You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu 20.04中oathtool生成的TOTP 6位验证码无法通过pam_oath.so完成SSH双因素登录的问题求助

Ubuntu 20.04中oathtool生成的TOTP 6位验证码无法通过pam_oath.so完成SSH双因素登录的问题求助

我正在尝试给Ubuntu服务器的SSH登录配置TOTP双因素认证,目前遇到了一个棘手的问题——用oathtool生成的6位验证码始终无法通过pam_oath.so的验证,导致SSH登录被拒绝,想请教各位大佬哪里出了问题。

以下是我的配置和操作步骤:

1. OATH用户文件配置

我的/etc/users.oath文件内容如下:

HOTP/T30/6 testuser – 8436e373cbdabce46a5d8d019c463a

(注:这个密钥是我反复生成用于测试的,而且测试环境是离线的,所以可以安全公开)

文件权限和归属已经设置为符合要求的0600,且归root所有:

# ls /etc/users.oath -l
-rw------- 1 root root 55 Jan 29 15:39 /etc/users.oath

2. PAM配置

我在/etc/pam.d/sshd的最后一行添加了PAM oath模块的配置:

auth required pam_oath.so usersfile=/etc/users.oath window=30 digits=6

3. SSH服务配置

/etc/ssh/sshd_config中已经开启了必要的选项:

UsePAM yes
ChallengeResponseAuthentication yes

测试用户testuser已经通过adduser和passwd命令创建并设置了密码。

4. 生成验证码的操作

我先用oathtool把十六进制密钥转换为Base32格式:

# oathtool --verbose --totp 8436e373cbdabce46a5d8d019c463a
Hex secret: 8436e373cbdabce46a5d8d019c463a
Base32 secret: QQ3OG46L3K6OI2S5RUAZYRR2
Digits: 6
Window size: 0
Step size (seconds): 30
Start time: 1970-01-01 00:00:00 UTC (0)
Current time: 2024-01-29 13:51:57 UTC (1706536317)
Counter: 0x363FD3F (56884543)
261816

之后用这个Base32密钥生成实时的6位TOTP验证码:

oathtool --base32 --totp QQ3OG46L3K6OI2S5RUAZYRR2 -d 6

我会快速把生成的验证码输入到SSH客户端的双因素验证提示中,但每次都收到拒绝:

Using username "testuser".
Keyboard-interactive authentication prompts from server:
| Password:
| One-time password (OATH) for `testuser':
End of keyboard-interactive prompts from server
Access denied

Keyboard-interactive authentication prompts from server:
| Password:
| One-time password (OATH) for `testuser':
End of keyboard-interactive prompts from server
Access denied

5. 日志信息

查看/var/log/auth.log,日志只重复显示认证失败:

pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=172.1.2.3  user=testuser
error: PAM: Authentication failure for testuser from 172.1.2.3

6. 环境确认

我已经安装了libpam-oath包,对应的模块文件也存在:

# ls /lib/security/pam_oath.so -l
-rw-r--r-- 1 root root 18488 Feb  9  2019 /lib/security/pam_oath.so

我特意在同一台机器上测试,没有使用手机端的Google Authenticator或Authy等工具,就是为了排除时间同步的问题,但问题依然存在。感觉oathtool和pam_oath.so模块之间好像存在不兼容的情况?

想请教大家,我哪里配置出错了?怎么才能在Ubuntu 20.04上成功配置基于TOTP的SSH双因素认证?

备注:内容来源于stack exchange,提问作者Stefan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.20 10:35:33