{"id":552,"date":"2016-04-17T11:51:23","date_gmt":"2016-04-17T03:51:23","guid":{"rendered":"http:\/\/www.ipcpu.com\/?p=552"},"modified":"2016-04-17T11:51:23","modified_gmt":"2016-04-17T03:51:23","slug":"linux-pam-python","status":"publish","type":"post","link":"https:\/\/c.ipcpu.com\/2016\/04\/linux-pam-python\/","title":{"rendered":"Linux\u4e0b\u4f7f\u7528pam_python\u5b9e\u73b0SSH\u7684\u53cc\u56e0\u5b50\u8ba4\u8bc1\u767b\u5f55"},"content":{"rendered":"

Linux\u4e0b\u4f7f\u7528pam_python\u5b9e\u73b0SSH\u7684\u53cc\u56e0\u5b50\u8ba4\u8bc1\u767b\u5f55.md<\/p>\n

\u5173\u952e\u5b57<\/h3>\n

Linux PAM Python SSH 2 Two Multi Factor Authentication Login \u53cc\u56e0\u5b50 \u591a\u56e0\u5b50 \u5bc6\u4fdd TOKEN \u4e00\u6b21\u6027\u53e3\u4ee4 PASSPOD OTP yubikey \u8ba4\u8bc1 \u5b89\u5168 \u767b\u5f55<\/p>\n

\u5f15\u8a00<\/h2>\n

Linux\u7cfb\u7edf\u7ba1\u7406\u5458\uff08System Administrator\uff0cSA\uff09\u7ecf\u5e38\u78b0\u5230\u7684\u95ee\u9898\u5c31\u662f\u653e\u5728\u516c\u7f51\u7684\u670d\u52a1\u5668\u7ecf\u5e38\u88ab\u4eba\u731c\u6d4b\u5bc6\u7801\uff0c\u6bcf\u5929\u90fd\u53ef\u4ee5\u4ece\u7cfb\u7edf\u65e5\u5fd7\u91cc\u770b\u5230\u63a2\u6d4b\u5bc6\u7801\u7684\u4fe1\u606f\uff0c\u518d\u52a0\u4e0a\u6700\u8fd1\u5f88\u591a\u5382\u5546\u6cc4\u9732\u4e86\u5305\u542b\u7528\u6237\u5bc6\u7801\u7684\u6570\u636e\u5e93\uff0c\u649e\u5e93\u7684\u884c\u4e3a\u4e5f\u9010\u6b65\u5f00\u59cb\u8f6c\u79fb\u5230SSH\u4e0a\u3002<\/p>\n

\u6700\u521dSA\u7684\u9632\u5fa1\u624b\u6bb5\u4e00\u822c\u662f\u9650\u5236IP\u5730\u5740\u3001\u4fee\u6539SSH\u7aef\u53e3\u3001\u90e8\u7f72\u5931\u8d25\u4e00\u5b9a\u6b21\u6570\u5c31\u9501\u5b9a\u6216\u8005\u5c01IP\u7684\u7a0b\u5e8f\u6216\u8005\u811a\u672c\uff0c\u66f4\u6709\u6781\u5ba2\u60f3\u51fa\u4e86\u6572\u95e83\u6b21\u7aef\u53e3\u624d\u5f00\u653e\u7684\u529e\u6cd5\uff0c\u53ef\u8c13\u65e0\u6240\u4e0d\u7528\u5176\u6781\u3002\u4f46\u662f\u8fd9\u4e9b\u529e\u6cd5\u5f88\u591a\u90fd\u4e0d\u662f\u5f88\u65b9\u4fbf\uff0c\u6539\u4e86\u7aef\u53e3\uff0c\u8fde\u63a5\u65f6\u9700\u8981\u6307\u5b9a\u7aef\u53e3\uff1b\u9650\u5236\u4e86IP\u5730\u5740\uff0c\u53d1\u73b0\u5728\u5bb6\u4e0a\u7f51\u5c31\u767b\u5f55\u4e0d\u4e86\u4e86\uff0c\u5c01\u9501\u811a\u672c\u53ef\u80fd\u628a\u81ea\u5df1\u4e5f\u9501\u5b9a\u4e86\u3002<\/p>\n

\u5728\u5927\u516c\u53f8\u91cc\u4e00\u822c\u662f\u91c7\u7528\u7684\u201cRSA SecurID\u201d\u65b9\u6848\uff0c\u6216\u8005\u7c7b\u4f3c\u7684\u6280\u672f\u3002\u6211\u4eec\u79f0\u5176\u4e3a\u53cc\u56e0\u5b50\u8ba4\u8bc1\u6216\u8005\u591a\u56e0\u5b50\u8ba4\u8bc1\uff08Two Factor Authentication\uff1bMFA\uff0cMulti Factor Authentication\uff09\uff0c\u5728\u8f93\u5165\u5bc6\u7801\u7684\u540c\u65f6\u9700\u8981\u8f93\u5165\u4e00\u4e2a\u4e00\u6b21\u6027\u53e3\u4ee4\uff08OTP\uff0cOne Time Password\uff09\u3002\u8fd9\u79cd\u65b9\u6848\u4e5f\u6709\u8f6f\u4ef6\u5b9e\u73b0\u548c\u786c\u4ef6\u5b9e\u73b0\uff0c\u8f6f\u4ef6\u4f8b\u5982google authenticator\u3001Symantec Validation and ID Protection (VIP) \uff1b\u786c\u4ef6\u4f8b\u5982 RSA SecurID\u3001\u98de\u5929\u8bda\u4fe1\u7684\u5bc6\u4fdd\u4ea7\u54c1\u3002
\n\"\"<\/p>\n

\u4f7f\u7528RSA SecurID\u7684\u65b9\u6848\u770b\u8d77\u6765\u867d\u7136\u5f88\u597d\uff0c\u4f46\u662f\u4ed6\u9700\u8981\u72ec\u7acb\u90e8\u7f72RSA Server\uff0c\u9700\u8981\u5360\u7528\u4e00\u53f0\u670d\u52a1\u5668\uff0c\u5e76\u4e14Server\u7aef\u8f6f\u4ef6\u662f\u6536\u8d39\u7684\uff0cRSA SecurID\u5bc6\u4fdd\u4e5f\u662f\u6536\u8d39\u7684\u3002<\/p>\n

\u6709\u6ca1\u6709\u514d\u8d39\u7684\u529e\u6cd5\uff1f<\/p>\n

\u6709\u554a\uff0c\u4eca\u5929\u5c31\u6765\u4ecb\u7ecd\u4e00\u4e2a\u3002<\/p>\n

\u5b9e\u73b0\u65b9\u6cd5<\/h2>\n

\u6700\u7b80\u5355\u7684\u5b9e\u73b0\u7684\u65b9\u5f0f\uff0c\u7528\u6237\u767b\u5f55\u65f6\u9700\u8981\u8f93\u5165\u7528\u6237\u540d+PIN+\u5bc6\u7801\u65b9\u5f0f\u624d\u80fd\u767b\u5f55\u3002<\/p>\n

\u8fd9\u91cc\u7684PIN\u662f\u4e00\u4e2a\u5b57\u7b26\u4e32\uff0c\u4f8b\u5982\u201dipcpu.com\u201d\uff0c\u56fa\u5b9a\u6b7b\u7684\uff0c\u4e0d\u4f1a\u53d8\u3002<\/p>\n

  1. [<\/span>root@IPCPU<\/span>-<\/span>0<\/span> security<\/span>]#<\/span> ssh root@192<\/span>.<\/span>168.110<\/span>.<\/span>11<\/span><\/code><\/li>
  2. Enter<\/span> <\/span>Your<\/span> PIN<\/span>:<\/span> <\/span><\/code><\/li>
  3. Password<\/span>:<\/span> <\/span><\/code><\/li>
  4. Last<\/span> login<\/span>:<\/span> <\/span>Mon<\/span> <\/span>Mar<\/span> <\/span>21<\/span> <\/span>00<\/span>:<\/span>44<\/span>:<\/span>26<\/span> <\/span>2016<\/span> <\/span>from<\/span> <\/span>192.168<\/span>.<\/span>110.11<\/span><\/code><\/li>
  5. [<\/span>root@IPCPU<\/span>-<\/span>11<\/span> <\/span>~]#<\/span><\/code><\/li><\/ol><\/pre>\n

    \u5b89\u88c5pam_python\u6a21\u5757<\/h2>\n

    pam_python \uff08\u6ce8\u610f\u4e0d\u662fpython_pam\uff09\u662f\u4e00\u6b3e\u5f00\u6e90\u7684\u8f6f\u4ef6\uff0c\u5c06\u9700\u8981\u4f7f\u7528C\u8bed\u8a00\u7f16\u5199\u7684PAM\u6a21\u5757\u8f6c\u6362\u6210\u4e86\u53ef\u4ee5\u4f7f\u7528python\u8bed\u8a00\u6765\u5199\uff0c\u987f\u65f6\u611f\u89c9\u65b9\u4fbf\u591a\u4e86\u3002<\/p>\n

    \u5b98\u7f51\u5730\u5740\uff1ahttp:\/\/pam-python.sourceforge.net\/<\/a> <\/p>\n

    github\u5907\u4efd\uff1ahttps:\/\/github.com\/ipcpu\/pam-python-ipcpu<\/a> \uff08\u4fee\u6b63\u4e86CentOS\u7684\u62a5\u9519\uff0c\u653e\u4e86\u4e00\u4e9b\u6848\u4f8b\u548c\u4e2d\u6587\u8bf4\u660e\u8fdb\u53bb\uff09<\/p>\n

    \u5b89\u88c5\u65b9\u6cd5\u6bd4\u8f83\u7b80\u5355<\/p>\n

    1. ##@@\u5b89\u88c5\u7f16\u8bd1\u4f9d\u8d56<\/span><\/code><\/li>
    2. yum install pam pam<\/span>-<\/span>devel <\/span>-<\/span>y<\/span><\/code><\/li>
    3. ##@@\u89e3\u538b\u8fdb\u5165src\u76ee\u5f55<\/span><\/code><\/li>
    4. make lib<\/span><\/code><\/li>
    5. ##@@\u62f7\u8d1d.so\u6587\u4ef6\u5230\/lib64\/security\/<\/span><\/code><\/li>
    6. cp build<\/span>\/<\/span>lib<\/span>.<\/span>linux<\/span>-<\/span>x86_64<\/span>-<\/span>2.6<\/span>\/<\/span>pam_python<\/span>.<\/span>so <\/span>\/<\/span>lib64<\/span>\/<\/span>security<\/span>\/<\/span><\/code><\/li><\/ol><\/pre>\n

      \u7f16\u5199Python\u7a0b\u5e8f\u5b9e\u73b0\u8ba4\u8bc1\u6d41\u7a0b<\/h2>\n

      \u6211\u4eec\u8fdb\u5165\u5230 \/lib64\/security\/ \u7f16\u5199\u4e00\u4e2aauth.py\u6587\u4ef6\uff0c\u5185\u5bb9\u5982\u4e0b<\/p>\n

      1. #!\/usr\/bin\/env python<\/span><\/code><\/li>
      2. # -*- coding=utf-8 -*-<\/span><\/code><\/li>
      3. <\/code><\/li>
      4. \"\"\"<\/span><\/code><\/li>
      5. #\u8fd9\u4e2a\u51fd\u6570\u662f\u672c\u6b21\u7684\u91cd\u70b9\u5185\u5bb9\u54e6\uff0c\u5224\u65ad\u7528\u6237\u8f93\u5165\u7684PIN\u662f\u5426\u4e3aipcpu.com<\/span><\/code><\/li>
      6. \"\"\"<\/span><\/code><\/li>
      7. def<\/span> pam_sm_authenticate<\/span>(<\/span>pamh<\/span>,<\/span> flags<\/span>,<\/span> argv<\/span>):<\/span><\/code><\/li>
      8. <\/code><\/li>
      9. <\/span>for<\/span> attempt <\/span>in<\/span> range<\/span>(<\/span>0<\/span>,<\/span>3<\/span>):<\/span> <\/span><\/code><\/li>
      10. msg <\/span>=<\/span> pamh<\/span>.<\/span>Message<\/span>(<\/span>pamh<\/span>.<\/span>PAM_PROMPT_ECHO_OFF<\/span>,<\/span> <\/span>\"Enter Your PIN: \"<\/span>)<\/span><\/code><\/li>
      11. resp <\/span>=<\/span> pamh<\/span>.<\/span>conversation<\/span>(<\/span>msg<\/span>)<\/span><\/code><\/li>
      12. <\/code><\/li>
      13. <\/span>if<\/span> resp<\/span>.<\/span>resp <\/span>==<\/span> <\/span>\"ipcpu.com\"<\/span>:<\/span><\/code><\/li>
      14. <\/span>return<\/span> pamh<\/span>.<\/span>PAM_SUCCESS<\/span><\/code><\/li>
      15. <\/span>else<\/span>:<\/span><\/code><\/li>
      16. <\/span>continue<\/span><\/code><\/li>
      17. <\/span>return<\/span> pamh<\/span>.<\/span>PAM_AUTH_ERR<\/span><\/code><\/li>
      18. <\/code><\/li>
      19. \"\"\"<\/span><\/code><\/li>
      20. #\u4ee5\u4e0b\u90fd\u662f\u9ed8\u8ba4\u51fd\u6570<\/span><\/code><\/li>
      21. \"\"\"<\/span><\/code><\/li>
      22. def<\/span> pam_sm_setcred<\/span>(<\/span>pamh<\/span>,<\/span> flags<\/span>,<\/span> argv<\/span>):<\/span><\/code><\/li>
      23. <\/span>return<\/span> pamh<\/span>.<\/span>PAM_SUCCESS<\/span><\/code><\/li>
      24. <\/code><\/li>
      25. def<\/span> pam_sm_acct_mgmt<\/span>(<\/span>pamh<\/span>,<\/span> flags<\/span>,<\/span> argv<\/span>):<\/span><\/code><\/li>
      26. <\/span>return<\/span> pamh<\/span>.<\/span>PAM_SUCCESS<\/span><\/code><\/li>
      27. <\/code><\/li>
      28. def<\/span> pam_sm_open_session<\/span>(<\/span>pamh<\/span>,<\/span> flags<\/span>,<\/span> argv<\/span>):<\/span><\/code><\/li>
      29. <\/span>return<\/span> pamh<\/span>.<\/span>PAM_SUCCESS<\/span><\/code><\/li>
      30. <\/code><\/li>
      31. def<\/span> pam_sm_close_session<\/span>(<\/span>pamh<\/span>,<\/span> flags<\/span>,<\/span> argv<\/span>):<\/span><\/code><\/li>
      32. <\/span>return<\/span> pamh<\/span>.<\/span>PAM_SUCCESS<\/span><\/code><\/li>
      33. <\/code><\/li>
      34. def<\/span> pam_sm_chauthtok<\/span>(<\/span>pamh<\/span>,<\/span> flags<\/span>,<\/span> argv<\/span>):<\/span><\/code><\/li>
      35. <\/span>return<\/span> pamh<\/span>.<\/span>PAM_SUCCESS<\/span><\/code><\/li><\/ol><\/pre>\n

        \u914d\u7f6eSSHD\uff0c\u5f00\u542fPAM\u6a21\u5757<\/h2>\n

        \u4fee\u6539\/etc\/pam.d\/sshd\uff0c\u65b0\u589e\u4e00\u884c\uff0c\u5982\u4e0b<\/p>\n

        1. #%PAM-1.0<\/span><\/code><\/li>
        2. auth requisite pam_python<\/span>.<\/span>so auth<\/span>.<\/span>py<\/span><\/code><\/li>
        3. auth required pam_sepermit<\/span>.<\/span>so<\/span><\/code><\/li>
        4. auth include password<\/span>-<\/span>auth<\/span><\/code><\/li><\/ol><\/pre>\n

          \u4fee\u6539\/etc\/ssh\/sshd_config\uff0c\u6253\u5f00ChallengeResponse<\/p>\n

          1. ChallengeResponseAuthentication<\/span> yes<\/span><\/code><\/li><\/ol><\/pre>\n

            \u91cd\u542fSSHD\u670d\u52a1\uff0c\u63a5\u4e0b\u6765\u5c31\u53ef\u4ee5\u6d4b\u8bd5\u4e86\u3002<\/p>\n

            \u5982\u679c\u51fa\u73b0\u9519\u8bef\uff0c\u65e5\u5fd7\u4f1a\u5199\u5230\/var\/log\/secure\u91cc\u9762\u3002<\/p>\n

            \u8fdb\u9636-\u72ec\u7acb\u7684PIN<\/h2>\n

            \u4f7f\u7528\u56fa\u5b9a\u7684PIN\u4f18\u70b9\u592alow\u4e86\uff0c\u63a5\u4e0b\u6765\u6211\u4eec\u4ecb\u7ecd\u8fdb\u9636\u7684\u529e\u6cd5\uff0c\u6bcf\u4e2a\u4eba\u7528\u81ea\u5df1\u7684PIN\u3002<\/p>\n

            \u9996\u5148PIN\u9700\u8981\u6709\u4e2a\u5730\u65b9\u5b58\u653e\u8d77\u6765\uff0c\u6211\u4eec\u5c31\u76f4\u63a5\u4f7f\u7528\/etc\/passwd\u7684comment\u5b57\u6bb5\u6765\u5b58\u50a8\u3002<\/p>\n

            \u53ef\u4ee5\u901a\u8fc7\u547d\u4ee4 usermod\u6765\u4fee\u6539\u3002\u5982\u4e0b\uff0c<\/p>\n

            1. [<\/span>root@IPCPU <\/span>2factor<\/span>-<\/span>with<\/span>-<\/span>PIN<\/span>]#<\/span> usermod <\/span>-<\/span>c <\/span>',,15801581158,'<\/span> ipcpu<\/span><\/code><\/li>
            2. [<\/span>root@IPCPU <\/span>2factor<\/span>-<\/span>with<\/span>-<\/span>PIN<\/span>]#<\/span> cat <\/span>\/<\/span>etc<\/span>\/<\/span>passwd <\/span>|<\/span>grep ipcpu<\/span><\/code><\/li>
            3. ipcpu<\/span>:<\/span>x<\/span>:<\/span>501<\/span>:<\/span>501<\/span>:,,<\/span>15801581158<\/span>,:<\/span>\/home\/<\/span>ipcpu<\/span>:<\/span>\/bin\/<\/span>bash<\/span><\/code><\/li>
            4. [<\/span>root@IPCPU <\/span>2factor<\/span>-<\/span>with<\/span>-<\/span>PIN<\/span>]#<\/span><\/code><\/li><\/ol><\/pre>\n

              python\u7684\u4ee3\u7801\u4e5f\u9700\u8981\u4fee\u6539\u4e0b,\u5982\u4e0b<\/p>\n

              1. import<\/span> random<\/span>,<\/span> <\/span>string<\/span>,<\/span> hashlib<\/span>,<\/span> requests<\/span><\/code><\/li>
              2. import<\/span> pwd<\/span>,<\/span> syslog<\/span><\/code><\/li>
              3. <\/code><\/li>
              4. def<\/span> auth_log<\/span>(<\/span>msg<\/span>):<\/span><\/code><\/li>
              5. syslog<\/span>.<\/span>syslog<\/span>(<\/span>\"IPCPU-PAM-AUTH: \"<\/span> <\/span>+<\/span> msg<\/span>)<\/span><\/code><\/li>
              6. <\/code><\/li>
              7. <\/code><\/li>
              8. def<\/span> get_user_number<\/span>(<\/span>user<\/span>):<\/span><\/code><\/li>
              9. <\/span>\"\"\"Extract user's phone number for pw entry\"\"\"<\/span><\/code><\/li>
              10. <\/span>try<\/span>:<\/span><\/code><\/li>
              11. comments <\/span>=<\/span> pwd<\/span>.<\/span>getpwnam<\/span>(<\/span>user<\/span>).<\/span>pw_gecos<\/span><\/code><\/li>
              12. <\/span>except<\/span> <\/span>KeyError<\/span>:<\/span> <\/span># Bad user name<\/span><\/code><\/li>
              13. auth_log<\/span>(<\/span>\"No local user (%s) found.\"<\/span> <\/span>%<\/span> user<\/span>)<\/span><\/code><\/li>
              14. <\/span>return<\/span> <\/span>-<\/span>1<\/span><\/code><\/li>
              15. <\/code><\/li>
              16. <\/span>try<\/span>:<\/span><\/code><\/li>
              17. <\/span>return<\/span> comments<\/span>.<\/span>split<\/span>(<\/span>','<\/span>)[<\/span>2<\/span>]<\/span> <\/span># Return Office Phone<\/span><\/code><\/li>
              18. <\/span>except<\/span> <\/span>IndexError<\/span>:<\/span> <\/span># Bad comment section format<\/span><\/code><\/li>
              19. auth_log<\/span>(<\/span>\"Invalid comment block for user %s. Phone number must be listed as Office Phone\"<\/span> <\/span>%<\/span> <\/span>(<\/span>user<\/span>))<\/span><\/code><\/li>
              20. <\/span>return<\/span> <\/span>-<\/span>1<\/span><\/code><\/li>
              21. <\/code><\/li>
              22. <\/code><\/li>
              23. def<\/span> pam_sm_authenticate<\/span>(<\/span>pamh<\/span>,<\/span> flags<\/span>,<\/span> argv<\/span>):<\/span><\/code><\/li>
              24. <\/span>try<\/span>:<\/span><\/code><\/li>
              25. user <\/span>=<\/span> pamh<\/span>.<\/span>get_user<\/span>()<\/span><\/code><\/li>
              26. user_number <\/span>=<\/span> get_user_number<\/span>(<\/span>user<\/span>)<\/span><\/code><\/li>
              27. <\/span>except<\/span> pamh<\/span>.<\/span>exception<\/span>,<\/span> e<\/span>:<\/span><\/code><\/li>
              28. <\/span>return<\/span> e<\/span>.<\/span>pam_result<\/span><\/code><\/li>
              29. <\/code><\/li>
              30. <\/span>if<\/span> user <\/span>is<\/span> <\/span>None<\/span> <\/span>or<\/span> user_number <\/span>==<\/span> <\/span>-<\/span>1<\/span>:<\/span><\/code><\/li>
              31. msg <\/span>=<\/span> pamh<\/span>.<\/span>Message<\/span>(<\/span>pamh<\/span>.<\/span>PAM_ERROR_MSG<\/span>,<\/span> <\/span>\"Unable to send one time PIN.\\nPlease contact your System Administrator\"<\/span>)<\/span><\/code><\/li>
              32. pamh<\/span>.<\/span>conversation<\/span>(<\/span>msg<\/span>)<\/span><\/code><\/li>
              33. <\/span>return<\/span> pamh<\/span>.<\/span>PAM_AUTH_ERR<\/span><\/code><\/li>
              34. <\/code><\/li>
              35. <\/span>for<\/span> attempt <\/span>in<\/span> range<\/span>(<\/span>0<\/span>,<\/span>3<\/span>):<\/span> <\/span># 3 attempts to enter the one time PIN<\/span><\/code><\/li>
              36. msg <\/span>=<\/span> pamh<\/span>.<\/span>Message<\/span>(<\/span>pamh<\/span>.<\/span>PAM_PROMPT_ECHO_OFF<\/span>,<\/span> <\/span>\"Enter Your PIN: \"<\/span>)<\/span><\/code><\/li>
              37. resp <\/span>=<\/span> pamh<\/span>.<\/span>conversation<\/span>(<\/span>msg<\/span>)<\/span><\/code><\/li>
              38. <\/code><\/li>
              39. <\/span>if<\/span> resp<\/span>.<\/span>resp <\/span>==<\/span> user_number<\/span>:<\/span><\/code><\/li>
              40. auth_log<\/span>(<\/span>\"user: \"<\/span> <\/span>+<\/span> user <\/span>+<\/span> <\/span>\" login successful with PIN.\"<\/span>)<\/span><\/code><\/li>
              41. <\/span>return<\/span> pamh<\/span>.<\/span>PAM_SUCCESS<\/span><\/code><\/li>
              42. <\/span>else<\/span>:<\/span><\/code><\/li>
              43. auth_log<\/span>(<\/span>\"user: \"<\/span> <\/span>+<\/span> user <\/span>+<\/span> <\/span>\" login failed with PIN.\"<\/span>)<\/span><\/code><\/li>
              44. <\/span>continue<\/span><\/code><\/li>
              45. <\/span>return<\/span> pamh<\/span>.<\/span>PAM_AUTH_ERR<\/span><\/code><\/li>
              46. <\/code><\/li>
              47. def<\/span> pam_sm_setcred<\/span>(<\/span>pamh<\/span>,<\/span> flags<\/span>,<\/span> argv<\/span>):<\/span><\/code><\/li>
              48. <\/span>return<\/span> pamh<\/span>.<\/span>PAM_SUCCESS<\/span><\/code><\/li>
              49. <\/code><\/li>
              50. def<\/span> pam_sm_acct_mgmt<\/span>(<\/span>pamh<\/span>,<\/span> flags<\/span>,<\/span> argv<\/span>):<\/span><\/code><\/li>
              51. <\/span>return<\/span> pamh<\/span>.<\/span>PAM_SUCCESS<\/span><\/code><\/li>
              52. <\/code><\/li>
              53. def<\/span> pam_sm_open_session<\/span>(<\/span>pamh<\/span>,<\/span> flags<\/span>,<\/span> argv<\/span>):<\/span><\/code><\/li>
              54. <\/span>return<\/span> pamh<\/span>.<\/span>PAM_SUCCESS<\/span><\/code><\/li>
              55. <\/code><\/li>
              56. def<\/span> pam_sm_close_session<\/span>(<\/span>pamh<\/span>,<\/span> flags<\/span>,<\/span> argv<\/span>):<\/span><\/code><\/li>
              57. <\/span>return<\/span> pamh<\/span>.<\/span>PAM_SUCCESS<\/span><\/code><\/li>
              58. <\/code><\/li>
              59. def<\/span> pam_sm_chauthtok<\/span>(<\/span>pamh<\/span>,<\/span> flags<\/span>,<\/span> argv<\/span>):<\/span><\/code><\/li>
              60. <\/span>return<\/span> pamh<\/span>.<\/span>PAM_SUCCESS<\/span><\/code><\/li><\/ol><\/pre>\n

                \u7ee7\u7eed\u8fdb\u9636-\u77ed\u4fe1<\/h2>\n

                \u4e0a\u4e00\u6b65\uff0c\u6211\u4eec\u4f7f\u7528\u4e86\u6bcf\u4e2a\u7528\u6237\u72ec\u7acb\u7684PIN\u6765\u8fdb\u884c\u53cc\u56e0\u5b50\u8ba4\u8bc1\uff0c\u5982\u679c\u6211\u4eec\u628aPIN\u6362\u6210\u81ea\u5df1\u7684\u624b\u673a\u53f7\uff0c\u7136\u540e\u5728\u767b\u9646\u7684\u65f6\u5019\u5148\u751f\u6210\u968f\u673a\u5b57\u7b26\u4e32\uff0c\u7136\u540e\u77ed\u4fe1\u53d1\u9001\u5230\u7528\u6237\u7684\u624b\u673a\u4e0a\uff0c\u5bf9\u6bd4\u5b57\u7b26\u4e32\u662f\u5426\u4e00\u81f4\uff0c\u8fd9\u6837\u6211\u4eec\u5c31\u5b9e\u73b0\u4e86\u57fa\u4e8e\u77ed\u4fe1\u5f62\u5f0f\u7684\u53cc\u56e0\u5b50\u8ba4\u8bc1\u3002<\/p>\n

                \u8fd9\u90e8\u5206\u4ee3\u7801\u5c31\u7559\u7ed9\u8bfb\u8005\u81ea\u884c\u7ec3\u4e60\u4e86\u3002\u9700\u8981\u6ce8\u610f\u7684\u662f\u4e3a\u4e86\u9632\u6b62\u522b\u4eba\u731c\u6d4b\u5bc6\u7801\u65f6\u6536\u5230\u5927\u91cf\u77ed\u4fe1\uff0c\u8fd9\u91cc\u6700\u597d\u8fde\u624b\u673a\u53f7\u4e5f\u5bf9\u6bd4\u8ba4\u8bc1\u4e0b\u3002<\/p>\n

                \u53c2\u8003\u8d44\u6599<\/h2>\n

                \u8c37\u6b4cgoogle authenticator\u7b97\u6cd5\u5206\u6790
                \nhttps:\/\/garbagecollected.org\/2014\/09\/14\/how-google-authenticator-works\/<\/a>
                \nRSA SecurID\u76f8\u5173\u8d44\u6599
                \n
                http:\/\/www.slideshare.net\/Sandra4211\/rsa-security-authentication-ace-serversecurid<\/a>
                \n\u9e1f\u54e5\u5173\u4e8ePAM\u7684\u8bb2\u8ff0
                \n
                http:\/\/vbird.dic.ksu.edu.tw\/linux_basic\/0410accountmanager_5.php<\/a><\/p>\n

                \u8f6c\u8f7d\u8bf7\u6ce8\u660e\uff1aIPCPU-\u7f51\u7edc\u4e4b\u8def<\/a> » Linux\u4e0b\u4f7f\u7528pam_python\u5b9e\u73b0SSH\u7684\u53cc\u56e0\u5b50\u8ba4\u8bc1\u767b\u5f55<\/a><\/p>","protected":false},"excerpt":{"rendered":"

                Linux\u4e0b\u4f7f\u7528pam_python\u5b9e\u73b0SSH\u7684\u53cc\u56e0\u5b50\u8ba4\u8bc1\u767b\u5f55.md \u5173\u952e\u5b57 Linux PAM Python SSH 2 Two Multi Factor Authentication Login \u53cc\u56e0\u5b50 \u591a\u56e0\u5b50 \u5bc6\u4fdd TOKEN \u4e00\u6b21\u6027\u53e3\u4ee4 PASSPOD OTP yubikey \u8ba4\u8bc1 \u5b89\u5168 \u767b\u5f55 \u5f15\u8a00 Linux\u7cfb\u7edf\u7ba1\u7406\u5458\uff08System Administrator\uff0cSA\uff09\u7ecf\u5e38\u78b0\u5230\u7684\u95ee\u9898\u5c31\u662f\u653e\u5728\u516c\u7f51\u7684\u670d\u52a1\u5668\u7ecf\u5e38\u88ab\u4eba\u731c\u6d4b\u5bc6\u7801\uff0c\u6bcf\u5929\u90fd\u53ef\u4ee5\u4ece\u7cfb\u7edf\u65e5\u5fd7\u91cc\u770b\u5230\u63a2\u6d4b\u5bc6\u7801\u7684\u4fe1\u606f\uff0c\u518d\u52a0\u4e0a\u6700\u8fd1\u5f88\u591a\u5382\u5546\u6cc4\u9732\u4e86\u5305\u542b\u7528\u6237\u5bc6\u7801\u7684\u6570\u636e\u5e93\uff0c\u649e\u5e93\u7684\u884c\u4e3a\u4e5f\u9010\u6b65\u5f00\u59cb\u8f6c\u79fb\u5230SSH\u4e0a\u3002 \u6700\u521dSA\u7684\u9632\u5fa1\u624b\u6bb5\u4e00\u822c\u662f\u9650\u5236IP\u5730\u5740\u3001\u4fee\u6539SSH\u7aef\u53e3\u3001\u90e8\u7f72\u5931\u8d25\u4e00\u5b9a\u6b21\u6570\u5c31\u9501\u5b9a\u6216\u8005\u5c01IP\u7684\u7a0b\u5e8f\u6216\u8005\u811a\u672c\uff0c\u66f4\u6709\u6781\u5ba2\u60f3\u51fa\u4e86\u6572\u95e83\u6b21\u7aef\u53e3\u624d\u5f00\u653e\u7684\u529e\u6cd5\uff0c\u53ef\u8c13\u65e0\u6240\u4e0d\u7528\u5176\u6781\u3002\u4f46\u662f\u8fd9\u4e9b\u529e\u6cd5\u5f88\u591a\u90fd\u4e0d\u662f\u5f88\u65b9\u4fbf\uff0c\u6539\u4e86\u7aef\u53e3\uff0c\u8fde\u63a5\u65f6\u9700\u8981\u6307\u5b9a\u7aef\u53e3\uff1b\u9650\u5236\u4e86IP\u5730\u5740\uff0c\u53d1\u73b0\u5728\u5bb6\u4e0a\u7f51\u5c31\u767b\u5f55\u4e0d\u4e86\u4e86\uff0c\u5c01\u9501\u811a\u672c\u53ef\u80fd\u628a\u81ea\u5df1\u4e5f\u9501\u5b9a\u4e86\u3002 \u5728\u5927\u516c\u53f8\u91cc\u4e00\u822c\u662f\u91c7\u7528\u7684\u201cRSA SecurID\u201d\u65b9\u6848\uff0c\u6216\u8005\u7c7b\u4f3c\u7684\u6280\u672f\u3002\u6211\u4eec\u79f0\u5176\u4e3a\u53cc\u56e0\u5b50\u8ba4\u8bc1\u6216\u8005\u591a\u56e0\u5b50\u8ba4\u8bc1\uff08Two Factor Authentication\uff1bMFA\uff0cMulti Factor Authentication\uff09\uff0c\u5728\u8f93\u5165\u5bc6\u7801\u7684\u540c\u65f6\u9700\u8981\u8f93\u5165\u4e00\u4e2a\u4e00\u6b21\u6027\u53e3\u4ee4\uff08OTP\uff0cOne Time Password\uff09\u3002\u8fd9\u79cd\u65b9\u6848\u4e5f\u6709\u8f6f\u4ef6\u5b9e\u73b0\u548c\u786c\u4ef6\u5b9e\u73b0\uff0c\u8f6f\u4ef6\u4f8b\u5982google authenticator\u3001Symantec Validation and ID Protection (VIP) \uff1b\u786c\u4ef6\u4f8b\u5982 RSA SecurID\u3001\u98de\u5929\u8bda\u4fe1\u7684\u5bc6\u4fdd\u4ea7\u54c1\u3002 \u4f7f\u7528RSA SecurID\u7684\u65b9\u6848\u770b\u8d77\u6765\u867d\u7136\u5f88\u597d\uff0c\u4f46\u662f\u4ed6\u9700\u8981\u72ec\u7acb\u90e8\u7f72RSA Server\uff0c\u9700\u8981\u5360\u7528\u4e00\u53f0\u670d\u52a1\u5668\uff0c\u5e76\u4e14Server\u7aef\u8f6f\u4ef6\u662f\u6536\u8d39\u7684\uff0cRSA SecurID\u5bc6\u4fdd\u4e5f\u662f\u6536\u8d39\u7684\u3002 \u6709\u6ca1\u6709\u514d\u8d39\u7684\u529e\u6cd5\uff1f \u6709\u554a\uff0c\u4eca\u5929\u5c31\u6765\u4ecb\u7ecd\u4e00\u4e2a\u3002 \u5b9e\u73b0\u65b9\u6cd5 \u6700\u7b80\u5355\u7684\u5b9e\u73b0\u7684\u65b9\u5f0f\uff0c\u7528\u6237\u767b\u5f55\u65f6\u9700\u8981\u8f93\u5165\u7528\u6237\u540d+PIN+\u5bc6\u7801\u65b9\u5f0f\u624d\u80fd\u767b\u5f55\u3002 \u8fd9\u91cc\u7684PIN\u662f\u4e00\u4e2a\u5b57\u7b26\u4e32\uff0c\u4f8b\u5982\u201dipcpu.com\u201d\uff0c\u56fa\u5b9a\u6b7b\u7684\uff0c\u4e0d\u4f1a\u53d8\u3002 [root@IPCPU-0 security]# […]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[13],"tags":[17,64,65,15],"_links":{"self":[{"href":"https:\/\/c.ipcpu.com\/wp-json\/wp\/v2\/posts\/552"}],"collection":[{"href":"https:\/\/c.ipcpu.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/c.ipcpu.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/c.ipcpu.com\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/c.ipcpu.com\/wp-json\/wp\/v2\/comments?post=552"}],"version-history":[{"count":0,"href":"https:\/\/c.ipcpu.com\/wp-json\/wp\/v2\/posts\/552\/revisions"}],"wp:attachment":[{"href":"https:\/\/c.ipcpu.com\/wp-json\/wp\/v2\/media?parent=552"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/c.ipcpu.com\/wp-json\/wp\/v2\/categories?post=552"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/c.ipcpu.com\/wp-json\/wp\/v2\/tags?post=552"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}