From 5213f9b2d240ccfabd4ce454f8727bee8073a049 Mon Sep 17 00:00:00 2001 From: ebner Date: Wed, 11 Dec 2024 14:09:10 +0100 Subject: [PATCH] add info regarding disabling kerberos and public key authentication --- admin-guide/configuration/access/mfa.md | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/admin-guide/configuration/access/mfa.md b/admin-guide/configuration/access/mfa.md index dc324660..a741a1b1 100644 --- a/admin-guide/configuration/access/mfa.md +++ b/admin-guide/configuration/access/mfa.md @@ -3,6 +3,13 @@ MFA can be enabled on any standard system with following configuration: ```yaml +# disable kerberos authentication +ssh_server::enable_gssapi: false + +# #disable ssh key authentication +ssh_server::enable_public_key: false + + aaa::radius_auth: true aaa::radius_shared_secret: ENC[PKCS7,MIIBuQYJK...9Z82qA==] aaa::radius_servers: [ 'nps01.psi.ch', 'nps02.psi.ch' ]