Is it possible to require both a certificate and a Kerberos password for authentication?



Hi,

I'm currently using OpenSSH on OpenBSD as a remote access service.
Authentication is username & password via kerberos.

My problem is that I don't trust my users to validate the server certificate - I know that ignorant muppets will accept a man in the middle attack without any worries as long as it gives them access to our network (after giving out their password).
So I'd like to refuse access to clients that do not provide a certificate.
But I don't want to rely entirely upon the certificate, because I (a) don't trust the users to look after it and (b) don't want the users to have to remember both a certificate passphrase and their kerberos password.

What I want is to require two different methods of authentication.
Is this possible with OpenSSH?
With any other SSH server?

Thanks

Jim

.



Relevant Pages

  • Re: PGP and S/MIME
    ... instead of delegating the authentication ... > *.p7s signature signed by someone you already put explicit trust in. ... > recommend my clients and customers to separate the root certificate ...
    (sci.crypt)
  • Re: IPSec & Kerberos
    ... There are three authentication methods for ipsec - kerberos, ... certificate is not required for authentication. ...
    (microsoft.public.win2000.networking)
  • Re: Is it possible to require both a certificate and a Kerberos password for authentication?
    ... Authentication is username & password via kerberos. ... My problem is that I don't trust my users to validate the server ... So I'd like to refuse access to clients that do not provide a certificate.. ... What I want is to require two different methods of authentication. ...
    (comp.security.ssh)
  • Re: IPSec client from behind a NAT
    ... > What are you using for authentication? ... Kerberos, certificate, pre-shared ... >> The policy is there, ...
    (microsoft.public.windows.server.networking)
  • Re: Need help configuring Wireless Connection profile
    ... Windows authentication for all users,4129,LRG\ryanv,4149,Wireless ... Vaillancourt,4155,1,4154,Use Windows authentication for all ... SMALL BUSINESS SERVER: ... STEP #1 Install Certificate Services ...
    (microsoft.public.windowsxp.general)