Solved

Block password authetication on specific  user on Linux

Posted on 2013-05-17
3
585 Views
Last Modified: 2013-05-17
Hi,
I need to block password authentication for only specific users on Linux server, and leave key
option only. User can't be blocked to use password for other protocols like ftp

All changes should be done in sshd_config file
For UNIX I use following but it block all users on Linux

PasswordAuthDenyUsers user1 user2 user3
ChallRespAuthDenyUsers  [pam] user1 user2 user3

Thanks
0
Comment
Question by:IKeystone
3 Comments
 
LVL 27

Expert Comment

by:skullnobrains
ID: 39175602
create a group for your user in sshd_conf and deny whatever types of authentication you need in that group
0
 

Author Comment

by:IKeystone
ID: 39175815
Can you send me an example ?
0
 
LVL 29

Accepted Solution

by:
serialband earned 500 total points
ID: 39176279
I believe the following should work on your linux system.

Create a group named keyonly and put your users in it.

Then add the following to /etc/ssh/sshd_config

Match Group keyonly
      PasswordAuthentication no
      ChallengeResponseAuthentication yes



You could also just match individual users.
Match User User_Name
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I. Introduction There's an interesting discussion going on now in an Experts Exchange Group — Attachments with no extension (http://www.experts-exchange.com/discussions/210281/Attachments-with-no-extension.html). This reminded me of questions tha…
Every server (virtual or physical) needs a console: and the console can be provided through hardware directly connected, software for remote connections, local connections, through a KVM, etc. This document explains the different types of consol…
Learn several ways to interact with files and get file information from the bash shell. ls lists the contents of a directory: Using the -a flag displays hidden files: Using the -l flag formats the output in a long list: The file command gives us mor…
In a previous video, we went over how to export a DynamoDB table into Amazon S3.  In this video, we show how to load the export from S3 into a DynamoDB table.

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question