Yubico Forum

...visit our web-store at store.yubico.com
It is currently Tue Jan 30, 2018 10:51 am

All times are UTC + 1 hour




Post new topic Reply to topic  [ 2 posts ] 
Author Message
PostPosted: Fri Sep 01, 2017 11:17 pm 
Offline

Joined: Fri Sep 01, 2017 11:13 pm
Posts: 1
Hi,

I was wondering if it was possible to use the Yubikey NEO with the Yubico Authenticator app (NFC) to get two-factor authentication with OpenSSH (https://developers.yubico.com/yubico-pam/)?

I'm already using my Yubikey NEO to log on my OpenSSH server (in USB mode) but sometimes I don't have access to a computer/laptop and I would like to use my phone with some SSH client. I've implemented this scenario using the Google Authenticator app and their PAM module and it works great but I would like to leverage the NFC feature of my NEO for added security. But I can't figure out a way to do the same thing with the Yubico PAM module. With Google's solution it's very simple, all I have to do is call their script on the server side then I get a QR code that I scan using the mobile app and then I can log from anywhere using my username/password and the OTP that was generated by the app.

Is there a way to do that with the Yubico Authenticator app and the PAM module?

Thanks,

Christian


Top
 Profile  
Reply with quote  

Share On:

Share on Facebook FacebookShare on Twitter TwitterShare on Tumblr TumblrShare on Google+ Google+

PostPosted: Mon Oct 02, 2017 3:15 pm 
Offline
User avatar

Joined: Sun Jul 24, 2011 12:48 am
Posts: 37
I am not sure if this is what you want, but yesterday I experimented and followed a relatively simple to follow tutorial to add TOTP code 2-factor to my linux VPS server's openSSH login, when I login through Putty on windows. It asks me for a verification code, I plug in my Yubikey, authenticate with my password to the Yubico Authenticator program on my desktop, then I double click my VPS entry and copy the code, paste it into putty and press enter, then enter my account's password and press enter and then I am logged in. Through the process of setting it up I had to maximize my putty window to see the whole QR code, although they do provide the secret in text form that you can manually enter into the authenticator app to add the credential. Here is the guide: https://www.digitalocean.com/community/ ... untu-16-04

I hope that helps you out.

_________________
My GnuPG (PGP) Key ID: 614D98E6


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 2 posts ] 

All times are UTC + 1 hour


Who is online

Users browsing this forum: No registered users and 10 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group