How to force 2FA(Password + OTP) on IPA Clients for ssh authentications
Issue
- Identity Management Administrators may need to require some user accounts to access
IPA clients
with multifactor authentication or MFA (likepassword
andtotp
(token-based one time password) orhotp
(hmac one time password). - This article examines how to configure an
IPA client
forSSH
authentication usingOTP
.
Environment
- Red Hat Enterpise Linux 7, 8, and 9
- Red Hat Identity Management (IdM)
- IPA Client
- OpenSSH
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.