How to stack a Unix authentication followed by SecurID prompt with the RSA Authentication Agent for PAM for SSH and Telnet logins.
Originally Published: 2013-03-28
Last Modified: 2023-10-06
Article Number
Applies To
RSA Product/Service Type: Authentication Agent for PAM
RSA Version/Condition: 7, 6, 5
Platform: Red Hat Enterprise Linux
O/S Version: 32-bit and 64-bit RHEL 6, 5, 4
Issue
Resolution
Make a backup of the configuration file you are editing before making modifications to any PAM configuration files.
On Linux, the location of the PAM configuration files is /etc/pam.d.
The following sshd will prompt users who ssh to a Unix machine first for a password, then prompt for a two factor SecurID authentication:
#%PAM-1.0 auth required pam_stack.so service=system-auth auth required pam_securid.so auth required pam_nologin.so account required pam_stack.so service=system-auth password required pam_stack.so service=system-auth session required pam_stack.so service=system-auth session required pam_loginuid.so
If you are not receiving a passcode prompt for the second authentication prompt, check the /etc/ssh/sshd_config file and ensure the ChallengeResponseAuthentication parameter is set to yes, as in the example below:
ChallengeResponseAuthentication yes
If it is not set to yes, make the change and then restart ssh as root:
service sshd restart
The following remote file will prompt users who telnet to a Unix machine first for a password, then prompt for a two factor SecurID authentication:
#%PAM-1.0 auth required pam_securetty.so auth required pam_stack.so service=system-auth auth required pam_nologin.so auth required pam_securid.so account required pam_stack.so service=system-auth password required pam_stack.so service=system-auth # pam_selinux.so close should be the first session rule session required pam_selinux.so close session required pam_stack.so service=system-auth session required pam_loginuid.so session optional pam_console.so # pam_selinux.so open should be the last session rule session required pam_selinux.so open
Notes
Each protocol (sshd, rlogin, telnet (also known as "remote"), etc.) has its' own unique file name. This differs from Solaris, which uses a single file /etc/pam.conf, for PAM configuration directives.
Related Articles
Configuring RSA Authentication Agent 7.1 for PAM on SELinux 436Number of Views RSA Authentication Manager Web Tier installation fails with the following error: The directory already exists! 53Number of Views How to Configure Linux Password Authentication with RSA SecurID Authentication Agent for PAM 1.68KNumber of Views Best practices for installing, configuring and using the RSA MFA Agent 9.x for PAM/Unix 10Number of Views RSA Announces the Release of RSA MFA Agent 9.1 for UNIX 20Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?