Re: LDAP Password Security

Michael Ströder <[email protected]> Tue, 7 Apr 2020 21:03:41 +0200
Newsgroups gmane.comp.tools.sudo.user
Message-ID <[email protected]>
On 4/7/20 5:09 PM, LE BOUTER Leo wrote:
> TOTP for sudo auth sounds good, as long as the TOTP private key isnt
> on each and every server.
Yes, the shared secrets have to be stored in a central location and
validated there remotely.

But if your central 2FA solution takes the OT (one-time) in TOTP serious
you cannot use a TOTP value with clusterssh, ansible or whatever. It
gets even more complicated if your 2FA solution has multiple instances
for HA and your target systems access different instances.

Ciao, Michael.
____________________________________________________________
sudo-users mailing list <[email protected]>
For list information, options, or to unsubscribe, visit:
https://www.sudo.ws/mailman/listinfo/sudo-users