DaemonForums  

Go Back   DaemonForums > OpenBSD > OpenBSD Security

OpenBSD Security Functionally paranoid!

Reply
 
Thread Tools Display Modes
  #1   (View Single Post)  
Old 12th July 2023
bceverly bceverly is offline
Shell Scout
 
Join Date: Mar 2015
Posts: 88
Question Yubikey as a second factor in OpenBSD

Hi all,

I'm wanting to use my YubiKey as a second factor when logging into my OpenBSD laptop (in other words, I want to still be required to type a correct password but want it to fail unless the YubiKey has been inserted and the metal button touched).

From reading login_yubikey's manpage, I'm seeing how to do it as a replacement for a password but not IN ADDITION TO a password.

Does anyone know if this is possible? In Linux, there is a pam module that works the correct magic behind the scenes but I'm not seeing it available in the ports tree.

Thanks!
Reply With Quote
  #2   (View Single Post)  
Old 12th July 2023
jggimi's Avatar
jggimi jggimi is offline
More noise than signal
 
Join Date: May 2008
Location: USA
Posts: 7,984
Default

It looks like login_yubikey(8) supports using challenge / response services, which might provide the additional authentication you seek. Challenge and response services are described in login.conf(5). Unfortunately I don't have a Yubikey so cannot do any testing.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
2 factor authentication stanl Off-Topic 0 10th December 2022 05:12 PM
yubikey configuration jjstorm OpenBSD Security 1 24th May 2016 04:08 PM
Two Factor Authentication Peter_APIIT OpenBSD Security 7 20th June 2015 02:50 AM
ZeuS trojan attacks bank's 2-factor authentication J65nko News 0 22nd February 2011 02:38 PM


All times are GMT. The time now is 01:17 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content copyright © 2007-2010, the authors
Daemon image copyright ©1988, Marshall Kirk McKusick