-
Notifications
You must be signed in to change notification settings - Fork 30
WIP: Create ocserv-authentication-ad-googleauth.md #8
base: master
Are you sure you want to change the base?
Conversation
Integrate ocserv with Microsoft Active Directory and Google Authenticator
| This Recipe provides step by step instructions on how to install, configure, | ||
| and test Microsoft AD Authentication for Openconnect Server. This recipe focuses on | ||
| generic installation instructions, from packages available on Openconnect server. | ||
| No precompiled binary packages will be used, therefore this recipe was tested |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Not sure what this sentence means by "No precompiled binary packages will be used". Does it mean you didn't use the epel7 ocserv package?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| auth [success=1 default=ignore] pam_sss.so use_first_pass | ||
| auth requisite pam_deny.so | ||
| auth required pam_permit.so | ||
| auth required pam_google_authenticator.so |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I suppose that you added this line, what about using a diff or explicitly saying to add this line?
| fi | ||
| ``` | ||
| 3. Configure PAM to enable google-authenticator for password authentication. | ||
| You need to modify ```/etc/pam.d/ocserv```: |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
wouldn't you also need to change something in ocserv.conf to instruct it to use pam for user authentication?
|
|
||
| ### Scope | ||
|
|
||
| This Recipe provides step by step instructions on how to install, configure, |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Maybe this sentence should repeat that this is for both Microsoft AD and google authenticator OATH.
Integrate ocserv with Microsoft Active Directory and Google Authenticator