{"id":552,"date":"2016-04-17T11:51:23","date_gmt":"2016-04-17T03:51:23","guid":{"rendered":"http:\/\/www.ipcpu.com\/?p=552"},"modified":"2016-04-17T11:51:23","modified_gmt":"2016-04-17T03:51:23","slug":"linux-pam-python","status":"publish","type":"post","link":"https:\/\/c.ipcpu.com\/2016\/04\/linux-pam-python\/","title":{"rendered":"Linux\u4e0b\u4f7f\u7528pam_python\u5b9e\u73b0SSH\u7684\u53cc\u56e0\u5b50\u8ba4\u8bc1\u767b\u5f55"},"content":{"rendered":"
Linux\u4e0b\u4f7f\u7528pam_python\u5b9e\u73b0SSH\u7684\u53cc\u56e0\u5b50\u8ba4\u8bc1\u767b\u5f55.md<\/p>\n
Linux PAM Python SSH 2 Two Multi Factor Authentication Login \u53cc\u56e0\u5b50 \u591a\u56e0\u5b50 \u5bc6\u4fdd TOKEN \u4e00\u6b21\u6027\u53e3\u4ee4 PASSPOD OTP yubikey \u8ba4\u8bc1 \u5b89\u5168 \u767b\u5f55<\/p>\n
Linux\u7cfb\u7edf\u7ba1\u7406\u5458\uff08System Administrator\uff0cSA\uff09\u7ecf\u5e38\u78b0\u5230\u7684\u95ee\u9898\u5c31\u662f\u653e\u5728\u516c\u7f51\u7684\u670d\u52a1\u5668\u7ecf\u5e38\u88ab\u4eba\u731c\u6d4b\u5bc6\u7801\uff0c\u6bcf\u5929\u90fd\u53ef\u4ee5\u4ece\u7cfb\u7edf\u65e5\u5fd7\u91cc\u770b\u5230\u63a2\u6d4b\u5bc6\u7801\u7684\u4fe1\u606f\uff0c\u518d\u52a0\u4e0a\u6700\u8fd1\u5f88\u591a\u5382\u5546\u6cc4\u9732\u4e86\u5305\u542b\u7528\u6237\u5bc6\u7801\u7684\u6570\u636e\u5e93\uff0c\u649e\u5e93\u7684\u884c\u4e3a\u4e5f\u9010\u6b65\u5f00\u59cb\u8f6c\u79fb\u5230SSH\u4e0a\u3002<\/p>\n
\u6700\u521dSA\u7684\u9632\u5fa1\u624b\u6bb5\u4e00\u822c\u662f\u9650\u5236IP\u5730\u5740\u3001\u4fee\u6539SSH\u7aef\u53e3\u3001\u90e8\u7f72\u5931\u8d25\u4e00\u5b9a\u6b21\u6570\u5c31\u9501\u5b9a\u6216\u8005\u5c01IP\u7684\u7a0b\u5e8f\u6216\u8005\u811a\u672c\uff0c\u66f4\u6709\u6781\u5ba2\u60f3\u51fa\u4e86\u6572\u95e83\u6b21\u7aef\u53e3\u624d\u5f00\u653e\u7684\u529e\u6cd5\uff0c\u53ef\u8c13\u65e0\u6240\u4e0d\u7528\u5176\u6781\u3002\u4f46\u662f\u8fd9\u4e9b\u529e\u6cd5\u5f88\u591a\u90fd\u4e0d\u662f\u5f88\u65b9\u4fbf\uff0c\u6539\u4e86\u7aef\u53e3\uff0c\u8fde\u63a5\u65f6\u9700\u8981\u6307\u5b9a\u7aef\u53e3\uff1b\u9650\u5236\u4e86IP\u5730\u5740\uff0c\u53d1\u73b0\u5728\u5bb6\u4e0a\u7f51\u5c31\u767b\u5f55\u4e0d\u4e86\u4e86\uff0c\u5c01\u9501\u811a\u672c\u53ef\u80fd\u628a\u81ea\u5df1\u4e5f\u9501\u5b9a\u4e86\u3002<\/p>\n
\u5728\u5927\u516c\u53f8\u91cc\u4e00\u822c\u662f\u91c7\u7528\u7684\u201cRSA SecurID\u201d\u65b9\u6848\uff0c\u6216\u8005\u7c7b\u4f3c\u7684\u6280\u672f\u3002\u6211\u4eec\u79f0\u5176\u4e3a\u53cc\u56e0\u5b50\u8ba4\u8bc1\u6216\u8005\u591a\u56e0\u5b50\u8ba4\u8bc1\uff08Two Factor Authentication\uff1bMFA\uff0cMulti Factor Authentication\uff09\uff0c\u5728\u8f93\u5165\u5bc6\u7801\u7684\u540c\u65f6\u9700\u8981\u8f93\u5165\u4e00\u4e2a\u4e00\u6b21\u6027\u53e3\u4ee4\uff08OTP\uff0cOne Time Password\uff09\u3002\u8fd9\u79cd\u65b9\u6848\u4e5f\u6709\u8f6f\u4ef6\u5b9e\u73b0\u548c\u786c\u4ef6\u5b9e\u73b0\uff0c\u8f6f\u4ef6\u4f8b\u5982google authenticator\u3001Symantec Validation and ID Protection (VIP) \uff1b\u786c\u4ef6\u4f8b\u5982 RSA SecurID\u3001\u98de\u5929\u8bda\u4fe1\u7684\u5bc6\u4fdd\u4ea7\u54c1\u3002
\n<\/p>\n
\u4f7f\u7528RSA SecurID\u7684\u65b9\u6848\u770b\u8d77\u6765\u867d\u7136\u5f88\u597d\uff0c\u4f46\u662f\u4ed6\u9700\u8981\u72ec\u7acb\u90e8\u7f72RSA Server\uff0c\u9700\u8981\u5360\u7528\u4e00\u53f0\u670d\u52a1\u5668\uff0c\u5e76\u4e14Server\u7aef\u8f6f\u4ef6\u662f\u6536\u8d39\u7684\uff0cRSA SecurID\u5bc6\u4fdd\u4e5f\u662f\u6536\u8d39\u7684\u3002<\/p>\n
\u6709\u6ca1\u6709\u514d\u8d39\u7684\u529e\u6cd5\uff1f<\/p>\n
\u6709\u554a\uff0c\u4eca\u5929\u5c31\u6765\u4ecb\u7ecd\u4e00\u4e2a\u3002<\/p>\n
\u6700\u7b80\u5355\u7684\u5b9e\u73b0\u7684\u65b9\u5f0f\uff0c\u7528\u6237\u767b\u5f55\u65f6\u9700\u8981\u8f93\u5165\u7528\u6237\u540d+PIN+\u5bc6\u7801\u65b9\u5f0f\u624d\u80fd\u767b\u5f55\u3002<\/p>\n
\u8fd9\u91cc\u7684PIN\u662f\u4e00\u4e2a\u5b57\u7b26\u4e32\uff0c\u4f8b\u5982\u201dipcpu.com\u201d\uff0c\u56fa\u5b9a\u6b7b\u7684\uff0c\u4e0d\u4f1a\u53d8\u3002<\/p>\n
[<\/span>root@IPCPU<\/span>-<\/span>0<\/span> security<\/span>]#<\/span> ssh root@192<\/span>.<\/span>168.110<\/span>.<\/span>11<\/span><\/code><\/li>
Enter<\/span> <\/span>Your<\/span> PIN<\/span>:<\/span> <\/span><\/code><\/li>
Password<\/span>:<\/span> <\/span><\/code><\/li>
Last<\/span> login<\/span>:<\/span> <\/span>Mon<\/span> <\/span>Mar<\/span> <\/span>21<\/span> <\/span>00<\/span>:<\/span>44<\/span>:<\/span>26<\/span> <\/span>2016<\/span> <\/span>from<\/span> <\/span>192.168<\/span>.<\/span>110.11<\/span><\/code><\/li>
[<\/span>root@IPCPU<\/span>-<\/span>11<\/span> <\/span>~]#<\/span><\/code><\/li><\/ol><\/pre>\n
\u5b89\u88c5pam_python\u6a21\u5757<\/h2>\n
pam_python \uff08\u6ce8\u610f\u4e0d\u662fpython_pam\uff09\u662f\u4e00\u6b3e\u5f00\u6e90\u7684\u8f6f\u4ef6\uff0c\u5c06\u9700\u8981\u4f7f\u7528C\u8bed\u8a00\u7f16\u5199\u7684PAM\u6a21\u5757\u8f6c\u6362\u6210\u4e86\u53ef\u4ee5\u4f7f\u7528python\u8bed\u8a00\u6765\u5199\uff0c\u987f\u65f6\u611f\u89c9\u65b9\u4fbf\u591a\u4e86\u3002<\/p>\n
\u5b98\u7f51\u5730\u5740\uff1ahttp:\/\/pam-python.sourceforge.net\/<\/a> <\/p>\n