Guest User

ssh OTP

a guest
May 5th, 2018
741
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.43 KB | None | 0 0
  1. # Two factor authentication (2FA) in Debian
  2. ## Install needed packages ##
  3.  
  4. apt-get install libpam-oath oathtool
  5.  
  6. ## Generate secret ##
  7.  
  8. key=$( head -c 1024 /dev/urandom | openssl sha1 | awk '{ print $2 }' )
  9.  
  10. ## Replace [USERNAME] with the user which will use OTP ##
  11.  
  12. echo "HOTP/T30/6 [USERNAME] - ${key}" >> /etc/security/users.oath
  13. chmod 600 /etc/security/users.oath
  14. chown root /etc/security/users.oath
  15.  
  16. ## Edit /etc/ssh/sshd_config ##
  17. Change `ChallengeResponseAuthentication` to `yes` and add a few lines
  18.  
  19. ChallengeResponseAuthentication yes
  20. UsePAM yes
  21. PasswordAuthentication no
  22.  
  23. ## Let's create some rule excluding 2FA coming from our LAN ##
  24. Create the file `/etc/security/access-local.conf` and put this
  25.  
  26. + : ALL : 192.168.0.0/24
  27. + : ALL : LOCAL
  28. - : ALL : ALL
  29.  
  30. And secure it
  31.  
  32. chmod 600 /etc/security/access-local.conf
  33. chown root /etc/security/access-local.conf
  34.  
  35. ## Edit /etc/pam.d/sshd
  36. comment the first line to avoid information leakage as noted in step 5 [here][1] and add a few lines
  37.  
  38. # @include common-auth
  39. auth required pam_unix.so nullok_secure
  40. auth required pam_permit.so
  41. auth [success=1 default=ignore] pam_access.so accessfile=/etc/security/access-local.conf
  42. auth required pam_oath.so usersfile=/etc/security/users.oath window=30
  43.  
  44. ## Install otp client on your device and setup with Base32 secret
  45. To obtain the Base32 secret type
  46.  
  47. oathtool --totp -v ${key} | grep Base32 | awk '{print $3}'
  48.  
  49. You can take your Base32 formatted secret, and either enter it manually or generate a QR code. To make a QR code, you need a URL formatted string, as below. The example of 'username@securehost' is a simple description, so it can be anything you like.
  50.  
  51. otpauth://totp/username@securehost?secret=[YOUR_SECRET]
  52.  
  53. P.D. use qrencode
  54.  
  55. qrencode -o qrcode.png 'otpauth://totp/username@securehost?secret=[YOUR_SECRET]'
  56.  
  57. Now restart ssh daemon and try to login from an external network.
  58.  
  59. There's some extra reading here about [Pluggable Authentication Module (PAM)][2]
  60.  
  61. This how-to has been done using [this][3] tutorial and [this one][4].
  62.  
  63. [1]: http://mikeboers.com/blog/2011/05/28/one-time-passwords-for-ssh-on-ubuntu-and-os-x
  64. [2]: http://www.rjsystems.nl/en/2100-pam-debian.php
  65. [3]: http://blog.josefsson.org/tag/totp/
  66. [4]: http://spod.cx/blog/two-factor-ssh-auth-with-pam_oath-google-authenticator.shtml
Advertisement
Add Comment
Please, Sign In to add comment