Re: two factor authentication

This is a discussion on Re: two factor authentication within the OpenSSH Development forums, part of the Networking and Network Related category; On July 22, 2006 7:08:59 PM -0500 jacob martinson <martinson.jacob@gmail.com> wrote: > On ...


Go Back   Usenet Forums > Networking and Network Related > OpenSSH Development

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 07-23-2006
Frank Cusack
 
Posts: n/a
Default Re: two factor authentication

On July 22, 2006 7:08:59 PM -0500 jacob martinson <martinson.jacob@gmail.com> wrote:
> On 7/22/06, Frank Cusack <fcusack@fcusack.com> wrote:
>> On July 22, 2006 12:15:07 PM -0500 jacob martinson <martinson.jacob@gmail.com> wrote:
>> > Are there any plans on the table to add native support for two-factor
>> > authentication, such as password *and* public key?

>>
>> You can already do that. Public key is itself already 2-factor --
>> something you know (the pin/passcode) and something you have (the
>> device on which the public key resides). Password, via PAM or BSDAUTH,
>> allows any two factor device the host (server) system supports.
>>

>
> You can? How can you configure ssh to require both successful
> password authentication (via the underlying OS password verification
> mechanisms) and public key auth before the user is allowed onto the
> system?


Sorry, I meant you can already do native 2-factor auth via publickey
or via password alone.

> Public key is only single factor. All you need to know to
> authenticate is the private key. There is no way to enforce
> passphrase protection of the private from the server's perspective so
> - unless I'm missing something - that isn't two-factor.


You are correct, for files on disk. But publickey can also be used
with smartcards and via control of authorized_keys or using X.509
(there's a patch for that) you can restrict to keys known to be
protected by a pin/passphrase.

Or if the environment is small enough and you can trust your users
to have good passphrases you can probably claim 2-factor. The server
doesn't enforce that but your policy can. (in limited cases)

-frank
_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@mindrot.org
http://lists.mindrot.org/mailman/lis...enssh-unix-dev
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 05:29 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0