<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=4&amp;t=616" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2011-01-20T06:44:12+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=4&amp;t=616</id>
<entry>
<author><name><![CDATA[samir]]></name></author>
<updated>2011-01-20T06:44:12+01:00</updated>
<published>2011-01-20T06:44:12+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=616&amp;p=2517#p2517</id>
<link href="https://forum.yubico.com/viewtopic.php?t=616&amp;p=2517#p2517"/>
<title type="html"><![CDATA[Re: differentiate between local and remote connections]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=616&amp;p=2517#p2517"><![CDATA[
That sounds to be a good option!<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1076">samir</a> — Thu Jan 20, 2011 6:44 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[digininja]]></name></author>
<updated>2011-01-19T18:51:01+01:00</updated>
<published>2011-01-19T18:51:01+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=616&amp;p=2516#p2516</id>
<link href="https://forum.yubico.com/viewtopic.php?t=616&amp;p=2516#p2516"/>
<title type="html"><![CDATA[Re: differentiate between local and remote connections]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=616&amp;p=2516#p2516"><![CDATA[
Thanks, I'll have a look at that.<br /><br />My other options is to run two ssh servers, one for internal on standard port 22 then the other with yubikey on a different port that is NAT'ed through the firewall. The NAT means I don't need to worry about it being on a different port as it can still present itself on 22 if I want it to.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1482">digininja</a> — Wed Jan 19, 2011 6:51 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[samir]]></name></author>
<updated>2011-01-17T13:15:37+01:00</updated>
<published>2011-01-17T13:15:37+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=616&amp;p=2515#p2515</id>
<link href="https://forum.yubico.com/viewtopic.php?t=616&amp;p=2515#p2515"/>
<title type="html"><![CDATA[Re: differentiate between local and remote connections]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=616&amp;p=2515#p2515"><![CDATA[
Yubico PAM module does not support selective two or single factor authentication based on from where the user is connecting (i.e. remotely or locally). Only two factor authentication is supported for all users. However, by making a small modification in the Yubico PAM module it will be possible to selective provide either YubiKey based two factor authentication or single factor password based authentication to a group of users.<br /><br />The changes are needed to be made in the logic where the Yubico PAM module looks for the YubiKey ID and Username binding. If no YubiKey ID and Username binding found for a user, then the Yubico PAM module should skip all checks and send the success signal to the underlying PAM modules.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1076">samir</a> — Mon Jan 17, 2011 1:15 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[digininja]]></name></author>
<updated>2010-12-26T13:56:54+01:00</updated>
<published>2010-12-26T13:56:54+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=616&amp;p=2493#p2493</id>
<link href="https://forum.yubico.com/viewtopic.php?t=616&amp;p=2493#p2493"/>
<title type="html"><![CDATA[differentiate between local and remote connections]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=616&amp;p=2493#p2493"><![CDATA[
Is it possible to have the ssh/PAM module differentiate between an ssh connection from the same subnet and from a everywhere else?<br /><br />I'd like to restrict ssh connections coming in from the internet to have to use their yubikey but to allow local connections through with just a password.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1482">digininja</a> — Sun Dec 26, 2010 1:56 pm</p><hr />
]]></content>
</entry>
</feed>