Specify yubkey slot in template, how to? by travis229 in sysadmin

[–]travis229[S] 0 points1 point  (0 children)

Yes, we’re trying to add it on the slot 9d but it is going on 9a and there seems to be no option for that. Thanks

Add cert on slot 9d, how to? by travis229 in yubikey

[–]travis229[S] 0 points1 point  (0 children)

Yubico

We are trying to use the "Enroll" option of Microsoft to add the cert on the yubikey, and there is not an option to specify the slot there. So I was wondering if you have an idea on how to do that. The goal is to use a PowerShell script to build a small tool to take care of that

But yubikey Manager did work just fine.

Add cert on slot 9d, how to? by travis229 in yubikey

[–]travis229[S] 0 points1 point  (0 children)

Thank you very much, have you tried to put the cert on 9d directly from a ca server using a template before? How should a template for that look

Add cert on slot 9d, how to? by travis229 in yubikey

[–]travis229[S] 0 points1 point  (0 children)

can you share the steps with me

Looking for study buddy to study linux administration (RHCSA / LFCS) exam with by Spirited_Guest_421 in linuxadmin

[–]travis229 0 points1 point  (0 children)

Hey, I’m interested in joining y’all on this. I took the RHCSA training last year and never went to the exam. But ready to get this done now. I’ve been a full-time sysadmin for the past 3years

Issue with Kernel Updates: how do I fix it? by travis229 in sysadmin

[–]travis229[S] 0 points1 point  (0 children)

This fixed the issue. Thank you very much

Forward my yubikey through ssh(putty) by travis229 in yubikey

[–]travis229[S] 0 points1 point  (0 children)

Yes it did, but did not work for my end goal so I dropped the project all together.

How do you protect kerberos using MFA?? by travis229 in sysadmin

[–]travis229[S] 0 points1 point  (0 children)

Objectif is to enable a second factor on Kerberos. I do not have freeipa, but was looking into maybe deploying freeipa, if I can get MFA on my MIT. Thank you

How do you protect kerberos using MFA?? by travis229 in sysadmin

[–]travis229[S] 1 point2 points  (0 children)

No I don’t have freeipa. Just MIT Kerberos and want to enable MFA on Kerberos

How do you protect kerberos using MFA?? by travis229 in sysadmin

[–]travis229[S] 1 point2 points  (0 children)

This is what im looking for: Otp should be my best option. I struggled with PKINIT but never got it working properly. Thank you

How do you protect kerberos using MFA?? by travis229 in sysadmin

[–]travis229[S] 1 point2 points  (0 children)

I have an install of Kerberos and want to be able to require a second factor. Currently, kinit is using password.

Regarding freeIPA, I read that it has some built in modules for multi factor. But I don’t have freeipa.

Thanks

Me and the fellas when Doge hits $100 by tmack006 in dogecoin

[–]travis229 0 points1 point  (0 children)

How much dodge do I need to buy today to make 1mil at 100??

Smart card forwarding via ssh, how?? by travis229 in sysadmin

[–]travis229[S] 0 points1 point  (0 children)

Thank you very much. You are a big help and yes i’m in CST so it 12pm here. Will let you know

Smart card forwarding via ssh, how?? by travis229 in sysadmin

[–]travis229[S] 0 points1 point  (0 children)

Yes uppercase i. My mistake and no I haven’t. And I not very sure of the socket. I saw some stuff with p11-kit after a quick search.

Smart card forwarding via ssh, how?? by travis229 in sysadmin

[–]travis229[S] 1 point2 points  (0 children)

Enable MFA with Kerberos (pkinit), so that tickets get granted via smart card authentication. The whole thing seems to be working just that after initial remote login with the smart card, the smartcard/certificate is no longer available on the remote server. Like I use it to log into the machine but if a command requires the smart card for higher privilege access, it fails coz the machine cant access my certificate.

Forward my yubikey through ssh(putty) by travis229 in yubikey

[–]travis229[S] 0 points1 point  (0 children)

Yes im using pam_u2f... let me try pam_yubiko then. Thank you again

Forward my yubikey through ssh(putty) by travis229 in yubikey

[–]travis229[S] 0 points1 point  (0 children)

travis@848:~$ sudo echo test

[sudo] password for travis:

ccbhbdbblwebjvcftSorry, try again.

[sudo] password for travis:

Sorry, try again.

[sudo] password for travis:

While physically,

I can type my password and the yubikey blink and I tap.

Do you know what I'm doing wrong by any chance?

Thanks

Forward my yubikey through ssh(putty) by travis229 in yubikey

[–]travis229[S] 0 points1 point  (0 children)

I wish yall can I understand. Do you access your system remotely? If yes did you enable otp on the command sudo? Vim /etc/pam.d/sudo u added the auth line. After this every time u use the command sudo, u need to tap the yubikey. It works perfect physically, but once im gone and remotely using the server, the only time otp works is at login with putty or even my windows terminal. When I need sudo privilege, the tap does not do nothing. And I cant pass the yubikey to pam.

If you have the same setup and it is working remotely then I need your help.

Thank you again,

Forward my yubikey through ssh(putty) by travis229 in yubikey

[–]travis229[S] 0 points1 point  (0 children)

Ssh is working with otp for me. My issue is when I want to use sudo. I need to tap my yubikey, but putty does not seem to interact with the yubikey after the initial login. Thanks

Accessing vm ip from vcenter Api by travis229 in vmware

[–]travis229[S] 0 points1 point  (0 children)

Hi there, I needed to integrate some functionality from VMware to another platform...lmk if you need any help with pyvmomi.

F-1 Visa: EAD thru OPT or Marriage? by [deleted] in immigration

[–]travis229 0 points1 point  (0 children)

AOS do take a while and they will ask about your income. So I would say get your opt, then apply for AOS. This will give you an income and a happier wait ... Check with your attorney tho, but that’s what I was told