3 ms·
How I'm setting up SSH access currently is to use two factor authentication where one of the factors is a device identifier, i.e. SSH key stored in TPM or with
by macrolime 4y ago
How I'm setting up SSH access currently is to use two factor authentication where one of the factors is a device identifier, i.e. SSH key stored in TPM or with this on the Secure Enclave on a Mac, allowing only access from trusted devices. The second is a user identifier, stored in a yubikey.
In sshd_config, you can enable multifactor authentication with a comma separated list after AuthenticationMethods, for example publickey, publickey to require two keys.
https://manpages.debian.org/bullseye/openssh-server/sshd_config.5.en.html#AuthenticationMethods https://manpages.debian.org/bullseye/openssh-server/sshd_con...