Two-factor authentication for your own SSH server
Summary
Florian Winkler shows how SSH can be extended with a second factor via PAM and which configuration steps effectively secure your own Linux server. More factors only increase security if recovery and bypasses are designed just as carefully. A factor stored separately makes the theft of a single file less valuable.
Ideas
- A second factor limits the damage from stolen passwords or keys.
- PAM integrates additional authentication methods into existing Linux services.
- SSH AuthenticationMethods can require several successful proofs.
- Emergency access prevents a lost token from locking you out of the server for good.
Recommendations
- Keep an existing session open while you test new SSH rules.
- Store tested emergency codes offline and document the fallback path.
References
Links to the original source and the Web Archive open in a new tab.