bk99.de entertain the web since 1997

Two-factor authentication for your own SSH server

Summary

Florian Winkler shows how SSH can be extended with a second factor via PAM and which configuration steps effectively secure your own Linux server. More factors only increase security if recovery and bypasses are designed just as carefully. A factor stored separately makes the theft of a single file less valuable.

Ideas

  • A second factor limits the damage from stolen passwords or keys.
  • PAM integrates additional authentication methods into existing Linux services.
  • SSH AuthenticationMethods can require several successful proofs.
  • Emergency access prevents a lost token from locking you out of the server for good.

Recommendations

  • Keep an existing session open while you test new SSH rules.
  • Store tested emergency codes offline and document the fallback path.

References

Watch the talk

Search the Web Archive