{"repo":"kha7iq/kc-ssh-pam","free":true,"listed":false,"github":"https://github.com/kha7iq/kc-ssh-pam","clone":"git clone https://github.com/kha7iq/kc-ssh-pam.git","description":"KC SSH PAM is built to streamline the process of user authentication to access Linux systems through SSH with keycloak oidc","language":"Go","stars":108,"topics":["keycloak","linux","oidc","ssh","sso","golang"],"license":"MIT","category":"auth-billing-email","readme_excerpt":"Install • Usage • Configuration • Contributers • Contributing • Keycloak SSH PAM kc-ssh-pam designed to streamline the process of user authentication and enable users to access Linux systems through SSH. The program integrates with Keycloak to obtain a password grant token based on the user's login credentials, including their username and password. If two-factor authentication is enabled for the user, the program supports OTP code as well. Once the password grant token is obtained, the program verifies it and passes the necessary parameters so that the user can be authenticated via SSH and access the Linux systems. Install DEB & RPM Manual Usage Configuration For the program to function properly, it needs to locate a configuration file called config.toml . The program will search for this file in the follwoing order.. 1. If a config path is specified using the -c flag, it will override any other defined options. 2. Verify the existence of the KC SSH CONFIG variable; if it's defined, use the location specified within it. 3. The working directory where the program is being executed from. 4. Default install location /opt/kc-ssh-pam/ 5. $HOME/.config/ [!IMPORTANT] For proper operation, ensure that SeLinux is configured in Permissive mode. config.toml Edit /etc/pam.d/sshd and add the following at the top of file - User is not automatically created during login, so a local user must be present on the system before hand. To automatically create a user install Add the follwoing in /","default_branch":null,"files":null,"tree":[],"storefront":"/r/kha7iq","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/kha7iq/kc-ssh-pam/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}