Yubico Forum

...visit our web-store at store.yubico.com
It is currently Tue Jan 30, 2018 12:03 pm

All times are UTC + 1 hour




Post new topic Reply to topic  [ 3 posts ] 
Author Message
PostPosted: Thu Oct 24, 2013 4:01 pm 
Offline

Joined: Thu Oct 24, 2013 3:55 pm
Posts: 3
Hi Everyone,

Please forgive me if this has been asked before or is fully documented but I couldn't find anything.

Today I have setup a YubiRADIUS server in our corporate environment and integrated it with our active domain server.

Users have been imported from the domain and RADtest and OTP test were successful using my test yubikey.

I am now looking to integrate this into the following:

1. LDAP integration for desktop and VPN account logins.
2. SSH integration to our customers servers.

This should use our local YubiRADIUS server for authentication, and not yubico's online servers.

Is anyone able to point me in the direction of how to accomplish this as currently it does not appear to work with LDAP (I haven't yet tried integration with SSH).

Any help will be greatly appreciated.

Many Thanks!
Sam


Top
 Profile  
Reply with quote  

Share On:

Share on Facebook FacebookShare on Twitter TwitterShare on Tumblr TumblrShare on Google+ Google+

PostPosted: Thu Oct 24, 2013 4:15 pm 
Offline

Joined: Thu Oct 24, 2013 3:55 pm
Posts: 3
Ok I've found the pam stuff for SSH so no need for that.

However the LDAP stuff still stands as for some reason they still dont authenticate. Does something require doing on the AD server to get this working?


Top
 Profile  
Reply with quote  
PostPosted: Tue Oct 29, 2013 11:52 am 
Offline
Yubico Team
Yubico Team

Joined: Mon Feb 22, 2010 9:49 am
Posts: 183
Hello,

Please see the following details given as per your requirement:

1. LDAP integration for desktop and VPN account logins.

The VPN device which supports RADIUS protocol can be configured with the YubiRADIUS. You can use NetMotion Mobility server configuration for the desktop login with the YubiRADIUS for two factoor authentication. For windows desktop please refer following link http://wiki.yubico.com/wiki/index.php/A ... #NetMotion

2. SSH integration to our customers servers.

Yubico offers open source PAM module ( http://code.google.com/p/yubico-pam/ ) that can closely meet your requirements. Please refer to page http://code.google.com/p/yubico-pam/wik ... dSSHViaPAM which explains how you can configure and use the PAM module to implement YubiKey based two-factor authentication for SSH.

Since you are looking at either the root password OR a valid YubiKey OTP for authentication instead of two-factor authentication, you can make relevant changes to the PAM configuration to achieve the desired result.

Please see more details at http://www.yubico.com/ssh-authentication

Hope this helps!

Thanks and best regards,
Samir.


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 3 posts ] 

All times are UTC + 1 hour


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group