Re: Is it possible to require both a certificate and a Kerberos password for authentication?



On Jan 16, 5:41 am, "Jim Talbut" <<private>> wrote:
Hi,

I'm currently using OpenSSH on OpenBSD as a remote access service.
Authentication is username & password via kerberos.

My problem is that I don't trust my users to validate the server
certificate - I know that ignorant muppets will accept a man in the middle
attack without any worries as long as it gives them access to our network
(after giving out their password).
So I'd like to refuse access to clients that do not provide a certificate..
But I don't want to rely entirely upon the certificate, because I (a) don't
trust the users to look after it and (b) don't want the users to have to
remember both a certificate passphrase and their kerberos password.

What I want is to require two different methods of authentication.
Is this possible with OpenSSH?
With any other SSH server?

Thanks

Jim

Why not run the primary authentication technique on one port, and a
secondary technique on another port with separate restrictions in the
sshd_config to manage it as desired for each port?
.



Relevant Pages

  • Re: PGP and S/MIME
    ... instead of delegating the authentication ... > *.p7s signature signed by someone you already put explicit trust in. ... > recommend my clients and customers to separate the root certificate ...
    (sci.crypt)
  • Re: IPSec & Kerberos
    ... There are three authentication methods for ipsec - kerberos, ... certificate is not required for authentication. ...
    (microsoft.public.win2000.networking)
  • Is it possible to require both a certificate and a Kerberos password for authentication?
    ... My problem is that I don't trust my users to validate the server certificate - I know that ignorant muppets will accept a man in the middle attack without any worries as long as it gives them access to our network. ... But I don't want to rely entirely upon the certificate, because I don't trust the users to look after it and don't want the users to have to remember both a certificate passphrase and their kerberos password. ... What I want is to require two different methods of authentication. ...
    (comp.security.ssh)
  • Re: IPSec client from behind a NAT
    ... > What are you using for authentication? ... Kerberos, certificate, pre-shared ... >> The policy is there, ...
    (microsoft.public.windows.server.networking)
  • Re: Kerberos machine authentication - apparent authentication fail
    ... until a user logon event. ... the Netdiag utility will show the Kerberos error in this scenario ... On these machines I ... me a plausible starting point to solve my Kerberos authentication problem. ...
    (microsoft.public.windows.server.security)