[Freeipa-users] Using FreeIPA OTP in a PAM module
Jakub Hrozek
jhrozek at redhat.com
Tue Jun 30 07:09:19 UTC 2015
On Tue, Jun 30, 2015 at 11:34:55AM +0530, Prashant Bapat wrote:
> Hi,
>
> I was able to set this up in a Fedora instance with SSSD and it works as
> expected. SSHD first uses the public key and then prompts for password
> which is ofcourse password+OTP.
>
> However, having a user enter the password+OTP every time he logs in during
> the day is kind of inconvenient. Is it possible to make sure the user has
> to login once and the credentials are cached for say 12/24 hours. I know
> this is possible just using the password. Question is, is this possible
> using password+OTP?
We have an SSSD feature under review now that would help you:
https://fedorahosted.org/sssd/ticket/1807
But to be honest, I'm not sure if we tested the patches with 2FA yet. We
should!
More information about the Freeipa-users
mailing list