Re: freeradius using pam_oath doesn't return otp challenge

2013-06-17 Thread Martin Kraus
On Sun, Jun 16, 2013 at 01:15:06PM -0400, Alan DeKok wrote: Martin Kraus wrote: Yes I did that before posting. However the only thing that would allow something like a standard password plus otp is using google authenticator with the forward password option through rlm_pam again. I was

Re: freeradius using pam_oath doesn't return otp challenge

2013-06-17 Thread Alan DeKok
Martin Kraus wrote: Ok. However I still don't see how I would go about setting it up. I thought I can call only a single authentication module in freeradius. When one succeeds the authentication section terminates. There are many modules in FreeRADIUS which do challenge-response. They all

Re: freeradius using pam_oath doesn't return otp challenge

2013-06-16 Thread Martin Kraus
On Sun, Jun 16, 2013 at 10:46:51AM +0100, Phil Mayers wrote: There are various ways of doing OTP with FreeRADIUS. Read the docs/wiki and sample configs, and search the archives of the list. Yes I did that before posting. However the only thing that would allow something like a standard password

Re: freeradius using pam_oath doesn't return otp challenge

2013-06-16 Thread Alan DeKok
Martin Kraus wrote: Yes I did that before posting. However the only thing that would allow something like a standard password plus otp is using google authenticator with the forward password option through rlm_pam again. I was looking for other options just to look at it from different angle

freeradius using pam_oath doesn't return otp challenge

2013-06-15 Thread Martin Kraus
Hi. I'd like to have freeradius authenticate users using their password (for simplicity I'm using /etc/shadow now) and TOTP through liboath. I was hoping to use freeradius to centralize this. PAM looked like the easiest way. I'm using freeradius 2.1.12 from debian wheezy. PAM confiuration is