#3264 [RFE] Make 2FA prompting configurable
Closed: Fixed by jhrozek. Opened by jhrozek.

Ticket was cloned from Red Hat Bugzilla (product Red Hat Enterprise Linux 7): Bug 1402056

Description of problem:
Currently when 2-factor authentication is configured on the server side SSSD
prompts for:
    First Factor:
    Second Factor:
To be able to change the prompts to give the user a better hint what to enter
in a given environment or to short-cut it to a single prompt where both factors
are entered in a single string new config options should be added to sssd.conf.

Metadata Update from @jhrozek:
- Issue set to the milestone: SSSD Future releases (no date set yet)

Metadata Update from @jhrozek:
- Custom field mark reset (from no)
- Custom field review reset (from True)
- Custom field sensitive reset (from 0)
- Issue close_status updated to: None
- Issue set to the milestone: SSSD 1.16.0 (was: SSSD Future releases (no date set yet))

Metadata Update from @jhrozek:
- Custom field mark reset (from false)
- Custom field review reset (from false)
- Custom field sensitive reset (from false)
- Issue tagged with: RFE

When implementing this change, please be mindful about ticket #3438 and check the discussion there!

Metadata Update from @jhrozek:
- Custom field mark reset (from false)
- Custom field review reset (from false)
- Custom field sensitive reset (from false)

Since we are required to release a new upstream tarball no later than Friday Oct-20, I'm moving tickets that will not be closed by that date to the next milestone, 1.16.1

Metadata Update from @jhrozek:
- Custom field mark reset (from false)
- Custom field review reset (from false)
- Custom field sensitive reset (from false)
- Issue set to the milestone: SSSD 1.16.1 (was: SSSD 1.16.0)

Metadata Update from @jhrozek:
- Custom field mark reset (from false)
- Custom field review reset (from false)
- Custom field sensitive reset (from false)
- Issue tagged with: postpone-to-2-0

Being able to modify the change password prompts, or include helper text (e.g. multi-line text describing the password policy) could also be useful.

(this kind of matches the banner and pwhelp arguments for pam_krb5)

Metadata Update from @jhrozek:
- Custom field mark reset (from false)
- Custom field review reset (from false)
- Custom field sensitive reset (from false)
- Issue untagged with: postpone-to-2-0
- Issue set to the milestone: SSSD 2.0 (was: SSSD 1.16.1)

Metadata Update from @jhrozek:
- Custom field mark reset (from false)
- Custom field review reset (from false)
- Custom field sensitive reset (from false)
- Issue set to the milestone: SSSD 2.1 (was: SSSD 2.0)

Jumping in from #3888

{quote}
Please, allow this for ssh connections (and sudo, ok, all sssd authorised services :) ) too. We have per host 2FA and we'd like to remove the "Second Factor (optional):" prompt from those hosts that do not require 2FA.
{quote}

Metadata Update from @jhrozek:
- Custom field mark reset (from false)
- Custom field review reset (from false)
- Custom field sensitive reset (from false)
- Issue set to the milestone: SSSD 2.2 (was: SSSD 2.1)

Metadata Update from @sbose:
- Issue assigned to sbose

https://github.com/SSSD/sssd/pull/792

Metadata Update from @sbose:
- Custom field mark reset (from false)
- Custom field review reset (from false)
- Custom field sensitive reset (from false)

Commit 45efba71 relates to this ticket

Commit a4d17859 relates to this ticket

Commit fc26b4a8 relates to this ticket

Commit ac4b33f7 relates to this ticket

Commit fa8ef7c6 relates to this ticket

  • master:
    45efba71befd96c8e9fe0a51fc300cafa93bd703
    a4d178593bec65a4c7534b841cedfbb74c56f49f
    fc26b4a82d4a92b29cf321fba8dbec52c3bff8d6
    ac4b33f765ac322949ac7c2f24985d3b9c178168
    fa8ef7c6db19a160d807f05b08bbc66c0c25ebfe

Metadata Update from @jhrozek:
- Custom field mark reset (from false)
- Custom field review reset (from false)
- Custom field sensitive reset (from false)

  • sssd-1-16:
    558b543270d4bb56336c48040611fbc7c5552451
    efefac9f41354e5e8d794ce5c6ceb7f0ebc3ed78
    c91c6dd4ba87ace0b1566e93539a95b59ec385fa
    ca65bfdab55c614eb5c1195065d38e696594a80d
    d453f92e1c2312655b3359fc16f386b8d569c668
    ceb4c8e219d01c29d0dfbfff13020ca58b4113d2

Metadata Update from @jhrozek:
- Custom field mark reset (from false)
- Custom field review reset (from false)
- Custom field sensitive reset (from false)
- Issue close_status updated to: Fixed
- Issue status updated to: Closed (was: Open)

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/4297

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Metadata