Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #242186 > unrolled thread
| Started by | André Rodier <andre@rodier.me> |
|---|---|
| First post | 2021-11-14 19:00 +0100 |
| Last post | 2021-11-15 08:20 +0100 |
| Articles | 3 — 2 participants |
Back to article view | Back to linux.debian.user
Use one of many second factors authentication on PAM André Rodier <andre@rodier.me> - 2021-11-14 19:00 +0100
Re: Use one of many second factors authentication on PAM Celejar <celejar@gmail.com> - 2021-11-14 21:30 +0100
Re: Use one of many second factors authentication on PAM André Rodier <andre@rodier.me> - 2021-11-15 08:20 +0100
| From | André Rodier <andre@rodier.me> |
|---|---|
| Date | 2021-11-14 19:00 +0100 |
| Subject | Use one of many second factors authentication on PAM |
| Message-ID | <DjrXk-1JP-11@gated-at.bofh.it> |
Hello all, I have been able to configure pam on Linux, to add two factors authentication for session, sudo, etc... First, I tried Google authenticator and a code from my phone, and it is working like a charm. Then, I commented out the google-authenticator entry, and tried a U2F key. Again, this is working very well, and the light blink after I type the password. Same for a Yubikey, working like a charm, and I even have a clue message on GDM "Please touch your device". Now, I would like to achieve the following: - Having my password as the first authentication, of course mandatory. - Then, being able to use one of my second authentication device. This is basically what we have on Google, for instance. Any idea ? Thanks for your answers. 𝓐𝓡 - André Rodier.
[toc] | [next] | [standalone]
| From | Celejar <celejar@gmail.com> |
|---|---|
| Date | 2021-11-14 21:30 +0100 |
| Message-ID | <Djuiu-3io-5@gated-at.bofh.it> |
| In reply to | #242186 |
On Sun, 14 Nov 2021 17:57:53 +0000 André Rodier <andre@rodier.me> wrote: > Hello all, > > I have been able to configure pam on Linux, to add two factors > authentication for session, sudo, etc... > > First, I tried Google authenticator and a code from my phone, and it is > working like a charm. > > Then, I commented out the google-authenticator entry, and tried a U2F > key. Again, this is working very well, and the light blink after I type > the password. > > Same for a Yubikey, working like a charm, and I even have a clue message > on GDM "Please touch your device". > > Now, I would like to achieve the following: > > - Having my password as the first authentication, of course mandatory. > - Then, being able to use one of my second authentication device. > > This is basically what we have on Google, for instance. > > Any idea ? I think you need to look into the details of PAM stacking. See here: https://unix.stackexchange.com/a/638466 for a discussion of something similar to what you want to do (although you'll have to adapt it to your specific preferences), and here for more information: https://developer.ibm.com/tutorials/l-pam/ Celejar
[toc] | [prev] | [next] | [standalone]
| From | André Rodier <andre@rodier.me> |
|---|---|
| Date | 2021-11-15 08:20 +0100 |
| Message-ID | <DjErv-1dE-1@gated-at.bofh.it> |
| In reply to | #242191 |
On 14/11/2021 20:26, Celejar wrote: > On Sun, 14 Nov 2021 17:57:53 +0000 > André Rodier <andre@rodier.me> wrote: > >> Hello all, >> >> I have been able to configure pam on Linux, to add two factors >> authentication for session, sudo, etc... >> >> First, I tried Google authenticator and a code from my phone, and it is >> working like a charm. >> >> Then, I commented out the google-authenticator entry, and tried a U2F >> key. Again, this is working very well, and the light blink after I type >> the password. >> >> Same for a Yubikey, working like a charm, and I even have a clue message >> on GDM "Please touch your device". >> >> Now, I would like to achieve the following: >> >> - Having my password as the first authentication, of course mandatory. >> - Then, being able to use one of my second authentication device. >> >> This is basically what we have on Google, for instance. >> >> Any idea ? > > I think you need to look into the details of PAM stacking. See here: > > https://unix.stackexchange.com/a/638466 > > for a discussion of something similar to what you want to do (although you'll have to adapt it > to your specific preferences), and here for more information: > > https://developer.ibm.com/tutorials/l-pam/ > > Celejar > Thanks! -- 𝓐𝓡 - André Rodier
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web