One Time Password" with vsftpd

255 views
Skip to first unread message

cesar

unread,
May 7, 2007, 4:38:28 PM5/7/07
to Linux Users Group
Do you know any well-documented "One Time Password" package that
would work with vsftpd?

Any help would be helpful. Thanks

Jeremiah Bess

unread,
May 7, 2007, 7:20:09 PM5/7/07
to linuxus...@googlegroups.com


What about PKI keys. I use that for my SSH connections, never need a password, only my private key.

--
Jeremiah E. Bess
Network Ninja, Penguin Geek, Father of three

Jackley Cesar

unread,
May 7, 2007, 9:19:55 PM5/7/07
to linuxus...@googlegroups.com
I just need a way to provide temporary access to clients to
upload/download files.I don't think that would do it.


--
Jackley Cesar
Email : jackle...@gmail.com
IM : joc...@hotmail.com

Jeremiah Bess

unread,
May 7, 2007, 11:22:52 PM5/7/07
to linuxus...@googlegroups.com


On 5/7/07, Jackley Cesar <jackle...@gmail.com> wrote:

I just need a way to provide temporary access to clients to
upload/download files.I don't think that would do it.

Sorry, mis-understood.

Sasquatch Brohan

unread,
May 8, 2007, 6:45:14 AM5/8/07
to linuxus...@googlegroups.com
OPIE is good. (one time passwords in everything)

Jackley Cesar

unread,
May 8, 2007, 8:10:46 AM5/8/07
to linuxus...@googlegroups.com
I tested both OPIE, and OTPW but it's a pain to get them to work with
vsftpd. They work if I type "login" at the shell prompt but they don't
when I try to use them with PAM + vsftpd. They are poorly documented.

http://en.wikipedia.org/wiki/One_time_password

http://www.cl.cam.ac.uk/~mgk25/otpw.html
http://www.inner.net/opie


On 5/8/07, Sasquatch Brohan <sasqua...@gmail.com> wrote:
> OPIE is good. (one time passwords in everything)
>
> >
>

Nick Owen

unread,
May 9, 2007, 10:03:25 AM5/9/07
to Linux Users Group
On May 8, 8:10 am, "Jackley Cesar" <jackley.ce...@gmail.com> wrote:
> I tested both OPIE, and OTPW but it's a pain to get them to work with
> vsftpd. They work if I type "login" at the shell prompt but they don't
> when I try to use them with PAM + vsftpd. They are poorly documented.
>
We have set up and documented a number of services for one-time
passwords using PAM with the WiKID two-factor auth server. Just
configure vsftp to use PAM and configure your PAM service to talk to
the OTP server. Usually, this is done via radius or ldap. Here are
some docs:

http://www.wikidsystems.net/howtos/pam_ldap_twofactor/ - PAM Ldap +
OTP
http://www.wikidsystems.net/howtos/tacacs_twofactorauthentication/ -
TACAS+ + OTP
http://www.wikidsystems.com/documentation/howtos/pamradius - PAM
radius + OTP.

The last one is for the commercial version - the open source version
does not support radius. When I get a chance, I will specifically
look at vsftp.

hth,

nick

--
Nick Owen
WiKID Systems, Inc.
404.962.8983
http://www.wikidsystems.com
Commercial/Open Source Two-Factor Authentication
https://www.linkedin.com/in/nickowen

Reply all
Reply to author
Forward
0 new messages