Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


    Cloudron Forum

    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular

    Do you know an alternative to libpam-google-authenticator and do you think it should be implemented in Cloudron ?

    Discuss
    ssh authentication 2fa
    3
    7
    559
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JOduMonT
      JOduMonT last edited by girish

      For the common of mortal libpam-google-authenticator allow you to request a OTP for your SSH connection. (more info)

      Since nothing is bullet proof and security work by layer, I tough it might worth it to add a layer on this precious access.

      What do you think ?

      1 Reply Last reply Reply Quote 0
      • mehdi
        mehdi App Dev last edited by

        I think this can be installed manually by the admin on the underlying OS.

        I do think it's valuable, but I believe it should be kept separate from cloudron and installed by itself on the side, a bit like Fail2ban is today. It could however be mentioned in the docs, again like fail2ban ( https://cloudron.io/documentation/security/#fail2ban )

        JOduMonT 1 Reply Last reply Reply Quote 1
        • JOduMonT
          JOduMonT @mehdi last edited by

          @mehdi said in Do you know an alternative to libpam-google-authenticator and do you think it should be implemented in Cloudron ?:

          again like fail2ban ( https://cloudron.io/documentation/security/#fail2ban )

          LOL! I thought Fail2Ban was installed by default and every containers, or at least few, where interacting with it, not to mention it again but MailCow run fail2ban by default as a container to protect SOGo and the entire Mail Stack.

          1 Reply Last reply Reply Quote 0
          • girish
            girish Staff last edited by

            For the moment, I will add it to our docs as @mehdi suggested.

            1 Reply Last reply Reply Quote 1
            • girish
              girish Staff last edited by

              I have added a section here to follow this DO guide

              JOduMonT 1 Reply Last reply Reply Quote 1
              • JOduMonT
                JOduMonT @girish last edited by

                @girish said in Do you know an alternative to libpam-google-authenticator and do you think it should be implemented in Cloudron ?:

                I have added a section here to follow this DO guide

                thanks for your consideration
                BTW I tried to update (PR) the ipset part of the doc since maxmind change their licensing and this command don't work anymore

                wget http://geolite.maxmind.com/download/geoip/database/GeoIPCountryCSV.zip
                
                1 Reply Last reply Reply Quote 0
                • girish
                  girish Staff last edited by

                  @JOduMonT Thanks! merged, should be part of our next deploy.

                  1 Reply Last reply Reply Quote 1
                  • First post
                    Last post
                  Powered by NodeBB