Re: 2way authentication for SSH?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



-----Original Message-----
From: centos-bounces@xxxxxxxxxx [mailto:centos-bounces@xxxxxxxxxx] On Behalf Of Rudi Ahlers
Sent: Monday, January 28, 2013 8:52 AM
To: CentOS
Subject:  2way authentication for SSH?

Hi,

Does anyone know of a stable / working "2way authentication" system for
SSH, and even web authentication services?

Most of the banks in South Africa have a system that, when you want to make
a payment, they send you an SMS and you need to verify the action with a
secret code which was SMS'd to you. gmail also has this.

Does anyone know of a "universal" plugin / application that can be used
with SSH and even websites like Wordpress / Joolma / Webmin / etc?


Any pointer would be appreciated.

-----Original Message-----
Is it really 2way (as in mutual) authentication or 2factor authentication?
Mutual authentication is normally done with ssl (server + client) certificates.
Most http engines (apache, tomcat) do support them.

For two factor (have, know) authentication "some assembly" is required, at least for openssh.
See: http://roumenpetrov.info/openssh/

Generally speaking, you _do_ want a trusted third party (like a CA) and certainly _not_ another additional unreliable man-in-the-middle. I mean: like google. But should I trust them with regards to security and availability???

HW




______________________________________________________________________
Dit bericht kan informatie bevatten die niet voor u is bestemd. Indien u niet de geadresseerde bent of dit bericht abusievelijk aan u is toegezonden, wordt u verzocht dat aan de afzender te melden en het bericht te verwijderen. De Staat aanvaardt geen aansprakelijkheid voor schade, van welke aard ook, die verband houdt met risico's verbonden aan het elektronisch verzenden van berichten.

This message may contain information that is not intended for you. If you are not the addressee or if this message was sent to you by mistake, you are requested to inform the sender and delete the message. The State accepts no liability for damage of any kind resulting from the risks inherent in the electronic transmission of messages.
_______________________________________________
CentOS mailing list
CentOS@xxxxxxxxxx
http://lists.centos.org/mailman/listinfo/centos


[Index of Archives]     [CentOS]     [CentOS Announce]     [CentOS Development]     [CentOS ARM Devel]     [CentOS Docs]     [CentOS Virtualization]     [Carrier Grade Linux]     [Linux Media]     [Asterisk]     [DCCP]     [Netdev]     [Xorg]     [Linux USB]
  Powered by Linux