# The following was performed on Debian Stretch
# Adapted from:
# https://ubuntuforums.org/showthread.php?t=1557180&p=9743605
# http://blog.fkraiem.org/2013/03/13/linux-smart-card-authentication-pam/
#
# Note: A X.509 certificate stored on the card is required. See:
# https://pastebin.com/dCypTy09
# =====================================================================
#
# Install the PKCS11 module for PAM
# Note: /etc/pam_pkcs11/cacerts and /etc/pam_pkcs11/crls are automatically
# created here.
# ---------------------------------------------------------------------
$ sudo apt-get install libpam-pkcs11
# Extract the pam_pkcs11.conf example file
# ---------------------------------------------------------------------
$ zcat /usr/share/doc/libpam-pkcs11/examples/pam_pkcs11.conf.example.gz | sudo tee /etc/pam_pkcs11/pam_pkcs11.conf
# Edit /etc/pam_pkcs11/pam_pkcs11.conf and change the 'module' line
# to the correct path of opensc-pkcs11.so.
# ---------------------------------------------------------------------
module = /usr/lib/x86_64-linux-gnu/opensc-pkcs11.so
# Extract the certificate from the card and store as the PAM PKCS11 CA
#
# Note: certificate is self-signed and its own CA
# ---------------------------------------------------------------------
$ pkcs15-tool --read-certificate 707db33cfbd0712e0d5cfc4238fa85be44da990d | sudo tee /etc/pam_pkcs11/cacerts/jdoe-smartcard.pem
# Rehash the certs stored in /etc/pam_pkcs11/cacerts
# ---------------------------------------------------------------------
$ sudo pkcs11_make_hash_link /etc/pam_pkcs11/cacerts
# Basic Test with sudo
# ---------------------------------------------------------------------
#
# Modify /etc/pam.d/sudo from:
# vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
%PAM-1.0
@include common-auth
@include common-account
@include common-session-noninteractive
# To:
# vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
#%PAM-1.0
auth sufficient pam_pkcs11.so
@include common-auth
@include common-account
@include common-session-noninteractive
# Confirm that sudo works
# ---------------------------------------------------------------------
#
# flush any cached passphrase
$ sudo --reset-timestamp
# gain root using PKCS11
$ sudo --login
Smartcard authentication starts
Smart card found.
Welcome OpenSC Card (John Doe)!
Smart card PIN:
verifying certificate
Checking signature
# Revert changes to /etc/pam.d/sudo
# ---------------------------------------------------------------------
# Remove the "auth sufficient pam_pkcs11.so" line
# Edit /etc/pam.d/common-auth to apply smartcard auth globally
#
# Note: It is important to add pam_pkcs11.so *BEFORE* the comment
# about the "Primary" block. Otherwise, it will be overwritten by
# pam-auth-update(8)
# ---------------------------------------------------------------------
#
# Original:
# vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
# /etc/pam.d/common-auth - authentication settings common to all services
#
# This file is included from other service-specific PAM config files,
# and should contain a list of the authentication modules that define
# the central authentication scheme for use on the system
# (e.g., /etc/shadow, LDAP, Kerberos, etc.). The default is to use the
# traditional Unix authentication mechanisms.
#
# As of pam 1.0.1-6, this file is managed by pam-auth-update by default.
# To take advantage of this, it is recommended that you configure any
# local modules either before or after the default block, and use
# pam-auth-update to manage selection of other modules. See
# pam-auth-update(8) for details.
# here are the per-package modules (the "Primary" block)
auth [success=1 default=ignore] pam_unix.so nullok_secure
# here's the fallback if no module succeeds
auth requisite pam_deny.so
# prime the stack with a positive return value if there isn't one already;
# this avoids us returning an error just because nothing sets a success code
# since the modules above will each just jump around
auth required pam_permit.so
# and here are more per-package modules (the "Additional" block)
# end of pam-auth-update config
# Updated:
# vvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
# /etc/pam.d/common-auth - authentication settings common to all services
#
# This file is included from other service-specific PAM config files,
# and should contain a list of the authentication modules that define
# the central authentication scheme for use on the system
# (e.g., /etc/shadow, LDAP, Kerberos, etc.). The default is to use the
# traditional Unix authentication mechanisms.
#
# As of pam 1.0.1-6, this file is managed by pam-auth-update by default.
# To take advantage of this, it is recommended that you configure any
# local modules either before or after the default block, and use
# pam-auth-update to manage selection of other modules. See
# pam-auth-update(8) for details.
auth [success=2 default=ignore] pam_pkcs11.so
# here are the per-package modules (the "Primary" block)
auth [success=1 default=ignore] pam_unix.so nullok_secure
# here's the fallback if no module succeeds
auth requisite pam_deny.so
# prime the stack with a positive return value if there isn't one already;
# this avoids us returning an error just because nothing sets a success code
# since the modules above will each just jump around
auth required pam_permit.so
# and here are more per-package modules (the "Additional" block)
# end of pam-auth-update config
# Disable password authentication for the current user
# Note: Verify smartcard auth works before locking account!
# ---------------------------------------------------------------------
$ sudo passwd --lock `whoami`
Smartcard authentication starts
Smart card found.
Welcome OpenSC Card (John Doe)!
Smart card PIN:
verifying certificate
Checking signature
passwd: password expiry information changed.
Comments
0 B
|👍
/👎