Whitelist IP from google-authenticator in sshd pam
Posted
by
spudwaffle
on Server Fault
See other posts from Server Fault
or by spudwaffle
Published on 2012-12-20T00:10:48Z
Indexed on
2012/12/20
5:04 UTC
Read the original article
Hit count: 540
My Ubuntu 12.04 server uses the google-authenticator pam module to provide two step authentication for ssh. I need to make it so that a certain IP does not need to type the verification code.
The /etc/pam.d/sshd file is below:
# PAM configuration for the Secure Shell service
# Read environment variables from /etc/environment and
# /etc/security/pam_env.conf.
auth required pam_env.so # [1]
# In Debian 4.0 (etch), locale-related environment variables were moved to
# /etc/default/locale, so read that as well.
auth required pam_env.so envfile=/etc/default/locale
# Standard Un*x authentication.
@include common-auth
# Disallow non-root logins when /etc/nologin exists.
account required pam_nologin.so
# Uncomment and edit /etc/security/access.conf if you need to set complex
# access limits that are hard to express in sshd_config.
# account required pam_access.so
# Standard Un*x authorization.
@include common-account
# Standard Un*x session setup and teardown.
@include common-session
# Print the message of the day upon successful login.
session optional pam_motd.so # [1]
# Print the status of the user's mailbox upon successful login.
session optional pam_mail.so standard noenv # [1]
# Set up user limits from /etc/security/limits.conf.
session required pam_limits.so
# Set up SELinux capabilities (need modified pam)
# session required pam_selinux.so multiple
# Standard Un*x password updating.
@include common-password
auth required pam_google_authenticator.so
I've already tried adding a
auth sufficient pam_exec.so /etc/pam.d/ip.sh
line above the google-authenticator line, but I can't understand how to check an IP adress in the bash script.
© Server Fault or respective owner