV)“. That adds another layer to the authentication.

The following command registers a credential that calls for PIN verification:

pamu2fcfg -u tux -N

pamu2fcfg supports the following options, among others:

pamu2fcfg --help
(out)[...]
(out)  -P, --no-user-presence   Allow the credential to be used without ensuring the
(out)                             user's presence  (default=off)
(out)  -N, --pin-verification   Require PIN verification during authentication
(out)                             (default=off)
(out)  -V, --user-verification  Require user verification during authentication
(out)[...]

For the configuration described here, a registration with user presence is normally enough. The printed credential then carries +presence.

Which variant makes sense depends on the security level you want and on the FIDO2 authenticator in use. Support for individual features can differ from one security key to the next.

Notes and tips

What happens if you lose the Nitrokey?

If you use a security key for signing in to Linux, give some thought to failure while you set it up. A lost, damaged or momentarily missing key should not lock you out of your system for good.

The most straightforward answer is to keep the password as a fallback. The configuration described here with auth sufficient does exactly that.

Safer still is a second FIDO2 authenticator held in reserve. pam-u2f supports several authenticators, so you can carry one key day to day and keep a second one in a safe place.

Keep a second root session open

While setting things up, keep a working root shell open alongside:

sudo -i

Close that shell only once you have tested the changes successfully. This goes for changes to /etc/pam.d/sudo, /etc/pam.d/su and /etc/pam.d/sddm in particular. All configuration changes described here take effect without a reboot.

Should a PAM configuration contain a mistake, you can correct the file through the root shell you left open. That keeps a faulty configuration from locking you out of your own system.

What to do when the login stops working

Should a faulty PAM configuration block the graphical login, you can switch to a virtual console, depending on your system. Under TUXEDO OS, Ctrl+Alt+F3 opens one.

Sign in there with a user account that still works and correct the PAM configuration in question. If signing in at a virtual console fails as well, a recovery system or a live system may be needed.

With changes to /etc/pam.d/sddm above all, you should therefore close your existing graphical session only after testing the FIDO2 login successfully.

Do not carry the configuration over blindly

PAM configurations differ by distribution, by version and by display manager. The package versions on offer can differ as well. The paths and settings shown here therefore refer to the test environment described above.

We tested the configuration with TUXEDO OS, KDE Plasma, SDDM, pam-u2f and a Nitrokey FIDO2. The underlying method carries over to Debian, Ubuntu and other Linux distributions that use PAM.

The procedure also works with a YubiKey and with other U2F- and FIDO2-compatible security keys. Differences can arise depending on the model, on its FIDO support, on the distribution and on the PAM version in use.

Beyond the login: FIDO2 for unlocking LUKS at boot

The configuration described so far takes hold once the system is already running. The obvious follow-up question is whether a FIDO2 key can unlock a system partition encrypted with LUKS (Linux Unified Key Setup) as well. The groundwork for that exists: with systemd-cryptenroll you enrol a FIDO2 authenticator into a LUKS2 container, and the data needed for it then sits in the LUKS2 header.

The catch sits one layer down, in the initramfs. Debian and the distributions built on it generate it with initramfs-tools, and its cryptsetup integration does not know the option fido2-device in /etc/crypttab. Generating the initramfs prints ignoring unknown option 'fido2-device' instead. This is not behaviour peculiar to TUXEDO OS but an open gap in Debian itself: it has been on file as a bug report against the package cryptsetup-initramfs since November 2022 and remains open to this day.

Note: A workaround doing the rounds is a switch from initramfs-tools to dracut. Dracut falls back on systemd-cryptsetup for unlocking and therefore copes with fido2-device. The route works, but it swaps out the initrd generator of the entire system. For an intervention that deep into the boot chain we see no reasonable payoff on a work machine, and we therefore do not recommend it.

If you want to pursue LUKS unlocking regardless, fido2luks offers a far less invasive approach. The project hooks into initramfs-tools through a keyscript rather than replacing the initrd generator. It reads the FIDO2 data that systemd-cryptenroll stored in the LUKS2 header and can thus put the security key to work during boot. The keyscript goes into /etc/crypttab, after which you generate the initramfs anew.

Warning: fido2luks (more on GitHub) is not part of the supported TUXEDO OS configuration. In Debian the package sits in testing and unstable only, not in the stable package sources. Anyone using it leaves the path we have tested and cannot expect support for it.

Changes to LUKS, to /etc/crypttab and to the initramfs can leave the system unable to boot. Before you generate the initramfs anew, therefore keep a working second LUKS key and a live system for recovery within reach.

For this guide, then, it stays with pam-u2f for sudo, su and the graphical login. We tested those three cases under TUXEDO OS, they leave the boot chain untouched, and the password remains as a fallback.

Service & Support

Welcome to TUXEDO Support - how can we help you?

Linux at TUXEDO

Are you wondering if Linux is right for you? Our team will be happy to answer your questions and explain details about the free operating system at TUXEDO.
Let the advantages and services convince you!

Hardware

Notebook, PC, both - and which model? Our technical service team also provides advice on selection, equipment and puts together suitable offers for your technical requirements.

Questions and Answers

Frequently asked questions and the corresponding answers can be found here. If you cannot find a solution to your problem here, it is also worth taking a look at the instructions section.


Find out more

Instructions and Tips

Most situations can be solved quickly and easily by yourself. This saves you time and you can use your device directly again. We provide you with instructions, first steps and short tips for all TUXEDO models.


Find out more

System Recovery

Even in the case of a case, you don't have to rely on us: Your device can be reset to the factory settings - completely automatically! Everything is included with your order and you can get started right away.


Find out more

Technical Service

Our competent technicians are also happy to help with service requests. You have different possibilities to contact us. We are personally there for you Monday to Friday from 9 am to 1 pm and from 2 pm to 5 pm. But also outside these times, you can contact our team with your request by e-mail.
An extra function is available in your customer account for repair requests (RMA).

 

Contact

We are personally there for you Monday to Friday from 9 am to 1 pm and from 2 pm to 5 pm (German time). But also outside these times, you can contact our team with your request by e-mail. You will receive confirmation of receipt within approximately 15 minutes. If not, please feel free to contact us by phone. Please include your order number, the model name of your laptop or PC and as detailed a description of your request as possible. The more details you give us, the faster we can process your request!

We might not be able to answer questions about third party hardware or software. For questions about popular open source software (Thunderbird, Filezilla...) please contact a forum e.g. ubuntuforums.org. The research effort for application specific setup is immense and not manageable at the current time. Basic compatibility questions e.g. are of course still welcome!

An extra function is available in your customer account for repair requests (RMA).

 

Image of Tux

Linux compatible
image of 5 years warranty badge

Up to 5 Years Warranty
stylized image of a Rocket

Immediately ready for use
image of germany with a wrench in the center

Assembled in Germany
image of germany with a section sign in the center

German Data Privacy
stylized image of a tech support worker

German Tech Support

Guidance

  • Service & Support
  • B2B


Mo - Fr: 9-13 & 14-17h
+49 (0) 821 / 8998 2992

Perform Revocation

About TUXEDO

  • Why TUXEDO
  • TUXEDO Control Center
  • TUXEDO Tomte
  • TUXEDO WebFAI
  • TUXEDO OS
  • TUXEDO Aquaris
  • Individual logos and keyboards

Help & Support

  • Downloads & Drivers
  • System Diagnostics
  • Frequent questions (FAQ)
  • Instructions
  • Help with my device
  • Revocation right
  • Shipping costs & delivery times
  • Payment methods

News & more

  • News & Blog
  • Press
  • Newsletter
  • Event Calendar
  • Jobs & Career
  • Sponsoring

Community


Your Linux specialist since 2004

  • Accessibility
  • Public Keys
  • Privacy policy
  • Imprint
  • Battery disposal
  • Conditions of Use

Shipping costs & delivery times

We ship your order to almost all countries, in Europe mostly even free of charge! The respective shipping costs and the cost threshold above which we will cover the costs for you can be found here or for international shipping in the table below.

 


Free shipping within Germany

There are no shipping costs within Germany for goods worth €100 or more.

 

7.99 € shipping cost at max!

No matter how many small articles you order, such as USB stick card reader, LAN adapters or fan articles, with us, you pay a maximum of 7.99 € shipping costs.

  • 7.99 € shipping fee for all orders below 100 € of goods
  • Free shipping from 100 € total value of goods

You can check all occurring shipping costs or if we even deliver for free right before sending your order!

 


International delivery

Here are the shipping costs as well as the amount threshold for your order. The threshold is referring to the total amount of your order, which enables free shipping.
 

Taxes and customs outside the EU:

For orders outside the EU there might be additional duties, taxes or charges needed to be paid by the customer. These don't have to be paid to the supplier, but to local authorities. Please check for any details with your local customs or tax authorities before ordering! But as a benefit you don't have to pay German taxes, this means you save up to 19%!
Due to the Brexit and the associated changes, there may be delays of several days in customs clearance on site for deliveries to the UK. This is not within our sphere of influence.

The processing of orders outside the EU may currently be subject to significant delays due to the respective customs authorities. Unfortunately, we have no influence over this and therefore ask you to check your shipment tracking daily. If the status of your shipment does not change for more than a week, please contact our customer service.

Thank you for your understanding!

 

 
⚠️   Countries to which we unfortunately cannot ship, and information on how you can still order from us, can be found here!
Country Shipping Fee Free Shipping From
Albania 99,00 EUR -
Andorra 59,00 EUR -
Austria 8,49 EUR 100 EUR
Belarus
(Temporarily no delivery possible)
59,00 EUR -
Belgium 8,49 EUR 100 EUR
Bulgaria 15,99 EUR 160 EUR
Canada 99,00 EUR -
Croatia 34,90 EUR 500 EUR
Cyprus 34,90 EUR 500 EUR
Czech Republic 15,99 EUR 160 EUR
Denmark 8,49 EUR 100 EUR
Estonia 15,99 EUR 160 EUR
Faroe Islands 129,00 EUR -
Finland 14,99 EUR 150 EUR
France
(Overseas France excluded)
9,99 EUR 120 EUR
Greece 22,90 EUR -
Hong Kong 199,00 EUR -
Hungary 15,99 EUR 160 EUR
Iceland 129,00 EUR -
India 199,00 EUR -
Ireland 14,99 EUR 150 EUR
Italy 9,99 EUR 120 EUR
Japan 99,00 EUR -
Latvia 15,99 EUR 160 EUR
Lithuania 15,99 EUR 160 EUR
Luxembourg 8,49 EUR 100 EUR
Macau 199,00 EUR -
Macedonia 59,00 EUR -
Malta 34,90 EUR 500 EUR
Moldova 199,00 EUR -
Monaco 19,00 EUR -
Montenegro 99,00 EUR -
Netherlands
(Dutch Carribean excluded)
8,49 EUR 100 EUR
Norway 14,99 EUR 150 EUR
Poland 15,99 EUR 160 EUR
Portugal 14,99 EUR 150 EUR
Qatar 199,00 EUR -
Romania 15,99 EUR 160 EUR
San Marino 9,99 EUR 120 EUR
Serbia 34,90 EUR 500 EUR
Singapore 199,00 EUR -
Slovakia 15,99 EUR 160 EUR
Slovenia 15,99 EUR 160 EUR
Spain
(Canary Islands excluded)
14,99 EUR 150 EUR
Sweden 14,99 EUR 150 EUR
Switzerland 13,99 EUR 150 EUR
Ukraine
(Temporarily no delivery possible)
129,00 EUR -
United Arab Emirates 199,00 EUR -
United Kingdom
(Overseas Territories excluded)
9,99 EUR 120 EUR
USA
(including Hawaii)
99,00 EUR -
⚠️ Countries to which we unfortunately cannot ship, and information on how you can still order from us, can be found here!

 


Time of delivery

If not stated differently in the article's description, we deliver goods in:

  • 7-10 working days within Germany
  • 10-12 working days outside Germany

For orders paid in advance, the delivery time starts with receipt of the payment. Please keep in mind that there is no delivery on Sundays or on holidays.
For goods delivered as download, there will be no shipping fees due.
Access data for downloads are sent out via e-mail 1-3 working days after contract formation. For orders with advanced payment, we will deliver after receiving the payment. You can download the item by using the link sent to you via e-mail.

Self-pick-up of orders is not possible, unfortunately.