SSH多因子验证必须同时满足ChallengeResponseAuthentication yes、UsePAM yes、用户本人运行google-authenticator生成密钥三项条件,缺一不可;否则登录静默跳过验证码,仅执行密码或密钥验证。

SSH多因素验证不会自动生效,必须同时满足三项硬性条件:ChallengeResponseAuthentication yes、UsePAM yes、用户本人运行google-authenticator生成密钥文件,缺一不可;否则登录时静默跳过验证码,只走密码或密钥流程。
为什么改完配置还是不弹验证码?
最常见原因是 OpenSSH 根本没启用交互式二次验证入口。即使 PAM 模块装了、/etc/pam.d/sshd写了规则、手机 App 也绑好了,只要 ChallengeResponseAuthentication 没设为 yes,就永远不会触发 OTP 输入环节。
-
ChallengeResponseAuthentication yes必须写成yes,写成on或漏掉都会失效 -
UsePAM yes必须存在且未被注释,否则 PAM 规则压根不加载 - 如果同时启用了公钥登录(
PubkeyAuthentication yes),还需加一行:AuthenticationMethods publickey,keyboard-interactive,否则密钥认证成功后直接放行,跳过后续验证 - 改完配置必须执行
sudo systemctl restart sshd——reload不会重载ChallengeResponseAuthentication状态
用户级密钥生成最容易踩哪些坑?
root 不能代劳,也不能复制 ~/.google_authenticator 文件过去——PAM 会因权限或属主不符直接忽略该用户验证。
Linux 性能分析与调优专家,覆盖 CPU、内存、磁盘 I/O、网络、内核参数、编译优化、容器/K8s。适用场景:系统卡顿/高负载、内存不足/OOM/Swap 高、CPU 异常/iowait 高。
- 必须切换到目标用户再执行:
su - username→google-authenticator - 关键选项建议全选
y:启用 TOTP、禁用重复码、启用速率限制(30 秒最多 3 次)、保存配置、生成恢复码 -
ls -l ~/.google_authenticator必须显示-rw-------(600 权限),否则日志里只有open() failed: Permission denied - 恢复码务必离线存好——手机丢了、文件损坏了,这是唯一能登进去的路
/etc/pam.d/sshd 的 auth 行怎么写才对?
顺序和参数错一个,就可能变成“所有人强制 MFA”或“所有人跳过 MFA”。Debian/Ubuntu 和 RHEL 系统路径、参数习惯不同,不能照搬。
- Debian/Ubuntu 推荐写在文件顶部:
auth [success=ok default=die] pam_google_authenticator.so nullok secret=/home/${USER}/.google_authenticator - RHEL/CentOS 更稳妥写法:
auth [success=ok new_authtok_reqd=ok default=bad] pam_google_authenticator.so nullok secret=/home/%u/.google_authenticator -
nullok表示未初始化.google_authenticator的用户可跳过这步(灰度上线时有用);上线后建议去掉,强制所有用户完成绑定 - 绝对不要用
required—— 它会让未初始化的用户直接认证失败,而不是跳过
PAM 模块根本没装上怎么办?
很多故障根源是 pam_google_authenticator.so 根本没装对,或路径不对,或被 SELinux/权限拦截。
- Debian/Ubuntu:检查
ls /lib/security/pam_google_authenticator.so是否存在;若无,运行sudo apt install libpam-google-authenticator - RHEL/CentOS/Rocky 8+:先启用 EPEL(
sudo dnf install epel-release),再装sudo dnf install google-authenticator;验证文件在/usr/lib64/security/pam_google_authenticator.so - 常见错误:
pam_google_authenticator.so: cannot open shared object file→ 检查包名是否拼错(CentOS 不是libpam-google-authenticator)、是否漏装 EPEL、是否 SELinux 阻断(临时setenforce 0测试)
真正容易被忽略的是时间同步问题:TOTP 基于服务器与手机的时间一致性,偏差超过 30 秒就会验证失败。别只盯着配置,chronyd 或 systemd-timesyncd 必须跑稳,且 timedatectl status 显示 “System clock synchronized: yes”。

















