Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #242186 > unrolled thread

Use one of many second factors authentication on PAM

Started byAndré Rodier <andre@rodier.me>
First post2021-11-14 19:00 +0100
Last post2021-11-15 08:20 +0100
Articles 3 — 2 participants

Back to article view | Back to linux.debian.user


Contents

  Use one of many second factors authentication on PAM André Rodier <andre@rodier.me> - 2021-11-14 19:00 +0100
    Re: Use one of many second factors authentication on PAM Celejar <celejar@gmail.com> - 2021-11-14 21:30 +0100
      Re: Use one of many second factors authentication on PAM André Rodier <andre@rodier.me> - 2021-11-15 08:20 +0100

#242186 — Use one of many second factors authentication on PAM

FromAndré Rodier <andre@rodier.me>
Date2021-11-14 19:00 +0100
SubjectUse one of many second factors authentication on PAM
Message-ID<DjrXk-1JP-11@gated-at.bofh.it>
Hello all,

I have been able to configure pam on Linux, to add two factors 
authentication for session, sudo, etc...

First, I tried Google authenticator and a code from my phone, and it is 
working like a charm.

Then, I commented out the google-authenticator entry, and tried a U2F 
key. Again, this is working very well, and the light blink after I type 
the password.

Same for a Yubikey, working like a charm, and I even have a clue message 
on GDM "Please touch your device".

Now, I would like to achieve the following:

- Having my password as the first authentication, of course mandatory.
- Then, being able to use one of my second authentication device.

This is basically what we have on Google, for instance.

Any idea ?

Thanks for your answers.

𝓐𝓡 - André Rodier.

[toc] | [next] | [standalone]


#242191

FromCelejar <celejar@gmail.com>
Date2021-11-14 21:30 +0100
Message-ID<Djuiu-3io-5@gated-at.bofh.it>
In reply to#242186
On Sun, 14 Nov 2021 17:57:53 +0000
André Rodier <andre@rodier.me> wrote:

> Hello all,
> 
> I have been able to configure pam on Linux, to add two factors 
> authentication for session, sudo, etc...
> 
> First, I tried Google authenticator and a code from my phone, and it is 
> working like a charm.
> 
> Then, I commented out the google-authenticator entry, and tried a U2F 
> key. Again, this is working very well, and the light blink after I type 
> the password.
> 
> Same for a Yubikey, working like a charm, and I even have a clue message 
> on GDM "Please touch your device".
> 
> Now, I would like to achieve the following:
> 
> - Having my password as the first authentication, of course mandatory.
> - Then, being able to use one of my second authentication device.
> 
> This is basically what we have on Google, for instance.
> 
> Any idea ?

I think you need to look into the details of PAM stacking. See here:

https://unix.stackexchange.com/a/638466

for a discussion of something similar to what you want to do (although you'll have to adapt it
to your specific preferences), and here for more information:

https://developer.ibm.com/tutorials/l-pam/

Celejar

[toc] | [prev] | [next] | [standalone]


#242198

FromAndré Rodier <andre@rodier.me>
Date2021-11-15 08:20 +0100
Message-ID<DjErv-1dE-1@gated-at.bofh.it>
In reply to#242191
On 14/11/2021 20:26, Celejar wrote:
> On Sun, 14 Nov 2021 17:57:53 +0000
> André Rodier <andre@rodier.me> wrote:
> 
>> Hello all,
>>
>> I have been able to configure pam on Linux, to add two factors
>> authentication for session, sudo, etc...
>>
>> First, I tried Google authenticator and a code from my phone, and it is
>> working like a charm.
>>
>> Then, I commented out the google-authenticator entry, and tried a U2F
>> key. Again, this is working very well, and the light blink after I type
>> the password.
>>
>> Same for a Yubikey, working like a charm, and I even have a clue message
>> on GDM "Please touch your device".
>>
>> Now, I would like to achieve the following:
>>
>> - Having my password as the first authentication, of course mandatory.
>> - Then, being able to use one of my second authentication device.
>>
>> This is basically what we have on Google, for instance.
>>
>> Any idea ?
> 
> I think you need to look into the details of PAM stacking. See here:
> 
> https://unix.stackexchange.com/a/638466
> 
> for a discussion of something similar to what you want to do (although you'll have to adapt it
> to your specific preferences), and here for more information:
> 
> https://developer.ibm.com/tutorials/l-pam/
> 
> Celejar
> 

Thanks!

-- 
𝓐𝓡 - André Rodier

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web