Re: [Freeipa-users] Host based 2FA ?

2014-12-12 Thread Simo Sorce
On Thu, 11 Dec 2014 18:30:06 -0500 Dmitri Pal d...@redhat.com wrote: On 12/11/2014 06:32 PM, free...@pettyvices.com wrote: I'd like to be able to require 2FA on *certain* hosts and allow just passwords on others. It seems you can check both passwords and 2FA under the user. I was

Re: [Freeipa-users] Host based 2FA ?

2014-12-12 Thread Dmitri Pal
On 12/12/2014 01:07 PM, Simo Sorce wrote: On Thu, 11 Dec 2014 18:30:06 -0500 Dmitri Pal d...@redhat.com wrote: On 12/11/2014 06:32 PM, free...@pettyvices.com wrote: I'd like to be able to require 2FA on *certain* hosts and allow just passwords on others. It seems you can check both passwords

Re: [Freeipa-users] Host based 2FA ?

2014-12-12 Thread Simo Sorce
On Fri, 12 Dec 2014 13:17:18 -0500 Dmitri Pal d...@redhat.com wrote: On 12/12/2014 01:07 PM, Simo Sorce wrote: On Thu, 11 Dec 2014 18:30:06 -0500 Dmitri Pal d...@redhat.com wrote: On 12/11/2014 06:32 PM, free...@pettyvices.com wrote: I'd like to be able to require 2FA on *certain*

Re: [Freeipa-users] Host based 2FA ?

2014-12-12 Thread Dmitri Pal
On 12/12/2014 01:27 PM, Simo Sorce wrote: On Fri, 12 Dec 2014 13:17:18 -0500 Dmitri Pal d...@redhat.com wrote: On 12/12/2014 01:07 PM, Simo Sorce wrote: On Thu, 11 Dec 2014 18:30:06 -0500 Dmitri Pal d...@redhat.com wrote: On 12/11/2014 06:32 PM, free...@pettyvices.com wrote: I'd like to be

Re: [Freeipa-users] Host based 2FA ?

2014-12-12 Thread Simo Sorce
On Fri, 12 Dec 2014 13:32:03 -0500 Dmitri Pal d...@redhat.com wrote: On 12/12/2014 01:27 PM, Simo Sorce wrote: On Fri, 12 Dec 2014 13:17:18 -0500 Dmitri Pal d...@redhat.com wrote: On 12/12/2014 01:07 PM, Simo Sorce wrote: On Thu, 11 Dec 2014 18:30:06 -0500 Dmitri Pal d...@redhat.com

Re: [Freeipa-users] Host based 2FA ?

2014-12-12 Thread Dmitri Pal
On 12/12/2014 01:32 PM, Dmitri Pal wrote: On 12/12/2014 01:27 PM, Simo Sorce wrote: On Fri, 12 Dec 2014 13:17:18 -0500 Dmitri Pal d...@redhat.com wrote: On 12/12/2014 01:07 PM, Simo Sorce wrote: On Thu, 11 Dec 2014 18:30:06 -0500 Dmitri Pal d...@redhat.com wrote: On 12/11/2014 06:32 PM,

Re: [Freeipa-users] Host based 2FA ?

2014-12-12 Thread Dmitri Pal
On 12/12/2014 01:38 PM, Simo Sorce wrote: On Fri, 12 Dec 2014 13:32:03 -0500 Dmitri Pal d...@redhat.com wrote: On 12/12/2014 01:27 PM, Simo Sorce wrote: On Fri, 12 Dec 2014 13:17:18 -0500 Dmitri Pal d...@redhat.com wrote: On 12/12/2014 01:07 PM, Simo Sorce wrote: On Thu, 11 Dec 2014

Re: [Freeipa-users] Host based 2FA ?

2014-12-12 Thread Simo Sorce
On Fri, 12 Dec 2014 13:49:24 -0500 Dmitri Pal d...@redhat.com wrote: On 12/12/2014 01:38 PM, Simo Sorce wrote: On Fri, 12 Dec 2014 13:32:03 -0500 Dmitri Pal d...@redhat.com wrote: On 12/12/2014 01:27 PM, Simo Sorce wrote: On Fri, 12 Dec 2014 13:17:18 -0500 Dmitri Pal d...@redhat.com

Re: [Freeipa-users] Host based 2FA ?

2014-12-12 Thread Nathaniel McCallum
On Fri, 2014-12-12 at 13:07 -0500, Simo Sorce wrote: On Thu, 11 Dec 2014 18:30:06 -0500 Dmitri Pal d...@redhat.com wrote: On 12/11/2014 06:32 PM, free...@pettyvices.com wrote: I'd like to be able to require 2FA on *certain* hosts and allow just passwords on others. It seems

Re: [Freeipa-users] Host based 2FA ?

2014-12-12 Thread Dmitri Pal
On 12/12/2014 02:40 PM, Nathaniel McCallum wrote: On Fri, 2014-12-12 at 13:07 -0500, Simo Sorce wrote: On Thu, 11 Dec 2014 18:30:06 -0500 Dmitri Pal d...@redhat.com wrote: On 12/11/2014 06:32 PM, free...@pettyvices.com wrote: I'd like to be able to require 2FA on *certain* hosts and allow

Re: [Freeipa-users] Host based 2FA ?

2014-12-12 Thread Nathaniel McCallum
On Fri, 2014-12-12 at 14:46 -0500, Dmitri Pal wrote: On 12/12/2014 02:40 PM, Nathaniel McCallum wrote: On Fri, 2014-12-12 at 13:07 -0500, Simo Sorce wrote: On Thu, 11 Dec 2014 18:30:06 -0500 Dmitri Pal d...@redhat.com wrote: On 12/11/2014 06:32 PM, free...@pettyvices.com wrote: I'd

Re: [Freeipa-users] Host based 2FA ?

2014-12-12 Thread Dmitri Pal
On 12/12/2014 02:29 PM, Simo Sorce wrote: On Fri, 12 Dec 2014 13:49:24 -0500 Dmitri Pal d...@redhat.com wrote: On 12/12/2014 01:38 PM, Simo Sorce wrote: On Fri, 12 Dec 2014 13:32:03 -0500 Dmitri Pal d...@redhat.com wrote: On 12/12/2014 01:27 PM, Simo Sorce wrote: On Fri, 12 Dec 2014

[Freeipa-users] Host based 2FA ?

2014-12-11 Thread freeipa
I'd like to be able to require 2FA on *certain* hosts and allow just passwords on others. It seems you can check both passwords and 2FA under the user. I was hoping I could create a HBAC such that certain hosts would only allow 2FA, but I can't see an obvious way to do that. Is it

Re: [Freeipa-users] Host based 2FA ?

2014-12-11 Thread Dmitri Pal
On 12/11/2014 06:32 PM, free...@pettyvices.com wrote: I'd like to be able to require 2FA on *certain* hosts and allow just passwords on others. It seems you can check both passwords and 2FA under the user. I was hoping I could create a HBAC such that certain hosts would only allow 2FA, but