#MFA without relying on a 3th party?

1 messages · Page 1 of 1 (latest)

fathom sinew
#

Hi,

Is there a possibility to do MFA for system manager without having to rely on a 3th party like SAML or OAUTH require?

With ssh, you can use a TOTP. But not for the web interface right?

Thanks
Pieter

charred cosmos
supple parrot
#

Are there any overlap between CLI and System Manager regarding MFA?

manic ivy
#

Technically, mfa could be
Password + PublicKey

charred cosmos
#

FIDO2 works for both so since 9.16.1 you can use that as unified solution (you need an SSH client that supports CAC though, regular PuTTY doesn't, so either use the PuTTY-CAC fork or, reportedly, a recent OpenSSH client)

#

TR-4647 has all the details on how to set it up