google / google-authenticator-libpam

Apache License 2.0
1.8k stars 286 forks source link

Verify that the user entered just the OTP #121

Closed trimentor closed 5 years ago

trimentor commented 5 years ago

When the option forward_pass isn't set in the PAM rule, but option use_first_pass is and the user enters a bogus password in combination with a valid one-time password then the authenticaton must fail, because we don't forward the password to another PAM module.

googlebot commented 5 years ago

Thanks for your pull request. It looks like this may be your first contribution to a Google open source project (if not, look below for help). Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

:memo: Please visit https://cla.developers.google.com/ to sign.

Once you've signed (or fixed any issues), please reply here (e.g. I signed it!) and we'll verify it.


What to do if you already signed the CLA

Individual signers
Corporate signers