Re: LDAP Password Security
Michael Ströder <[email protected]> Tue, 7 Apr 2020 21:03:41 +0200
| Newsgroups | gmane.comp.tools.sudo.user |
|---|---|
| Message-ID | <[email protected]> |
On 4/7/20 5:09 PM, LE BOUTER Leo wrote: > TOTP for sudo auth sounds good, as long as the TOTP private key isnt > on each and every server. Yes, the shared secrets have to be stored in a central location and validated there remotely. But if your central 2FA solution takes the OT (one-time) in TOTP serious you cannot use a TOTP value with clusterssh, ansible or whatever. It gets even more complicated if your 2FA solution has multiple instances for HA and your target systems access different instances. Ciao, Michael. ____________________________________________________________ sudo-users mailing list <[email protected]> For list information, options, or to unsubscribe, visit: https://www.sudo.ws/mailman/listinfo/sudo-users