On ma, 22 helmi 2021, Mariusz Stysiak via FreeIPA-users wrote:
Alexander,
Thank you for your prompt and informative answer, it cleared my last
doubts. Two other questions come to my mind:
1. Is it possible to enforce two-step auth for AD users (first step
being AD authentication, second OTP used by freeipa)?

Not on Kerberos level.

2. Except kerberos-based MFA are there any other ways to achieve this
goal (AD users being able to log on Linux machines with 2FA)? Things
like PBIS use something, I guess? Couldn't something similar be used
here?

SSH has means to require multiple authentication methods at the same
time. This can be used to 'emulate' such multi-factor access. This was
asked several times in past, archives are useful too. ;)

See, for example, 
https://lists.fedorahosted.org/archives/list/[email protected]/thread/KOKOBFAHJTTI744243PED5RAD3EXN6IL/


--
/ Alexander Bokovoy
Sr. Principal Software Engineer
Security / Identity Management Engineering
Red Hat Limited, Finland
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam on the list, report it: 
https://pagure.io/fedora-infrastructure

Reply via email to