discussion on shibboleth-dev (fwd)

Russ Allbery rra at stanford.edu
Thu Sep 6 13:05:51 EDT 2012


Michael Schwartz <mike at gluu.org> writes:

> Ok... I officially botched the description... but luckily Jon from Duo 
> comes to the rescue !

[...]

> From: Jon Oberheide <jono at duosecurity.com>
> To: Tom Scavo <trscavo at internet2.edu>, mike at gluu.org
> Cc: support at duosecurity.com
> Subject: discussion on shibboleth-dev

> Tom,

> The login_duo module that is commonly used to protect ssh logins should
> be invoked via OpenSSH's ForceCommand directive, either globally in
> sshd_config or wrapping individual pubkeys in the user's authorized_keys
> file:

Ah, yes, ForceCommand will work (although of course only for ssh).

-- 
Russ Allbery (rra at stanford.edu)             <http://www.eyrie.org/~eagle/>


More information about the dev mailing list