Tweaking Two-Factor Authentication for SSH
Hello,
I'm using two-factor authentication for remote SSH access.
This also means accessing the SSH server from the local network requires two-factor authentication.
Is there a way to exude specific users from two-factor authentication and than grant them only local access?
At the moment all users seem to require two-factor authentication, regardless whether they have set a second validation level.
!The Lazy Admin Club
I'm using two-factor authentication for remote SSH access.
This also means accessing the SSH server from the local network requires two-factor authentication.
Is there a way to exude specific users from two-factor authentication and than grant them only local access?
At the moment all users seem to require two-factor authentication, regardless whether they have set a second validation level.
!The Lazy Admin Club
Rebeka Catalina 🐛
in reply to Andy H3 • •like this
Andy H3 likes this.
Rebeka Catalina 🐛
Unknown parent • •Ok.. well the pipe symbol ( "|" ) in my comment above stands for 'or' - so you have to read <a>|<b> like '<a> or <b>'
Perhaps you could define two different UNIX-groups. For example 'simpleAccess' and '2fAcces' and the in sshd_config you do something like
Andy H3
in reply to Andy H3 • •auth [success=done default=ignore] pam_access.so accessfile=/etc/security/access-local.conf
and then local access defined.See here: https://unix.stackexchange.com/questions/388384/ssh-only-require-google-authenticator-from-outside-local-network
Rebeka Catalina 🐛
in reply to Andy H3 • •Well, I don't understand pam, because I don't use it. I used to compile my operating systems completely without pam support - so I can't really say anything to this solution, but awesome, that you could solve the problem
Andy H3
in reply to Rebeka Catalina 🐛 • •Can you use 2FA without pam? Prior to enabling 2FA, I didn't use pam either.
Rebeka Catalina 🐛
in reply to Andy H3 • •like this
Andy H3 likes this.
Andy H3
in reply to Andy H3 • •like this
Rebeka Catalina 🐛 likes this.
Andy H3
Unknown parent • •Rebeka Catalina 🐛
in reply to Andy H3 • •