discussion on shibboleth-dev (fwd)

Tom Scavo trscavo at gmail.com
Thu Sep 6 13:29:56 EDT 2012


On Thu, Sep 6, 2012 at 1:05 PM, Russ Allbery <rra at stanford.edu> wrote:
>
>> The login_duo module that is commonly used to protect ssh logins should
>> be invoked via OpenSSH's ForceCommand directive, either globally in
>> sshd_config or wrapping individual pubkeys in the user's authorized_keys
>> file:
>
> Ah, yes, ForceCommand will work (although of course only for ssh).

Alternatively, PAM may be used for more comprehensive coverage [1]
and/or you can secure your VPN with the same technology. Ten different
VPN products are supported. (I haven't tried any of these yet,
however.)

We're using the Duo Verify API [2] to architect a kind of two-factor
password reset process. We hope to have this ready for demo at the
upcoming Member Meeting.

Tom

[1] http://www.duosecurity.com/docs/duounix
[2] http://www.duosecurity.com/docs/duoverify


More information about the dev mailing list