You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Amazon Linux 2中bastion用户pam_google_authenticator权限拒绝问题求助

解决Amazon Linux 2中bastion用户PAM谷歌认证权限拒绝问题

核心修复步骤

  • 初始化用户的谷歌认证器
    切换到bastion用户完成认证配置:

    su - bastion
    google-authenticator
    

    按提示选择y启用时间同步令牌、生成应急码,确保成功生成~/.google_authenticator文件。

  • 修复认证文件权限
    确保认证文件仅对bastion用户可读:

    chmod 600 /home/bastion/.google_authenticator
    chown bastion:bastion /home/bastion/.google_authenticator
    
  • 验证PAM与SSHD配置

    1. 检查/etc/pam.d/sshd是否包含正确的认证规则:
      auth       required     pam_google_authenticator.so
      
      确保该行未被注释,且无其他冲突的PAM规则。
    2. 确认/etc/ssh/sshd_config配置正确:
      ChallengeResponseAuthentication yes
      UsePAM yes
      PasswordAuthentication no  # 可选,若仅采用密钥+二次认证模式
      
    3. 重启sshd服务加载配置:
      systemctl restart sshd
      
  • 处理SELinux限制
    Amazon Linux 2默认启用SELinux,可能阻止PAM模块访问用户认证文件:

    1. 查看是否存在SELinux拒绝日志:
      ausearch -m avc -ts recent
      
    2. 授权PAM访问认证文件:
      chcon -t auth_home_t /home/bastion/.google_authenticator
      setsebool -P authlogin_yubikey on
      

测试验证

从客户端重新SSH登录bastion用户,完成密钥验证后输入谷歌认证器的6位令牌,确认登录成功。

内容的提问来源于stack exchange,提问作者YasiuMaster

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 17:07:13