I researched this a few months back and was not able to find a clean way to add TFA to a key based login. Any suggestions from other HN readers?
I researched this a few months back and was not able to find a clean way to add TFA to a key based login. Any suggestions from other HN readers?
Red Hat added a similar though slightly different patch with RequiredAuthentications1 and RequiredAuthentications2. They patched OpenSSH 5.3 in RHEL 6 (and CentOS) as of 2012-06-20. [2]
So instead of Google Authenticator you could use publickey + password for 2-factor auth.
I got the ForceCommand idea from a thread last year about setting up two factor SSH auth using Authy: https://news.ycombinator.com/item?id=4444926
http://blog.authy.com/two-factor-ssh-in-thirty-seconds
(disclaimer: I am a founder of the company).