2 factor authentication, google authenticator accessibility, and sshd configuration
Hello, I realize that's a complex subject. Let me break it down. First, is anyone using google authenticator to implement two factor authentication with a service? I lost a google account password, forgot it is more like it, so I went in and google sent my phone a sms message, that I just had to open and then I was logged in. This is a capability i'd like to have with my services, openssh sshd to be specific. If anyone is using this or has additional information i'd like to know about it. Thanks. Dave.
I've successfully used Google Authenticator on iOS. It looks like this article covers setting up the necessary PAM modules and configurations to get sshd working with TOTP. http://delyan.me/securing-ssh-with-totp/ This will require that you supply the 6-digit code provided by Google Authenticator. If you want something where you just accept a push notification or similar, take a look at Duo Mobile. https://duo.com/docs/duounix Chris On Mon, Mar 27, 2017 at 09:08:58PM -0400, David Mehler wrote:
Hello,
I realize that's a complex subject. Let me break it down.
First, is anyone using google authenticator to implement two factor authentication with a service?
I lost a google account password, forgot it is more like it, so I went in and google sent my phone a sms message, that I just had to open and then I was logged in. This is a capability i'd like to have with my services, openssh sshd to be specific.
If anyone is using this or has additional information i'd like to know about it.
Thanks. Dave.
_______________________________________________ Blind-sysadmins mailing list Blind-sysadmins@lists.hodgsonfamily.org https://lists.hodgsonfamily.org/listinfo/blind-sysadmins
Chris Nestrud <ccn@chrisnestrud.com> wrote:
I've successfully used Google Authenticator on iOS.
Also, if you have the key, you can run oathtool --totop -b from your shell prompt (supplying the key as the last argument). After acquiring keys from sites that use TOTP (Google among them), I just create a shell script for the oathtool command. The output of the command is the six-digit code that you need to supply as the second authentication factor.
participants (3)
-
Chris Nestrud
-
David Mehler
-
Jason White