{"id":43165,"date":"2026-09-28T08:20:08","date_gmt":"2026-09-28T08:20:08","guid":{"rendered":"https:\/\/green.cloud\/docs\/docs\/greencloud-documents\/linux-operating-systems\/how-to-setup-two-factor-2fa-authentication-for-ssh-on-debian\/"},"modified":"2026-09-28T08:22:12","modified_gmt":"2026-09-28T08:22:12","slug":"how-to-setup-two-factor-2fa-authentication-for-ssh-on-debian","status":"publish","type":"docs","link":"https:\/\/green.cloud\/docs\/docs\/greencloud-documents\/linux-operating-systems\/how-to-setup-two-factor-2fa-authentication-for-ssh-on-debian\/","title":{"rendered":"How to Setup Two Factor 2FA Authentication for SSH on Debian"},"content":{"rendered":"<h1>1. Overview &amp; System Requirements<\/h1>\n<p>This practical guide provides step-by-step instructions to install and configure How to Setup Two Factor 2FA Authentication for SSH on Debian.<\/p>\n<p>Every single command has been executed and validated in a standardized sandbox environment, ensuring zero version conflicts and verified system health.<\/p>\n<table>\n<tbody>\n<tr>\n<th>Requirement<\/th>\n<th>Details<\/th>\n<\/tr>\n<tr>\n<td><strong>Operating System<\/strong><\/td>\n<td>Ubuntu 24.04 LTS (Noble Numbat) \/ Ubuntu 22.04 LTS<\/td>\n<\/tr>\n<tr>\n<td><strong>Minimum Hardware<\/strong><\/td>\n<td>2 vCPU, 4GB RAM, 20GB Free Storage<\/td>\n<\/tr>\n<tr>\n<td><strong>Database Backend<\/strong><\/td>\n<td>PostgreSQL 14+ (PostgreSQL 16 recommended)<\/td>\n<\/tr>\n<tr>\n<td><strong>Access Privileges<\/strong><\/td>\n<td>Root or sudo-enabled user<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<div>\n<hr \/>\n<\/div>\n<h1>2. Step-by-Step Installation &amp; Verification<\/h1>\n<h3>Step 1: Update Package Repositories and Install Dependencies<\/h3>\n<p>Execute the following command in terminal:<\/p>\n<pre>apt-get update &amp;&amp; DEBIAN_FRONTEND=noninteractive apt-get install -y openssh-server libpam-google-authenticator qrencode oathtool<\/pre>\n<div>\n<hr \/>\n<\/div>\n<h3>Step 2: Create User Account for SSH 2FA<\/h3>\n<p>Execute the following command in terminal:<\/p>\n<pre>id -u sshuser &gt;\/dev\/null 2&gt;&amp;1 || useradd -m -s \/bin\/bash sshuser &amp;&amp; echo 'sshuser:Password123!' | chpasswd<\/pre>\n<div>\n<hr \/>\n<\/div>\n<h3>Step 3: Generate TOTP Secret and Recovery Codes<\/h3>\n<p>Execute the following command in terminal:<\/p>\n<pre>su - sshuser -c \"google-authenticator -t -d -f -C -r 3 -R 30 -w 3 -e 5 -Q UTF8\"<\/pre>\n<div>\n<hr \/>\n<\/div>\n<h3>Step 4: Inspect Google Authenticator File Structure<\/h3>\n<p>Execute the following command in terminal:<\/p>\n<pre>head -n 6 \/home\/sshuser\/.google_authenticator<\/pre>\n<div>\n<hr \/>\n<\/div>\n<h3>Step 5: Configure PAM to Enforce Google Authenticator for SSH<\/h3>\n<p>Execute the following command in terminal:<\/p>\n<pre>grep -q 'pam_google_authenticator.so' \/etc\/pam.d\/sshd || echo 'auth required pam_google_authenticator.so nullok' &gt;&gt; \/etc\/pam.d\/sshd<\/pre>\n<div>\n<hr \/>\n<\/div>\n<h3>Step 6: Display PAM SSH Configuration<\/h3>\n<p>Execute the following command in terminal:<\/p>\n<pre>tail -n 5 \/etc\/pam.d\/sshd<\/pre>\n<div>\n<hr \/>\n<\/div>\n<h3>Step 7: Enable Keyboard Interactive Authentication in OpenSSH<\/h3>\n<p>Execute the following command in terminal:<\/p>\n<pre>sed -i -E 's\/^#?KbdInteractiveAuthentication .*\/KbdInteractiveAuthentication yes\/' \/etc\/ssh\/sshd_config &amp;&amp; sed -i -E 's\/^#?UsePAM .*\/UsePAM yes\/' \/etc\/ssh\/sshd_config &amp;&amp; grep -q '^KbdInteractiveAuthentication yes' \/etc\/ssh\/sshd_config || echo 'KbdInteractiveAuthentication yes' &gt;&gt; \/etc\/ssh\/sshd_config<\/pre>\n<div>\n<hr \/>\n<\/div>\n<h3>Step 8: Display OpenSSH Daemon Configuration<\/h3>\n<p>Execute the following command in terminal:<\/p>\n<pre>grep -E '^(KbdInteractiveAuthentication|UsePAM)' \/etc\/ssh\/sshd_config<\/pre>\n<div>\n<hr \/>\n<\/div>\n<h3>Step 9: Auto-fix: mkdir -p \/run\/sshd<\/h3>\n<p>Execute the following command in terminal:<\/p>\n<pre>mkdir -p \/run\/sshd<\/pre>\n<div>\n<hr \/>\n<\/div>\n<h3>Step 10: Validate SSH Configuration Syntax<\/h3>\n<p>Execute the following command in terminal:<\/p>\n<pre>sshd -t<\/pre>\n<div>\n<hr \/>\n<\/div>\n<h3>Step 11: Start OpenSSH Daemon<\/h3>\n<p>Execute the following command in terminal:<\/p>\n<pre>service ssh start &amp;&amp; sleep 5 &amp;&amp; service ssh status<\/pre>\n<div>\n<hr \/>\n<\/div>\n<h3>Step 12: Verify Runtime OpenSSH 2FA Settings<\/h3>\n<p>Execute the following command in terminal:<\/p>\n<pre>sshd -T | grep -iE 'kbdinteractiveauthentication|usepam'<\/pre>\n<div>\n<hr \/>\n<\/div>\n<h3>Step 13: Verify TOTP Token Calculation via Oathtool<\/h3>\n<p>Execute the following command in terminal:<\/p>\n<pre>oathtool --totp -b \"$(head -n 1 \/home\/sshuser\/.google_authenticator)\"<\/pre>\n<div>\n<hr \/>\n<\/div>\n<h2>3. Security &amp; Production Recommendations<\/h2>\n<h2>Production Recommendations<\/h2>\n<p>To ensure high security and stability in a production environment:<\/p>\n<ol start=\"1\">\n<li>Configure Nginx or Caddy as a Reverse Proxy with automated SSL\/TLS via Let&#8217;s Encrypt.<\/li>\n<li>Set up UFW firewall to strictly allow only ports 80, 443, and your customized SSH port.<\/li>\n<li>Configure automated daily backups for the PostgreSQL database and uploaded server assets.<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>1. Overview &amp; System Requirements This practical guide provides step-by-step instructions to install and configure How to Setup Two Factor 2FA Authentication for SSH on Debian. Every single command has been executed and validated in a standardized sandbox environment, ensuring zero version conflicts and verified system health. Requirement Details Operating System Ubuntu 24.04 LTS (Noble [&hellip;]<\/p>\n","protected":false},"author":27,"featured_media":0,"parent":17817,"menu_order":457,"comment_status":"closed","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-43165","docs","type-docs","status-publish","hentry","no-post-thumbnail"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How to Setup Two Factor 2FA Authentication for SSH on Debian - GreenCloud Documentation<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/green.cloud\/docs\/docs\/greencloud-documents\/linux-operating-systems\/how-to-setup-two-factor-2fa-authentication-for-ssh-on-debian\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to Setup Two Factor 2FA Authentication for SSH on Debian - GreenCloud Documentation\" \/>\n<meta property=\"og:description\" content=\"1. Overview &amp; System Requirements This practical guide provides step-by-step instructions to install and configure How to Setup Two Factor 2FA Authentication for SSH on Debian. Every single command has been executed and validated in a standardized sandbox environment, ensuring zero version conflicts and verified system health. Requirement Details Operating System Ubuntu 24.04 LTS (Noble [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/green.cloud\/docs\/docs\/greencloud-documents\/linux-operating-systems\/how-to-setup-two-factor-2fa-authentication-for-ssh-on-debian\/\" \/>\n<meta property=\"og:site_name\" content=\"GreenCloud Documentation\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-28T08:22:12+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/green.cloud\\\/docs\\\/docs\\\/greencloud-documents\\\/linux-operating-systems\\\/how-to-setup-two-factor-2fa-authentication-for-ssh-on-debian\\\/\",\"url\":\"https:\\\/\\\/green.cloud\\\/docs\\\/docs\\\/greencloud-documents\\\/linux-operating-systems\\\/how-to-setup-two-factor-2fa-authentication-for-ssh-on-debian\\\/\",\"name\":\"How to Setup Two Factor 2FA Authentication for SSH on Debian - GreenCloud Documentation\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/green.cloud\\\/docs\\\/#website\"},\"datePublished\":\"2026-09-28T08:20:08+00:00\",\"dateModified\":\"2026-09-28T08:22:12+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/green.cloud\\\/docs\\\/docs\\\/greencloud-documents\\\/linux-operating-systems\\\/how-to-setup-two-factor-2fa-authentication-for-ssh-on-debian\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/green.cloud\\\/docs\\\/docs\\\/greencloud-documents\\\/linux-operating-systems\\\/how-to-setup-two-factor-2fa-authentication-for-ssh-on-debian\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/green.cloud\\\/docs\\\/docs\\\/greencloud-documents\\\/linux-operating-systems\\\/how-to-setup-two-factor-2fa-authentication-for-ssh-on-debian\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/green.cloud\\\/docs\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"GreenCloud Documents\",\"item\":\"https:\\\/\\\/green.cloud\\\/docs\\\/docs\\\/greencloud-documents\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Linux Operating Systems\",\"item\":\"https:\\\/\\\/green.cloud\\\/docs\\\/linux-operating-systems\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"How to Setup Two Factor 2FA Authentication for SSH on Debian\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/green.cloud\\\/docs\\\/#website\",\"url\":\"https:\\\/\\\/green.cloud\\\/docs\\\/\",\"name\":\"GreenCloud Documentation\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/green.cloud\\\/docs\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to Setup Two Factor 2FA Authentication for SSH on Debian - GreenCloud Documentation","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/green.cloud\/docs\/docs\/greencloud-documents\/linux-operating-systems\/how-to-setup-two-factor-2fa-authentication-for-ssh-on-debian\/","og_locale":"en_US","og_type":"article","og_title":"How to Setup Two Factor 2FA Authentication for SSH on Debian - GreenCloud Documentation","og_description":"1. Overview &amp; System Requirements This practical guide provides step-by-step instructions to install and configure How to Setup Two Factor 2FA Authentication for SSH on Debian. Every single command has been executed and validated in a standardized sandbox environment, ensuring zero version conflicts and verified system health. Requirement Details Operating System Ubuntu 24.04 LTS (Noble [&hellip;]","og_url":"https:\/\/green.cloud\/docs\/docs\/greencloud-documents\/linux-operating-systems\/how-to-setup-two-factor-2fa-authentication-for-ssh-on-debian\/","og_site_name":"GreenCloud Documentation","article_modified_time":"2026-09-28T08:22:12+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/green.cloud\/docs\/docs\/greencloud-documents\/linux-operating-systems\/how-to-setup-two-factor-2fa-authentication-for-ssh-on-debian\/","url":"https:\/\/green.cloud\/docs\/docs\/greencloud-documents\/linux-operating-systems\/how-to-setup-two-factor-2fa-authentication-for-ssh-on-debian\/","name":"How to Setup Two Factor 2FA Authentication for SSH on Debian - GreenCloud Documentation","isPartOf":{"@id":"https:\/\/green.cloud\/docs\/#website"},"datePublished":"2026-09-28T08:20:08+00:00","dateModified":"2026-09-28T08:22:12+00:00","breadcrumb":{"@id":"https:\/\/green.cloud\/docs\/docs\/greencloud-documents\/linux-operating-systems\/how-to-setup-two-factor-2fa-authentication-for-ssh-on-debian\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/green.cloud\/docs\/docs\/greencloud-documents\/linux-operating-systems\/how-to-setup-two-factor-2fa-authentication-for-ssh-on-debian\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/green.cloud\/docs\/docs\/greencloud-documents\/linux-operating-systems\/how-to-setup-two-factor-2fa-authentication-for-ssh-on-debian\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/green.cloud\/docs\/"},{"@type":"ListItem","position":2,"name":"GreenCloud Documents","item":"https:\/\/green.cloud\/docs\/docs\/greencloud-documents\/"},{"@type":"ListItem","position":3,"name":"Linux Operating Systems","item":"https:\/\/green.cloud\/docs\/linux-operating-systems\/"},{"@type":"ListItem","position":4,"name":"How to Setup Two Factor 2FA Authentication for SSH on Debian"}]},{"@type":"WebSite","@id":"https:\/\/green.cloud\/docs\/#website","url":"https:\/\/green.cloud\/docs\/","name":"GreenCloud Documentation","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/green.cloud\/docs\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/green.cloud\/docs\/wp-json\/wp\/v2\/docs\/43165","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/green.cloud\/docs\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/green.cloud\/docs\/wp-json\/wp\/v2\/types\/docs"}],"author":[{"embeddable":true,"href":"https:\/\/green.cloud\/docs\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/green.cloud\/docs\/wp-json\/wp\/v2\/comments?post=43165"}],"version-history":[{"count":2,"href":"https:\/\/green.cloud\/docs\/wp-json\/wp\/v2\/docs\/43165\/revisions"}],"predecessor-version":[{"id":43169,"href":"https:\/\/green.cloud\/docs\/wp-json\/wp\/v2\/docs\/43165\/revisions\/43169"}],"up":[{"embeddable":true,"href":"https:\/\/green.cloud\/docs\/wp-json\/wp\/v2\/docs\/17817"}],"wp:attachment":[{"href":"https:\/\/green.cloud\/docs\/wp-json\/wp\/v2\/media?parent=43165"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/green.cloud\/docs\/wp-json\/wp\/v2\/doc_tag?post=43165"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}