Linux & Unix · Multi Factor Authentication

SSH Two Factor Authentication

Spriv's PAM module adds a second factor to every SSH login on your Linux and Unix servers. Users authenticate once, then later sessions are validated continuously in the background, so the shell opens as fast as it always has.

Six-digit TOTP code in the Spriv app, used as an offline second factor for SSH
SSH 2FA · Adaptive by default, TOTP when offline
0
Codes to type on a trusted login
0
Entry points from one module: SSH, su and sudo
0 s
TOTP fallback refresh, works offline
0 min
Install time, start to finish
Why SSH needs 2FA

A single SSH credential can open a whole server

SSH is how administrators reach production. If one password or private key leaks, the attacker gets the same shell your admins do, unless a second factor stands in the way.

Guessed and reused passwords

Internet-facing SSH is scanned and brute forced constantly, and passwords reused from other breaches work on the first try.

Stolen private keys

Keys copied from a laptop, a backup or a CI system never expire on their own. A second factor makes a copied key useless by itself.

Compliance requirements

PCI DSS calls for two-factor authentication on remote administrative access, and FFIEC, HIPAA and SOX expect strong authentication.

How it works

How Spriv adds two factor authentication to SSH

STEP 01

sshd hands off to PAM

With UsePAM enabled, the SSH daemon runs Spriv's module as part of the server's PAM stack. No change to the SSH client is needed.

STEP 02

Spriv checks the pair

The user's paired phone and the connecting workstation are verified in the background. A trusted pair passes without a prompt.

STEP 03

Challenge only when it matters

An unfamiliar pair falls through to another method: push approval, two-way SMS or a TOTP code typed at the prompt.

Configuration

Works alongside SSH keys

The recommended sshd configuration keeps public-key authentication on and turns password logins off, with Spriv's PAM module adding the second factor through challenge-response.

Before restarting SSH, leave your current session open and test from a second connection, so a typo in the configuration can't lock you out. PAM module stacking differs between distributions such as Fedora, CentOS and Ubuntu.

/etc/ssh/sshd_config
UsePAM yes
ChallengeResponseAuthentication yes
UseDNS no
PubkeyAuthentication yes
PasswordAuthentication no
Deployment

Installing SSH 2FA on a Linux server

1. Pair the user

The login user must exist in Spriv's end-user list and have a paired phone before you install.

2. Build the module

Request the Linux Adaptive PAM/SSH package, then run the build script, configure, make and make install.

3. Add your keys

Put your company key and secret in /etc/spriv/pam.conf.

4. Wire up SSH

Update sshd_config and /etc/pam.d/sshd, enable the SELinux boolean where required, then restart SSH.

Questions

SSH two factor authentication questions

Do I have to give up SSH keys?

No. The recommended configuration keeps public-key authentication enabled and disables password logins, with Spriv providing the second factor.

Which authentication methods work over SSH?

Adaptive authentication (the default, no interaction on a trusted pair), push approval, two-way SMS and TOTP codes.

What if my phone has no signal?

Use TOTP. The Spriv app generates a six-digit code from the phone's clock every 30 seconds, with no internet or carrier reception needed.

Does it also protect sudo and su?

Yes, the same PAM module covers privilege escalation. sudo and su MFA.

How do I roll it out to many servers?

Install and test on one server first. The configuration files are the same on every host, so your configuration management tools can push them across the fleet.

Checkit!

Two factor authentication for every SSH login

Two free users and two free servers, no credit card. Install the PAM module in under five minutes.