discussion on shibboleth-dev (fwd)

Michael Schwartz mike at gluu.org
Thu Sep 6 12:34:17 EDT 2012


Ok... I officially botched the description... but luckily Jon from Duo 
comes to the rescue !

- Mike


---------- Forwarded message ----------
Date: Thu, 06 Sep 2012 12:03:57 -0400
From: Jon Oberheide <jono at duosecurity.com>
To: Tom Scavo <trscavo at internet2.edu>, mike at gluu.org
Cc: support at duosecurity.com
Subject: discussion on shibboleth-dev

Tom,

The login_duo module that is commonly used to protect ssh logins should
be invoked via OpenSSH's ForceCommand directive, either globally in
sshd_config or wrapping individual pubkeys in the user's authorized_keys
file:

http://www.duosecurity.com/docs/duounix

We don't ever recommend invoking login_duo out of .profile or similar
files.

Also, we do have a Shibboleth module (as Mike was curious about):

http://www.duosecurity.com/docs/shibboleth

Hope that's helpful clarification, thanks guys!

Regards,
Jon Oberheide

-- 
Jon Oberheide
Co-Founder & CTO | Duo Security
1.855.DUO.AUTH | http://www.duosecurity.com


More information about the dev mailing list