Amazon Linux 2中bastion用户pam_google_authenticator权限拒绝问题求助
解决Amazon Linux 2中bastion用户PAM谷歌认证权限拒绝问题
核心修复步骤
初始化用户的谷歌认证器
切换到bastion用户完成认证配置:su - bastion google-authenticator按提示选择
y启用时间同步令牌、生成应急码,确保成功生成~/.google_authenticator文件。修复认证文件权限
确保认证文件仅对bastion用户可读:chmod 600 /home/bastion/.google_authenticator chown bastion:bastion /home/bastion/.google_authenticator验证PAM与SSHD配置
- 检查
/etc/pam.d/sshd是否包含正确的认证规则:
确保该行未被注释,且无其他冲突的PAM规则。auth required pam_google_authenticator.so - 确认
/etc/ssh/sshd_config配置正确:ChallengeResponseAuthentication yes UsePAM yes PasswordAuthentication no # 可选,若仅采用密钥+二次认证模式 - 重启sshd服务加载配置:
systemctl restart sshd
- 检查
处理SELinux限制
Amazon Linux 2默认启用SELinux,可能阻止PAM模块访问用户认证文件:- 查看是否存在SELinux拒绝日志:
ausearch -m avc -ts recent - 授权PAM访问认证文件:
chcon -t auth_home_t /home/bastion/.google_authenticator setsebool -P authlogin_yubikey on
- 查看是否存在SELinux拒绝日志:
测试验证
从客户端重新SSH登录bastion用户,完成密钥验证后输入谷歌认证器的6位令牌,确认登录成功。
内容的提问来源于stack exchange,提问作者YasiuMaster
相关产品推荐
相关产品推荐

