pam_google_authenticator(8) PAM module for two-step verification



The current version requires the existance of ~/.google-authenticator. If the file does not exist for a user, the authentication module will fail. Each user MUST create their secret key with google-authenticator(1) PRIOR TO enabling this module.

When used with sshd remember to edit sshd_config:
  ChallengeResponseAuthentication yes


Add this line to /etc/pam.d/<FAVORITESERVICE>:

auth required

If needed only for a certain group:

auth [default=1 success=ignore] quiet user ingroup <group>

auth required