[GH-ISSUE #249] MFA TOTP change Google by another #66

Closed
opened 2026-05-07 00:18:19 +02:00 by BreizhHardware · 3 comments

Originally created by @FlochonR on GitHub (Sep 27, 2021).
Original GitHub issue: https://github.com/ovh/the-bastion/issues/249

Hello,

I enabled the MFA TOTP to connect to Bastion and Vm's behind.
I changed, in the configuration file /etc/pam.d/sshd, the Google PAM authenticator by Duo PAM but when a user enable the MFA with "selfMFASetupTOTP" I have still the QR code from Google PAM authenticator.
Is it possible to disable that ?
(The authentication with Duo is ok with the modification in /etc/pam.d/sshd)

Thanks in advance for your help,
FlochonR

Originally created by @FlochonR on GitHub (Sep 27, 2021). Original GitHub issue: https://github.com/ovh/the-bastion/issues/249 Hello, I enabled the MFA TOTP to connect to Bastion and Vm's behind. I changed, in the configuration file /etc/pam.d/sshd, the Google PAM authenticator by Duo PAM but when a user enable the MFA with "selfMFASetupTOTP" I have still the QR code from Google PAM authenticator. Is it possible to disable that ? (The authentication with Duo is ok with the modification in /etc/pam.d/sshd) Thanks in advance for your help, FlochonR
Author
Owner

@speed47 commented on GitHub (Sep 28, 2021):

Hello FlochonR,

Sure, I never tried with the Duo's PAM integration, but it should work flawlessly. I'll just make the setup command configurable, so that one can customize it. As you said, in the case of Duo, it seems there is no per-user local setup to do, so /bin/true will be a perfect setup command :)

<!-- gh-comment-id:928918028 --> @speed47 commented on GitHub (Sep 28, 2021): Hello FlochonR, Sure, I never tried with the Duo's PAM integration, but it should work flawlessly. I'll just make the setup command configurable, so that one can customize it. As you said, in the case of Duo, it seems there is no per-user local setup to do, so /bin/true will be a perfect setup command :)
Author
Owner

@FlochonR commented on GitHub (Sep 29, 2021):

Hello speed47 !

Thank you ! :)

<!-- gh-comment-id:929895775 --> @FlochonR commented on GitHub (Sep 29, 2021): Hello speed47 ! Thank you ! :)
Author
Owner

@speed47 commented on GitHub (Nov 3, 2021):

Merged #255

<!-- gh-comment-id:959317548 --> @speed47 commented on GitHub (Nov 3, 2021): Merged #255
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/the-bastion#66
No description provided.