3 ms·
No need to touch SSH itself, PAM is a thing (unless you're on OpenBSD). Here's an example of pam-u2f with OpenSSH: https://aprilmacdonald.com/two-factor-ssh-au
by floatboth 8y ago
No need to touch SSH itself, PAM is a thing (unless you're on OpenBSD). Here's an example of pam-u2f with OpenSSH:
https://aprilmacdonald.com/two-factor-ssh-authentication-with-u2f-hardware-security-key/ https://aprilmacdonald.com/two-factor-ssh-authentication-wit...
I actually use a Yubikey for SSH in a different way: with gpg-agent. E.g. https://blog.habets.se/2013/02/GPG-and-SSH-with-Yubikey-NEO.html https://blog.habets.se/2013/02/GPG-and-SSH-with-Yubikey-NEO....
- jlgaddis 8y ago> PAM is a thing (unless you're on OpenBSD) And if you are on OpenBSD, there's login_yubikey [0] (although it uses OTP instead of U2F). [0]: https://man.openbsd.org/login_yubikey.8 https://man.openbsd.org/login_yubikey.8