Use Google Authenticator For Two-Factor SSH Authentication in Linux
scottlinux.com
scottlinux.com
Our setup is that key based authentication works as normal, but if you want to use a password based authentication, you need to 2-factor auth.
This approach allows us to maintain security without losing the ability to go "Oh no I'm somewhere without any of my private keys and I really need to log into that server to fix this production error!"
I researched this a few months back and was not able to find a clean way to add TFA to a key based login. Any suggestions from other HN readers?
Red Hat added a similar though slightly different patch with RequiredAuthentications1 and RequiredAuthentications2. They patched OpenSSH 5.3 in RHEL 6 (and CentOS) as of 2012-06-20. [2]
So instead of Google Authenticator you could use publickey + password for 2-factor auth.
I got the ForceCommand idea from a thread last year about setting up two factor SSH auth using Authy: https://news.ycombinator.com/item?id=4444926
http://blog.authy.com/two-factor-ssh-in-thirty-seconds
(disclaimer: I am a founder of the company).
- Option of TOTP or HOTP ("time-based" or "counter-based")
- SHA1 only
- 6-digit codes only
- 30-second time step only (TOTP)
- Base32-encoded keys only
"Google Authenticator" also implies that the secret is stored on your phone, where it's far more susceptible to remote compromise than if it were stored in a dedicated hardware TOTP token.Personally, my preference for SSH two-factor authentication is to just use standard pubkey authentication, but only allow keys that have been placed into PIN-protected, tamper-resistant hardware. The crypto is stronger, it doesn't involve some obscure PAM module, and the attack surface is smaller (since you can avoid invoking PAM at all until after authentication succeeds).
And your ability to access to your hardware isn't dependent on an external organisation. I mean its not unheard of for Google to close down accounts from time to time. I wouldn't want my keys in somebody elses safe...
According to the gauth “disclaimer” on the website, the recent versions of the Android app are proprietary: the most recent on Google Play is from February 13. It’s hard to tell if there will be any more commits to that repo.
Fork: kaie/otp-authenticator-android https://github.com/kaie/otp-authenticator-android
I'm not sure about the details of MOTP, but I can't find much chatter elsewhere about it. I would need much more before I recommended it to anyone as an alternative.
(and that fork is just a one-off fork of the google repo, with only two changes made to the README since forking)
It's free for individuals, and they even answer support emails ;)
(Undisclaimer: I have no interest in the company, just a fan)
https://github.com/hungtruong/chef-duo-unix
It's my first recipe so feedback would be appreciated if you actually use it!
According to the SSH screenshot you gotta choose the auth type, then enter the password or wait for auth.
In every case their central server seems to have authority over the 2nd factor, too.
Also, even the whitepaper is advertisement bullshit, no technical info. Is there any technical info anywhere?
In terms of SSH, one of the features of Duo is that you can have many methods to authentication... push to phone, phone call, sms, yubikey, etc -- having that list allows you to pick how upon login.
We're definitely a SaaS provider so going through us is part of our service -- this also allows us to handle things such as telephony needs, push notifications, etc. for customers.
In terms of technical information, is there a specific feature or technology you're interested in knowing more about?
I suppose automated deploy scripts could also be modified to accept an authenticator code as a parameter too.
I think you're misunderstanding. Two-factor authentication is a layer of security on top of regular authentication to ssh (whether password or key based). It's not meant to replace anything or stand on its own. This is for added security; first you authenticate via password or key, and then you authenticate via google authenticator.
If it is, it doesn't really add any security.
Morever, if the servers you authenticate too all share the same secret (ie you use the same token with all of them), you're decreasing the value of the 2nd factor by the amount of servers.
That's because anyone getting access to those servers can generate your OTP and connect to the other servers (if they also have the SSH key).
One way to mitigate that is to have a centralized authentication server for OTP.
All in all, if you want to protect your secret, OTP isn't the best solution. It's just something convenient. I would recommend using an openpgp smartcard instead.
I understand why and how this adds the extra security for the 'traditional' password authentication due to all the methods of compromising a password: brute force, guessing, exploits etc.; so for TFA to add an extra layer surely the private key would have to be exploitable in some form?
Maybe I phrased myself incorrectly in that I still see how it adds an extra layer of security but I fail to see why one would do this on top of a key based auth method.
I know the original article didn't mention using it on top of key auth but I wanted some insight as to whether or not it would be worth doing. As do many, I use TFA for any online service I can so I do appreciate its point in that sense.
EDIT: I never really considered the fact that the private key could be stolen via malicious software. Taking that into account I see the value in TFA for SSH.
we have a similar script to Stripe such that you can drop in a complete JS widget in seconds with your public API key.
<form action="/verify" method="post">
<script src="//getprove.com/v1/verify.js" data-callback="/verified.html" data-key="YOUR-API-PUBLIC-KEY" class="prove-verify"></script>
</form>
https://getprove.com(plug)
http://zcentric.com/2012/10/09/google-authenticator-with-ope...
Can't quite work out how it is displaying it, I'm not competent enough with plain old C, but I'm sure someone can follow the code and chime in.
EDIT: Looks like it uses libqrencode and if that's not found it just uses Unicode block elements for actually displaying it from Google's API.
[0] http://google-authenticator.googlecode.com/git/libpam/google...