Tutorial testando em CentOS 7
Leia o artigo completamente antes de seguir, nesse artigo possui passos que podem indisponibilizar o SSH se mal executado.
1. Repositório
2. Instalação & Configuração do Google Authenticator
3. Repositório
sudo yum install https://dl.fedoraproject.org/pub/epel/epel-release-latest-7.noarch.rpm4.Instalação & Configuração do Google Authenticator
2.1. Ajuste o horário de sua máquina, isso é MUITO IMPORTANTE
sudo timedatectl set-timezone America/Sao_Paulo2.2. Instalação do Google Authenticator
sudo yum install google-authenticator -y 2.2. Configuração
Execute o comando abaixo e use a sequencia abaixo de respostas para configurar o serviço.
google-authenticator Do you want authentication tokens to be time-based (y/n) y
Do you want me to update your “/home/sammy/.google_authenticator” file (y/n) y
Output
Do you want to disallow multiple uses of the same authentication
token? This restricts you to one login about every 30s, but it increases
your chances to notice or even prevent man-in-the-middle attacks (y/n) y
Output
By default, tokens are good for 30 seconds. In order to compensate for
possible time-skew between the client and the server, we allow an extra
token before and after the current time. If you experience problems with
poor time synchronization, you can increase the window from its default
size of +-1min (window size of 3) to about +-4min (window size of 17 acceptable tokens).
Do you want to do so? (y/n) n
Output
If the computer that you are logging into isn’t hardened against brute-force
login attempts, you can enable rate-limiting for the authentication module.
By default, this limits attackers to no more than 3 login attempts every 30s.
Do you want to enable rate-limiting (y/n) y
3. Configurando de validação
3.1 Ajuste do arquivo pam
sudo nano /etc/pam.d/sshdAdicione a linha no final do arquivo:
auth required pam_google_authenticator.so 3.2. Ajuste no sshd_config
Localize a opção #ChallengeResponseAuthentication no no arquivo sshd_config
sudo nano /etc/ssh/sshd_config Agora remova o comentário a função e no lugar de no mude para yes.
Feito isso, reinicie o serviço sshd usando o comando
sudo systemctl restart sshd.service Pronto! A função deve está habilitada agora, mas para ter certeza, duplique o terminal para fazer uma nova conexão no mesmo servidor SEM FECHAR O ATUAL.
Se tudo deu certo, após a requisição de senha será necessário informar o código de 6 dígitos do Google Authenticator.