How to Setup Two Factor 2FA Authentication for SSH on Debian
1. Overview & System Requirements
This practical guide provides step-by-step instructions to install and configure How to Setup Two Factor 2FA Authentication for SSH on Debian.
Every single command has been executed and validated in a standardized sandbox environment, ensuring zero version conflicts and verified system health.
| Requirement | Details |
|---|---|
| Operating System | Ubuntu 24.04 LTS (Noble Numbat) / Ubuntu 22.04 LTS |
| Minimum Hardware | 2 vCPU, 4GB RAM, 20GB Free Storage |
| Database Backend | PostgreSQL 14+ (PostgreSQL 16 recommended) |
| Access Privileges | Root or sudo-enabled user |
2. Step-by-Step Installation & Verification
Step 1: Update Package Repositories and Install Dependencies
Execute the following command in terminal:
apt-get update && DEBIAN_FRONTEND=noninteractive apt-get install -y openssh-server libpam-google-authenticator qrencode oathtool
Step 2: Create User Account for SSH 2FA
Execute the following command in terminal:
id -u sshuser >/dev/null 2>&1 || useradd -m -s /bin/bash sshuser && echo 'sshuser:Password123!' | chpasswd
Step 3: Generate TOTP Secret and Recovery Codes
Execute the following command in terminal:
su - sshuser -c "google-authenticator -t -d -f -C -r 3 -R 30 -w 3 -e 5 -Q UTF8"
Step 4: Inspect Google Authenticator File Structure
Execute the following command in terminal:
head -n 6 /home/sshuser/.google_authenticator
Step 5: Configure PAM to Enforce Google Authenticator for SSH
Execute the following command in terminal:
grep -q 'pam_google_authenticator.so' /etc/pam.d/sshd || echo 'auth required pam_google_authenticator.so nullok' >> /etc/pam.d/sshd
Step 6: Display PAM SSH Configuration
Execute the following command in terminal:
tail -n 5 /etc/pam.d/sshd
Step 7: Enable Keyboard Interactive Authentication in OpenSSH
Execute the following command in terminal:
sed -i -E 's/^#?KbdInteractiveAuthentication .*/KbdInteractiveAuthentication yes/' /etc/ssh/sshd_config && sed -i -E 's/^#?UsePAM .*/UsePAM yes/' /etc/ssh/sshd_config && grep -q '^KbdInteractiveAuthentication yes' /etc/ssh/sshd_config || echo 'KbdInteractiveAuthentication yes' >> /etc/ssh/sshd_config
Step 8: Display OpenSSH Daemon Configuration
Execute the following command in terminal:
grep -E '^(KbdInteractiveAuthentication|UsePAM)' /etc/ssh/sshd_config
Step 9: Auto-fix: mkdir -p /run/sshd
Execute the following command in terminal:
mkdir -p /run/sshd
Step 10: Validate SSH Configuration Syntax
Execute the following command in terminal:
sshd -t
Step 11: Start OpenSSH Daemon
Execute the following command in terminal:
service ssh start && sleep 5 && service ssh status
Step 12: Verify Runtime OpenSSH 2FA Settings
Execute the following command in terminal:
sshd -T | grep -iE 'kbdinteractiveauthentication|usepam'
Step 13: Verify TOTP Token Calculation via Oathtool
Execute the following command in terminal:
oathtool --totp -b "$(head -n 1 /home/sshuser/.google_authenticator)"
3. Security & Production Recommendations
Production Recommendations
To ensure high security and stability in a production environment:
- Configure Nginx or Caddy as a Reverse Proxy with automated SSL/TLS via Let’s Encrypt.
- Set up UFW firewall to strictly allow only ports 80, 443, and your customized SSH port.
- Configure automated daily backups for the PostgreSQL database and uploaded server assets.