Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Two factor authentication (2FA) in Debian
- ## Install needed packages ##
- apt-get install libpam-oath oathtool
- ## Generate secret ##
- key=$( head -c 1024 /dev/urandom | openssl sha1 | awk '{ print $2 }' )
- ## Replace [USERNAME] with the user which will use OTP ##
- echo "HOTP/T30/6 [USERNAME] - ${key}" >> /etc/security/users.oath
- chmod 600 /etc/security/users.oath
- chown root /etc/security/users.oath
- ## Edit /etc/ssh/sshd_config ##
- Change `ChallengeResponseAuthentication` to `yes` and add a few lines
- ChallengeResponseAuthentication yes
- UsePAM yes
- PasswordAuthentication no
- ## Let's create some rule excluding 2FA coming from our LAN ##
- Create the file `/etc/security/access-local.conf` and put this
- + : ALL : 192.168.0.0/24
- + : ALL : LOCAL
- - : ALL : ALL
- And secure it
- chmod 600 /etc/security/access-local.conf
- chown root /etc/security/access-local.conf
- ## Edit /etc/pam.d/sshd
- comment the first line to avoid information leakage as noted in step 5 [here][1] and add a few lines
- # @include common-auth
- auth required pam_unix.so nullok_secure
- auth required pam_permit.so
- auth [success=1 default=ignore] pam_access.so accessfile=/etc/security/access-local.conf
- auth required pam_oath.so usersfile=/etc/security/users.oath window=30
- ## Install otp client on your device and setup with Base32 secret
- To obtain the Base32 secret type
- oathtool --totp -v ${key} | grep Base32 | awk '{print $3}'
- You can take your Base32 formatted secret, and either enter it manually or generate a QR code. To make a QR code, you need a URL formatted string, as below. The example of 'username@securehost' is a simple description, so it can be anything you like.
- otpauth://totp/username@securehost?secret=[YOUR_SECRET]
- P.D. use qrencode
- qrencode -o qrcode.png 'otpauth://totp/username@securehost?secret=[YOUR_SECRET]'
- Now restart ssh daemon and try to login from an external network.
- There's some extra reading here about [Pluggable Authentication Module (PAM)][2]
- This how-to has been done using [this][3] tutorial and [this one][4].
- [1]: http://mikeboers.com/blog/2011/05/28/one-time-passwords-for-ssh-on-ubuntu-and-os-x
- [2]: http://www.rjsystems.nl/en/2100-pam-debian.php
- [3]: http://blog.josefsson.org/tag/totp/
- [4]: http://spod.cx/blog/two-factor-ssh-auth-with-pam_oath-google-authenticator.shtml
Advertisement
Add Comment
Please, Sign In to add comment