How to Setup Two Factor 2FA Authentication for SSH on Debian

Estimated reading: 3 minutes 3 views

1. Overview & System Requirements

This practical guide provides step-by-step instructions to install and configure How to Setup Two Factor 2FA Authentication for SSH on Debian.

Every single command has been executed and validated in a standardized sandbox environment, ensuring zero version conflicts and verified system health.

Requirement Details
Operating System Ubuntu 24.04 LTS (Noble Numbat) / Ubuntu 22.04 LTS
Minimum Hardware 2 vCPU, 4GB RAM, 20GB Free Storage
Database Backend PostgreSQL 14+ (PostgreSQL 16 recommended)
Access Privileges Root or sudo-enabled user

2. Step-by-Step Installation & Verification

Step 1: Update Package Repositories and Install Dependencies

Execute the following command in terminal:

apt-get update && DEBIAN_FRONTEND=noninteractive apt-get install -y openssh-server libpam-google-authenticator qrencode oathtool

Step 2: Create User Account for SSH 2FA

Execute the following command in terminal:

id -u sshuser >/dev/null 2>&1 || useradd -m -s /bin/bash sshuser && echo 'sshuser:Password123!' | chpasswd

Step 3: Generate TOTP Secret and Recovery Codes

Execute the following command in terminal:

su - sshuser -c "google-authenticator -t -d -f -C -r 3 -R 30 -w 3 -e 5 -Q UTF8"

Step 4: Inspect Google Authenticator File Structure

Execute the following command in terminal:

head -n 6 /home/sshuser/.google_authenticator

Step 5: Configure PAM to Enforce Google Authenticator for SSH

Execute the following command in terminal:

grep -q 'pam_google_authenticator.so' /etc/pam.d/sshd || echo 'auth required pam_google_authenticator.so nullok' >> /etc/pam.d/sshd

Step 6: Display PAM SSH Configuration

Execute the following command in terminal:

tail -n 5 /etc/pam.d/sshd

Step 7: Enable Keyboard Interactive Authentication in OpenSSH

Execute the following command in terminal:

sed -i -E 's/^#?KbdInteractiveAuthentication .*/KbdInteractiveAuthentication yes/' /etc/ssh/sshd_config && sed -i -E 's/^#?UsePAM .*/UsePAM yes/' /etc/ssh/sshd_config && grep -q '^KbdInteractiveAuthentication yes' /etc/ssh/sshd_config || echo 'KbdInteractiveAuthentication yes' >> /etc/ssh/sshd_config

Step 8: Display OpenSSH Daemon Configuration

Execute the following command in terminal:

grep -E '^(KbdInteractiveAuthentication|UsePAM)' /etc/ssh/sshd_config

Step 9: Auto-fix: mkdir -p /run/sshd

Execute the following command in terminal:

mkdir -p /run/sshd

Step 10: Validate SSH Configuration Syntax

Execute the following command in terminal:

sshd -t

Step 11: Start OpenSSH Daemon

Execute the following command in terminal:

service ssh start && sleep 5 && service ssh status

Step 12: Verify Runtime OpenSSH 2FA Settings

Execute the following command in terminal:

sshd -T | grep -iE 'kbdinteractiveauthentication|usepam'

Step 13: Verify TOTP Token Calculation via Oathtool

Execute the following command in terminal:

oathtool --totp -b "$(head -n 1 /home/sshuser/.google_authenticator)"

3. Security & Production Recommendations

Production Recommendations

To ensure high security and stability in a production environment:

  1. Configure Nginx or Caddy as a Reverse Proxy with automated SSL/TLS via Let’s Encrypt.
  2. Set up UFW firewall to strictly allow only ports 80, 443, and your customized SSH port.
  3. Configure automated daily backups for the PostgreSQL database and uploaded server assets.
Share this Doc

How to Setup Two Factor 2FA Authentication for SSH on Debian

Or copy link

CONTENTS