直接配challengeresponseauthentication yes不生效,因openssh不校验验证码,必须同时装对pam模块、用户自生成密钥、/etc/pam.d/sshd位置正确、sshd_config选项开启四者齐备才能触发验证码输入。

直接配 ChallengeResponseAuthentication yes 不生效,因为 OpenSSH 本身不校验验证码——必须装对 PAM 模块、用户自己生成密钥、/etc/pam.d/sshd 放对位置、sshd_config 开对选项,四者全齐才能弹出验证码。
怎么确认 pam_google_authenticator.so 已装好且能加载
很多“配置完了却没提示输验证码”的问题,根源是模块根本没加载成功。
- Debian/Ubuntu:运行
ls /lib/security/pam_google_authenticator.so,不存在就装sudo apt install libpam-google-authenticator - RHEL/CentOS/Rocky:先确认 EPEL 已启用(
sudo dnf install epel-release),再装sudo dnf install google-authenticator,模块路径通常是/usr/lib64/security/pam_google_authenticator.so - 报错
pam_google_authenticator.so: cannot open shared object file?检查是否拼错包名(CentOS 不是libpam-google-authenticator)、SELinux 是否拦截(临时setenforce 0测试)、文件权限是否为0755
为什么用户必须自己运行 google-authenticator,不能 root 代劳
google-authenticator 生成的 ~/.google_authenticator 文件,PAM 会严格校验属主和权限。root 写的文件会被跳过验证,登录时静默失败。
在无 root/sudo 权限的环境(云容器、VPS、隔离主机)中安装并配置 OpenClaw 浏览器工具的 headless Chrome。适用场景:...
- 切到目标用户执行:
su - username,再运行google-authenticator - 关键选项别全按 y:第 1 项(启用 TOTP)必须 y;第 3 项(禁用重复使用码)必须 y;第 4 项(启用速率限制)建议 y
- 生成后立刻检查:
ls -l ~/.google_authenticator应为-rw-------(600),且~目录权限必须是700,否则sshd -d日志只显示authentication failure - 恢复码务必离线保存——手机丢了或文件损坏,这是唯一能登上去的路
/etc/pam.d/sshd 里加哪一行、加在哪
加错位置或控制标志写错,会导致验证被跳过、所有用户强制 MFA、或无限循环失败。
- 必须加在
auth include password-auth这一行的正上方,不能在它下面 - 推荐写法(兼容性好):
auth [success=ok new_authtok_reqd=ok default=bad] pam_google_authenticator.so nullok secret=/home/%u/.google_authenticator - 别用
auth required ...—— 它会让未初始化.google_authenticator的用户彻底无法登录;上线前可先保留nullok,稳定后再删 - 确保
/etc/ssh/sshd_config中有UsePAM yes,否则整段 PAM 配置不生效
为什么 SSH 登录没让输验证码,直接报 Permission denied
这不是配置漏了,而是认证流程被绕过了——常见于公钥登录优先触发,或 AuthenticationMethods 没设对。
- 如果启用了
PubkeyAuthentication yes,默认只走公钥路径,完全不进 PAM 验证环节 - 强制双因子:在
sshd_config中设置AuthenticationMethods publickey,keyboard-interactive(注意逗号后**不能有空格**) - 同时确认
KbdInteractiveAuthentication yes和ChallengeResponseAuthentication yes都已开启 - 改完先别关当前终端!用新终端测试,输错 3 次组合会触发 PAM 锁定,没图形界面解不了
时间不同步是隐形杀手:TOTP 码有效期仅 30 秒,服务器与手机时间差超 90 秒(±3 个窗口)就失效。别调宽窗口,老老实实跑 chronyd 或 systemctl restart systemd-timesyncd 同步时间。










