google / google-authenticator-libpam

Apache License 2.0
1.76k stars 281 forks source link

Allow disabling OTP for selected users #143

Closed Keruspe closed 4 years ago

Keruspe commented 4 years ago

This allows enforcing OTP for "privileged" users while disabling it for "guest" users

googlebot commented 4 years ago

Thanks for your pull request. It looks like this may be your first contribution to a Google open source project (if not, look below for help). Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

:memo: Please visit https://cla.developers.google.com/ to sign.

Once you've signed (or fixed any issues), please reply here with @googlebot I signed it! and we'll verify it.


What to do if you already signed the CLA

Individual signers
Corporate signers

ℹ️ Googlers: Go here for more info.

Keruspe commented 4 years ago

@googlebot I signed it!

googlebot commented 4 years ago

CLAs look good, thanks!

ℹ️ Googlers: Go here for more info.

ThomasHabets commented 4 years ago

Does this not belong in the PAM config?

Something like:

auth [success=1,default=ok] pam_listfile.so item=user sense=deny file=/etc/otp_disabled 

That way users can't "opt out" of OTP. And if they can opt out, then this option is the same as having nullok in your config, no?

Keruspe commented 4 years ago

Hmm, it seems I misunderstood how nullok worked here, it's sufficient for what I want, thanks!