Setting Up Two-Factor Authentication for SSH

Setting Up Two-Factor Authentication for SSH

Adding 2FA to SSH requires both your SSH key/password and a time-based one-time code from an authenticator app.

Step 1 — Install Google Authenticator PAM Module

apt install libpam-google-authenticator -y

Step 2 — Configure for Your User

google-authenticator

Answer the prompts:

  • Time-based tokens? Yes
  • Scan the QR code with Google Authenticator or Authy on your phone
  • Save the emergency scratch codes in a safe place
  • Update .google_authenticator? Yes
  • Disallow multiple uses? Yes
  • Permit tokens up to 30 seconds? Yes
  • Enable rate limiting? Yes

Step 3 — Configure PAM

nano /etc/pam.d/sshd

Add at the top:

auth required pam_google_authenticator.so

Step 4 — Configure SSH

nano /etc/ssh/sshd_config

Set or add:

ChallengeResponseAuthentication yes
AuthenticationMethods publickey,keyboard-interactive

Step 5 — Restart SSH

systemctl restart sshd

Important: Test in a second terminal window before closing your current session. You will now be prompted for your SSH key then a verification code.

  • 0 Users Found This Useful
Was this answer helpful?

Related Articles

Securing SSH Access

Securing SSH Access SSH is the main entry point to your server. Hardening it is one of the most...

Setting Up a Firewall with UFW

Setting Up a Firewall with UFW UFW (Uncomplicated Firewall) makes managing firewall rules...

Installing Fail2Ban to Prevent Brute Force Attacks

Installing Fail2Ban Fail2Ban monitors your log files and automatically bans IP addresses that...

Setting Up Let's Encrypt SSL Certificates

Setting Up Let's Encrypt SSL Certificates Let's Encrypt provides free, trusted SSL certificates....

Scanning for Rootkits with rkhunter and chkrootkit

Scanning for Rootkits Rootkits are malware that hide from standard detection tools. Two widely...