Skip to content
This repository was archived by the owner on Dec 11, 2020. It is now read-only.

Conversation

@dpelivan
Copy link
Contributor

@dpelivan dpelivan commented Apr 7, 2019

Integrate ocserv with Microsoft Active Directory and Google Authenticator

Integrate ocserv with Microsoft Active Directory and Google Authenticator
This Recipe provides step by step instructions on how to install, configure,
and test Microsoft AD Authentication for Openconnect Server. This recipe focuses on
generic installation instructions, from packages available on Openconnect server.
No precompiled binary packages will be used, therefore this recipe was tested
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not sure what this sentence means by "No precompiled binary packages will be used". Does it mean you didn't use the epel7 ocserv package?

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

auth [success=1 default=ignore] pam_sss.so use_first_pass
auth requisite pam_deny.so
auth required pam_permit.so
auth required pam_google_authenticator.so
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I suppose that you added this line, what about using a diff or explicitly saying to add this line?

fi
```
3. Configure PAM to enable google-authenticator for password authentication.
You need to modify ```/etc/pam.d/ocserv```:
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

wouldn't you also need to change something in ocserv.conf to instruct it to use pam for user authentication?


### Scope

This Recipe provides step by step instructions on how to install, configure,
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe this sentence should repeat that this is for both Microsoft AD and google authenticator OATH.

@nmav nmav changed the title Create ocserv-authentication-ad-googleauth.md WIP: Create ocserv-authentication-ad-googleauth.md Jul 14, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants