linux增加二次验证

安装google-authenticator

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
#关闭selinux
sed -i 's@SELINUX=enforcing@SELINUX=disabled@' /etc/selinux/config
setenforce 0
#安装阿里epel
curl  http://mirrors.aliyun.com/repo/epel-7.repo >/etc/yum.repos.d/epel.repo
#安装google-authenticator
yum -y install google-authenticator

#修改sshd
sed -i 's#^ChallengeResponseAuthentication no#ChallengeResponseAuthentication yes#' /etc/ssh/sshd_config
#修改PAM模块修改google模块
sed -i '1a auth       required    pam_google_authenticator.so' /etc/pam.d/sshd

#生成二维码
google-authenticator


#重启sshd
systemctl restart sshd