SSH Two Factor Authentication
Spriv's PAM module adds a second factor to every SSH login on your Linux and Unix servers. Users authenticate once, then later sessions are validated continuously in the background, so the shell opens as fast as it always has.
A single SSH credential can open a whole server
SSH is how administrators reach production. If one password or private key leaks, the attacker gets the same shell your admins do, unless a second factor stands in the way.
Guessed and reused passwords
Internet-facing SSH is scanned and brute forced constantly, and passwords reused from other breaches work on the first try.
Stolen private keys
Keys copied from a laptop, a backup or a CI system never expire on their own. A second factor makes a copied key useless by itself.
Compliance requirements
PCI DSS calls for two-factor authentication on remote administrative access, and FFIEC, HIPAA and SOX expect strong authentication.
How Spriv adds two factor authentication to SSH
sshd hands off to PAM
With UsePAM enabled, the SSH daemon runs Spriv's module as part of the server's PAM stack. No change to the SSH client is needed.
Spriv checks the pair
The user's paired phone and the connecting workstation are verified in the background. A trusted pair passes without a prompt.
Challenge only when it matters
An unfamiliar pair falls through to another method: push approval, two-way SMS or a TOTP code typed at the prompt.
Works alongside SSH keys
The recommended sshd configuration keeps public-key authentication on and turns password logins off, with Spriv's PAM module adding the second factor through challenge-response.
Before restarting SSH, leave your current session open and test from a second connection, so a typo in the configuration can't lock you out. PAM module stacking differs between distributions such as Fedora, CentOS and Ubuntu.
UsePAM yes ChallengeResponseAuthentication yes UseDNS no PubkeyAuthentication yes PasswordAuthentication no
Installing SSH 2FA on a Linux server
1. Pair the user
The login user must exist in Spriv's end-user list and have a paired phone before you install.
2. Build the module
Request the Linux Adaptive PAM/SSH package, then run the build script, configure, make and make install.
3. Add your keys
Put your company key and secret in /etc/spriv/pam.conf.
4. Wire up SSH
Update sshd_config and /etc/pam.d/sshd, enable the SELinux boolean where required, then restart SSH.
SSH two factor authentication questions
Do I have to give up SSH keys?
No. The recommended configuration keeps public-key authentication enabled and disables password logins, with Spriv providing the second factor.
Which authentication methods work over SSH?
Adaptive authentication (the default, no interaction on a trusted pair), push approval, two-way SMS and TOTP codes.
What if my phone has no signal?
Use TOTP. The Spriv app generates a six-digit code from the phone's clock every 30 seconds, with no internet or carrier reception needed.
Does it also protect sudo and su?
Yes, the same PAM module covers privilege escalation. sudo and su MFA.
How do I roll it out to many servers?
Install and test on one server first. The configuration files are the same on every host, so your configuration management tools can push them across the fleet.
Related pages
Two factor authentication for every SSH login
Two free users and two free servers, no credit card. Install the PAM module in under five minutes.