{"id":36873,"date":"2019-10-31T22:14:26","date_gmt":"2019-10-31T19:14:26","guid":{"rendered":"https:\/\/prohoster.info\/blog\/server-dvuhfaktornoj-avtorizatsii-linotp\/"},"modified":"2019-10-31T22:14:26","modified_gmt":"2019-10-31T19:14:26","slug":"server-dvuhfaktornoj-avtorizatsii-linotp","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/server-dvuhfaktornoj-avtorizatsii-linotp","title":{"rendered":"Serveri i autentifikimit t\u00eb dy faktor\u00ebve LinOTP","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Serveri i autentifikimit t\u00eb dy faktor\u00ebve LinOTP\" src=\"\/wp-content\/uploads\/2019\/08\/8164a72d86173d429e3aaf4efdfee77c.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nSot par ndihm\u00ebn time, do t\u00eb ndaj si t\u00eb konfigurohet nj\u00eb server p\u00ebr autorizimin me dy faktor\u00eb, p\u00ebr t\u00eb mbrojtur rrjetin korporativ, faqet e internetit, sh\u00ebrbimet, ssh. N\u00eb server do t\u00eb funksionoj\u00eb nj\u00eb lidhje: LinOTP + FreeRadius. <\/p>\n<p>Pse na nevojitet? <br \/>\nKjo \u00ebsht\u00eb nj\u00eb zgjidhje krejt\u00ebsisht falas, e leht\u00eb p\u00ebr t'u p\u00ebrdorur brenda rrjetit t\u00ebnd, e pavarur nga ofruesit e jasht\u00ebm.<\/p>\n<p>Ky sh\u00ebrbim \u00ebsht\u00eb shum\u00eb i p\u00ebrshtatsh\u00ebm, i qart\u00eb n\u00eb krahasim me produktet e tjera me burim t\u00eb hapur, dhe gjithashtu mb\u00ebshtet nj\u00eb gam\u00eb t\u00eb gjer\u00eb funksionesh dhe politikash (p\u00ebr shembull login + password + (PIN + OTP Token)). Ndihmon p\u00ebr integrimin me sh\u00ebrbimet e d\u00ebrgimit t\u00eb sms-ve p\u00ebrmes API (LinOTP Config-&gt;Provider Config-&gt;SMS Provider), gjeneron kode p\u00ebr aplikacione mobile si Google Authenticator dhe shum\u00eb t\u00eb tjera. E mendoj at\u00eb m\u00eb t\u00eb p\u00ebrshtatshme se sh\u00ebrbimi i shqyrtuar n\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/308988\/\">artikulli yn\u00eb<\/a><\/noindex>.<\/p>\n<p>Ky server funksionon shk\u00eblqyesh\u00ebm me Cisco ASA, serverin OpenVPN, Apache2, dhe n\u00eb p\u00ebrgjith\u00ebsi praktiksht me \u00e7do gj\u00eb q\u00eb mb\u00ebshtet autentifikimin p\u00ebrmes serverit RADIUS (p\u00ebr shembull p\u00ebr SSH n\u00eb data center).<\/p>\n<p>K\u00ebrkohet:<\/p>\n<p>1 ) Debian 8 (jessie) \u2014<b> Patjet\u00ebr!<\/b> (instalimi provues n\u00eb debian 9 \u00ebsht\u00eb p\u00ebrshkruar n\u00eb fund t\u00eb artikullit)<\/p>\n<p>Fillimi:<\/p>\n<p>Instalojm\u00eb Debian 8.<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\nShtojm\u00eb depot LinOTP:<\/p>\n<pre><code class=\"bash\"># echo 'deb http:\/\/www.linotp.org\/apt\/debian jessie linotp' &gt; \/etc\/apt\/sources.list.d\/linotp.list<\/code><\/pre>\n<p>\nShtojm\u00eb \u00e7el\u00ebsat:<\/p>\n<pre><code class=\"bash\"># gpg --search-keys 913DFF12F86258E5<\/code><\/pre>\n<p>\nNdonj\u00ebher\u00eb gjat\u00eb instalimit 't\u00eb past\u00ebr', pas ekzekutimit t\u00eb k\u00ebsaj komande, Debian jep: <\/p>\n<pre><code class=\"plaintext\">gpg: krijohet dosja `\/root\/.gnupg`\ngpg: krijohet nj\u00eb skedar i ri konfigurimi `\/root\/.gnupg\/gpg.conf`\ngpg: K\u00cbSHILLIM: parametrat n\u00eb `\/root\/.gnupg\/gpg.conf' nuk jan\u00eb ende aktiv\u00eb n\u00eb k\u00ebt\u00eb ekzekutim\ngpg: krijohet tabela e \u00e7el\u00ebsave `\/root\/.gnupg\/secring.gpg`\ngpg: krijohet tabela e \u00e7el\u00ebsave `\/root\/.gnupg\/pubring.gpg`\ngpg: nuk jan\u00eb caktuar server\u00eb \u00e7el\u00ebsash (p\u00ebrdorni --keyserver)\ngpg: d\u00ebshtim n\u00eb k\u00ebrkimin n\u00eb serverin e \u00e7el\u00ebsave: URI i keq\n<\/code><\/pre>\n<p>\nKy \u00ebsht\u00eb konfigurimi fillestar i gnupg. Nuk ka gj\u00eb t\u00eb keqe. Thjesht ekzekutoni komand\u00ebn p\u00ebrs\u00ebri.<br \/>\nN\u00eb pyetjen e Debiant:<\/p>\n<pre><code class=\"plaintext\">gpg: k\u00ebrkim \"913DFF12F86258E5\" n\u00eb serverin hkp keys.gnupg.net\n(1) LSE LinOTP2 Packaging \n\t2048 bit RSA key F86258E5, krijuar: 2010-05-10\nKeys 1-1 e 1 p\u00ebr \"913DFF12F86258E5\". Shkruani numrat, N) Tjet\u00ebr ose Q) Dalja&gt;<\/code><\/pre>\n<p>\nP\u00ebrgjigjemi: 1<\/p>\n<p>Pastaj: <\/p>\n<pre><code class=\"bash\"># gpg --export 913DFF12F86258E5 | apt-key add -<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"bash\"># apt-get update<\/code><\/pre>\n<p>\nInstalojm\u00eb mysql. N\u00eb teori, mund t\u00eb p\u00ebrdorim nj\u00eb server tjet\u00ebr sql, por p\u00ebr thjesht\u00ebsi do ta p\u00ebrdor k\u00ebt\u00eb, si t\u00eb rekomanduar p\u00ebr LinOTP.<\/p>\n<p>(informacione t\u00eb tjera, duke p\u00ebrfshir\u00eb rikompozimin e baz\u00ebs LinOTP, mund t\u00eb gjenden n\u00eb dokumentacionin zyrtar p\u00ebr <noindex><a rel=\"nofollow\" href=\"http:\/\/linotp.org\/doc\/latest\/part-installation\/server-installation\/deb_install.html#debian\">linkun<\/a><\/noindex>. Atje gjithashtu, mund t\u00eb gjeni komand\u00ebn: dpkg-reconfigure linotp p\u00ebr t\u00eb ndryshuar parametrat n\u00ebse e keni instaluar tashm\u00eb mysql).<\/p>\n<pre><code class=\"bash\"># apt-get install mysql-server<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"bash\"># apt-get update<\/code><\/pre>\n<p> (kontrollimi i p\u00ebrdit\u00ebsimeve p\u00ebrs\u00ebri nuk d\u00ebmton)<br \/>\nInstalojm\u00eb LinOTP dhe modulet shtes\u00eb:<\/p>\n<pre><code class=\"bash\"># apt-get install linotp<\/code><\/pre>\n<p>\nP\u00ebrgjigjemi n\u00eb pyetjet e instaluesit: <br \/>\nT\u00eb p\u00ebrdorim Apache2: po<br \/>\nMendoni nj\u00eb fjal\u00ebkalim p\u00ebr admin Linotp: \"Fjal\u00ebkalimiJuaj\"<br \/>\nT\u00eb gjenerojm\u00eb nj\u00eb certifikat\u00eb t\u00eb vet\u00ebshkruar?: po<br \/>\nT\u00eb p\u00ebrdorim MySQL?: po<br \/>\nKu ndodhet baza e t\u00eb dh\u00ebnave: localhost<br \/>\nKrijojm\u00eb baz\u00ebn LinOTP(emri i baz\u00ebs) n\u00eb serverin: LinOTP2<br \/>\nKrijojm\u00eb nj\u00eb p\u00ebrdorues t\u00eb ve\u00e7ant\u00eb p\u00ebr baz\u00ebn e t\u00eb dh\u00ebnave: LinOTP2<br \/>\nI vendosim fjal\u00ebkalimin p\u00ebrdoruesit: \u00abFjal\u00ebkalimiJuaj\u00bb<br \/>\nA duhet t\u00eb krijohet nj\u00eb baz\u00eb tani? (di\u00e7ka si \u201cA jeni t\u00eb sigurt se doni t\u00eb \u2026\u201d): po<br \/>\nShtypim fjal\u00ebkalimin root t\u00eb MySQL q\u00eb krijuam gjat\u00eb instalimit: \u00abFjal\u00ebkalimiJuaj\u00bb<br \/>\nGati.<\/p>\n<p>(opsionale, mund t\u00eb mos e vendosni)<\/p>\n<pre><code class=\"bash\"># apt-get install linotp-adminclient-cli <\/code><\/pre>\n<p>\n(opsionale, mund t\u00eb mos e vendosni)<\/p>\n<pre><code class=\"bash\"># apt-get install libpam-linotp  <\/code><\/pre>\n<p>\nK\u00ebshtu, nd\u00ebrfaqja jon\u00eb e internetit Linotp tani \u00ebsht\u00eb e qasshme n\u00eb adres\u00ebn: <\/p>\n<pre><code class=\"plaintext\">&quot;&lt;b&gt;https&lt;\\\/b&gt;: \\\/\\\/IP_server\\\/manage&quot;<\/code><\/pre>\n<p>\nM\u00eb von\u00eb do t\u00eb flas p\u00ebr cil\u00ebsimet n\u00eb nd\u00ebrfaqen e internetit.<\/p>\n<p>Tani, gj\u00ebja m\u00eb e r\u00ebnd\u00ebsishme! Aktivizojm\u00eb FreeRadius dhe e lidhim me Linotp.<\/p>\n<p>Instalojm\u00eb FreeRadius dhe modulin e pun\u00ebs me LinOTP<\/p>\n<pre><code class=\"bash\"># apt-get install freeradius linotp-freeradius-perl<\/code><\/pre>\n<p>\nkrijojm\u00eb rezerv\u00eb p\u00ebr konfigurimet e klient\u00ebve dhe p\u00ebrdoruesve t\u00eb radiusit.<\/p>\n<pre><code class=\"bash\"># mv \/etc\/freeradius\/clients.conf  \/etc\/freeradius\/clients.old<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"bash\"># mv \/etc\/freeradius\/users  \/etc\/freeradius\/users.old<\/code><\/pre>\n<p>\nKrijojm\u00eb nj\u00eb skedar t\u00eb zbraz\u00ebt p\u00ebr klientin:<\/p>\n<pre><code class=\"bash\"># touch \/etc\/freeradius\/clients.conf<\/code><\/pre>\n<p>\nMegjithat\u00eb, redaktojm\u00eb skedarin ton\u00eb t\u00eb ri t\u00eb konfigurimit (konfigurimi i rezervuar mund t\u00eb p\u00ebrdoret si shembull)<\/p>\n<pre><code class=\"bash\"># nano \/etc\/freeradius\/clients.conf<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"plaintext\">client 192.168.188.0\/24 {\nsecret  = passwd # fjal\u00ebkalimi p\u00ebr lidhjen e klient\u00ebve\n}<\/code><\/pre>\n<p>\nM\u00eb pas krijojm\u00eb skedarin users:<\/p>\n<pre><code class=\"bash\"># touch \/etc\/freeradius\/users<\/code><\/pre>\n<p>\nRedaktojm\u00eb skedarin, duke i th\u00ebn\u00eb radiusit se do t\u00eb p\u00ebrdorim perl p\u00ebr autentifikim.<\/p>\n<pre><code class=\"bash\"># nano \/etc\/freeradius\/users<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"plaintext\">DEFAULT Auth-type := perl<\/code><\/pre>\n<p>\nPastaj redaktojm\u00eb skedarin \/etc\/freeradius\/modules\/perl<\/p>\n<pre><code class=\"bash\"># nano \/etc\/freeradius\/modules\/perl<\/code><\/pre>\n<p>\nNa nevojitet t\u00eb shkruajm\u00eb rrug\u00ebn n\u00eb skenarin perl linotp n\u00eb parametrin modul: <\/p>\n<pre><code class=\"plaintext\">Perl { .......\n.........\nmodule = \/usr\/lib\/linotp\/radius_linotp.pm<\/code><\/pre>\n<p>\n\u2026<br \/>\nM\u00eb pas krijojm\u00eb nj\u00eb skedar, n\u00eb t\u00eb cilin i themi nga cili (domain, baz\u00eb ose skedar) t\u00eb marrim t\u00eb dh\u00ebnat.<\/p>\n<pre><code class=\"bash\"># touch \/etc\/linotp2\/rlm_perl.ini<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"bash\"># nano \/etc\/linotp2\/rlm_perl.ini<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"plaintext\">URL=https:\/\/IP_i_serverit_ton\u00eb_LinOTP(192.168.X.X)\/validate\/simplecheck\nREALM=webusers1c\nRESCONF=LocalUser\nDebug=True\nSSL_CHECK=False<\/code><\/pre>\n<p>\nK\u00ebtu do t\u00eb ndalem pak m\u00eb shum\u00eb, pasi \u00ebsht\u00eb e r\u00ebnd\u00ebsishme:<\/p>\n<p>P\u00ebrshkrimi i plot\u00eb i skedarit me komente:<br \/>\n#IP of the linotp server (IP \u0430\u0434\u0440\u0435\u0441 \u043d\u0430\u0448\u0435\u0433\u043e LinOTP \u0441\u0435\u0440\u0432\u0435\u0440\u0430)<br \/>\nURL=https:\/\/172.17.14.103\/validate\/simplecheck<br \/>\n#\u041d\u0430\u0448\u0430 \u043e\u0431\u043b\u0430\u0441\u0442\u044c \u043a\u043e\u0442\u043e\u0440\u0443\u044e \u043c\u044b \u0441\u043e\u0437\u0434\u0430\u0434\u0438\u043c \u0432 \u0432\u0435\u0431 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0435 LinOTP.)<br \/>\nREALM=rearm1<br \/>\n#\u0418\u043c\u044f \u0433\u0440\u0443\u043f\u043f\u044b \u044e\u0437\u0432\u0435\u0440\u0435\u0439 \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0441\u043e\u0437\u0434\u0430\u0435\u0442\u0441\u044f \u0432 \u0432\u0435\u0431\u043c\u043e\u0440\u0434\u0435 LinOTP.<br \/>\nRESCONF=flat_file<br \/>\n#optional: comment out if everything seems to work fine<br \/>\nDebug=True<br \/>\n#optional: use this, if you have selfsigned certificates, otherwise comment out (SSL \u0435\u0441\u043b\u0438 \u043c\u044b \u0441\u043e\u0437\u0434\u0430\u0435\u043c \u0441\u0432\u043e\u0439 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442 \u0438 \u0445\u043e\u0442\u0438\u043c \u0435\u0433\u043e \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0442\u044c)<br \/>\nSSL_CHECK=False<\/p>\n<p>Pastaj krijojm\u00eb nj\u00eb skedar \/etc\/freeradius\/sites-available\/linotp<\/p>\n<pre><code class=\"bash\"># touch \/etc\/freeradius\/sites-available\/linotp<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"bash\"># nano \/etc\/freeradius\/sites-available\/linotp<\/code><\/pre>\n<p>\nDhe kopjojm\u00eb n\u00eb t\u00eb konfigurimin (nuk \u00ebsht\u00eb nevoja t\u00eb redaktojm\u00eb asgj\u00eb):<\/p>\n<pre><code class=\"plaintext\">authorize {\n#normalizes malformed client request before handed on to other modules (see '\/etc\/freeradius\/modules\/preprocess')\npreprocess\n#  N\u00ebse po p\u00ebrdorni lloje t\u00eb shumta realm, ndoshta\n#  d\u00ebshironi t\u00eb vendosni \"ignore_null = yes\" p\u00ebr t\u00eb gjith\u00eb ata.\n#  N\u00eb t\u00eb kund\u00ebrt, kur stili i par\u00eb i realm nuk p\u00ebrputhet,\n#  stilet e tjera nuk do t\u00eb kontrollohen.\n#lejon nj\u00eb list\u00eb realm (shih '\/etc\/freeradius\/modules\/realm')\nIPASS\n#kupton di\u00e7ka si USER@REALM dhe mund t\u00eb njoh\u00eb komponent\u00ebt (shih '\/etc\/freeradius\/modules\/realm')\nsuffix\n#kupton USERREALM dhe mund t\u00eb njoh\u00eb komponent\u00ebt (shih '\/etc\/freeradius\/modules\/realm')\nntdomain\n#  Lexoni skedarin 'users' p\u00ebr t\u00eb m\u00ebsuar rreth konfigurimeve speciale q\u00eb duhet t\u00eb p\u00ebrdoren p\u00ebr\n# p\u00ebrdoruesit e caktuar (shih '\/etc\/freeradius\/modules\/files')\nfiles\n# lejon q\u00eb autentifikimi t\u00eb skadoj\u00eb (shih '\/etc\/freeradius\/modules\/expiration')\nexpiration\n# lejon t\u00eb p\u00ebrcaktohen koh\u00ebt e sh\u00ebrbimit t\u00eb vlefsh\u00ebm (shih '\/etc\/freeradius\/modules\/logintime')\nlogintime\n# Nuk kemi radius_shortname_map!\npap\n}\n#k\u00ebtu moduli linotp perl thirret p\u00ebr p\u00ebrpunim t\u00eb m\u00ebtejsh\u00ebm\nauthenticate {\nperl\n}<\/code><\/pre>\n<p>\nM\u00eb pas do t\u00eb b\u00ebjm\u00eb nj\u00eb lidhje simbolike:<\/p>\n<pre><code class=\"bash\"># ln -s ..\/sites-available\/linotp \/etc\/freeradius\/sites-enabled<\/code><\/pre>\n<p>\nUn\u00eb personalisht shkat\u00ebrroj faqet default t\u00eb radius, por n\u00ebse ju nevojiten, mund t\u00eb ndryshoni konfigurimin e tyre ose t'i \u00e7aktivizoni.<\/p>\n<pre><code class=\"bash\"># rm \/etc\/freeradius\/sites-enabled\/default<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"bash\"># rm \/etc\/freeradius\/sites-enabled\/inner-tunnel<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"bash\"># service freeradius reload<\/code><\/pre>\n<p>\nTani kthehemi te nd\u00ebrfaqja web dhe do ta shqyrtojm\u00eb pak m\u00eb n\u00eb detaje:<br \/>\nN\u00eb k\u00ebndin e sip\u00ebrm t\u00eb djatht\u00eb klikoni LinOTP Config -&gt; UserIdResolvers -&gt; New<br \/>\nZgjidhni \u00e7far\u00eb d\u00ebshironi: LDAP (AD win, LDAP samba), apo SQL, apo p\u00ebrdorues lokal\u00eb t\u00eb sistemit Flatfile. <\/p>\n<p>Plot\u00ebsoni fushat e k\u00ebrkuara.<\/p>\n<p>M\u00eb pas krijojm\u00eb REALMS:<br \/>\nN\u00eb k\u00ebndin e sip\u00ebrm t\u00eb djatht\u00eb klikoni LinOTP Config -&gt; Realms -&gt; New. <br \/>\ndhe jepni emrin REALMS-it ton\u00eb, si dhe klikoni n\u00eb UserIdResolversin q\u00eb e krijuam m\u00eb par\u00eb.<\/p>\n<p>T\u00eb gjitha k\u00ebto t\u00eb dh\u00ebna nevojiten p\u00ebr freeRadius n\u00eb skedarin \/etc\/linotp2\/rlm_perl.ini, si\u00e7 e p\u00ebrmenda m\u00eb lart, prandaj, n\u00ebse nuk e keni redaktuar at\u00ebher\u00eb, b\u00ebni k\u00ebt\u00eb tani.<\/p>\n<p>T\u00eb gjitha serveri \u00ebsht\u00eb i konfiguruar.<\/p>\n<p>P\u00ebr t\u00eb ndryshuar konfigurimin, nuk \u00ebsht\u00eb e nevojshme t\u00eb d\u00ebrgoni trupin e k\u00ebrkes\u00ebs n\u00eb formatin<\/p>\n<p><b>Konfigurimi i LinOTP n\u00eb Debian 9<\/b>:<\/p>\n<p>Instalimi: <\/p>\n<pre><code class=\"bash\"># echo 'deb http:\/\/linotp.org\/apt\/debian stretch linotp' &gt; \/etc\/apt\/sources.list.d\/linotp.list <\/code><\/pre>\n<pre><code class=\"bash\"># apt-get install dirmngr<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"bash\"># apt-key adv --recv-keys 913DFF12F86258E5\n<\/code><\/pre>\n<pre><code class=\"bash\"># apt-get update<\/code><\/pre>\n<p><\/p>\n<pre><code class=\"bash\"># apt-get install mysql-server<\/code><\/pre>\n<p> (n\u00eb m\u00ebnyr\u00eb default, n\u00eb Debian 9 mysql (mariaDB) nuk k\u00ebrkon t\u00eb vendosni nj\u00eb fjal\u00ebkalim p\u00ebr rr\u00ebnj\u00ebn, natyrisht mund ta lini ashtu si\u00e7 \u00ebsht\u00eb, por n\u00ebse lexoni lajme, shpesh kjo \u00e7on n\u00eb \"epik failures\", prandaj ne do ta vendosim)<\/p>\n<pre><code class=\"bash\"># mysql -u root -p<\/code><\/pre>\n<pre><code class=\"bash\">use mysql;<\/code><\/pre>\n<pre><code class=\"bash\">UPDATE user SET Password = PASSWORD('k\u00ebtu_fjal\u00ebkalimi') WHERE User = 'root';\n<\/code><\/pre>\n<pre><code class=\"bash\">exit<\/code><\/pre>\n<pre><code class=\"bash\"># apt-get install linotp<\/code><\/pre>\n<pre><code class=\"bash\"># apt-get install linotp-adminclient-cli<\/code><\/pre>\n<pre><code class=\"bash\"># apt-get install python-ldap<\/code><\/pre>\n<pre><code class=\"bash\"># apt install freeradius<\/code><\/pre>\n<pre><code class=\"bash\"># nano \/etc\/freeradius\/3.0\/sites-enabled\/linotp<\/code><\/pre>\n<p>Ngjisim kodin (d\u00ebrguar nga JuriM, faleminderit p\u00ebr k\u00ebt\u00eb!):<\/p>\n<blockquote><p>server linotp {<br \/>\nlisten {<br \/>\n ipaddr = *<br \/>\n port = 1812<br \/>\n type = auth<br \/>\n}<br \/>\nlisten {<br \/>\n ipaddr = *<br \/>\n port = 1813<br \/>\n type = acct<br \/>\n}<br \/>\nauthorize { <br \/>\n preprocess<br \/>\n update { <br \/>\n &amp;control:Auth-Type := Perl<br \/>\n } <br \/>\n} <br \/>\nauthenticate {<br \/>\n Auth-Type Perl {<br \/>\n perl<br \/>\n }<br \/>\n}<br \/>\naccounting {<br \/>\n unix<br \/>\n}<br \/>\n}<\/p><\/blockquote>\n<p>Redaktoni \/etc\/freeradius\/3.0\/mods-enabled\/perl<\/p>\n<blockquote><p>perl {<br \/>\n filename = \/usr\/share\/linotp\/radius_linotp.pm<br \/>\n func_authenticate = authenticate<br \/>\n func_authorize = authorize<br \/>\n}<\/p><\/blockquote>\n<p>P\u00ebr fat t\u00eb keq, n\u00eb debian 9 biblioteka radius_linotp.pm nuk instalohet nga repo, prandaj do ta marrim nga github.<\/p>\n<pre><code class=\"bash\"># apt install git<\/code><\/pre>\n<pre><code class=\"bash\"># git clone https:\/\/github.com\/LinOTP\/linotp-auth-freeradius-perl<\/code><\/pre>\n<pre><code class=\"bash\"># cd linotp-auth-freeradius-perl\/<\/code><\/pre>\n<pre><code class=\"bash\"># cp radius_linotp.pm \/usr\/share\/linotp\/radius_linotp.pm<\/code><\/pre>\n<p>tani do t\u00eb riparojm\u00eb \/etc\/freeradius\/3.0\/clients.conf <\/p>\n<blockquote><p>client servers {<br \/>\n ipaddr = 192.168.188.0\/24<br \/>\n secret = fjal\u00ebkalimijuaj<br \/>\n}<\/p><\/blockquote>\n<p>tani do t\u00eb riparojm\u00eb nano \/etc\/linotp2\/rlm_perl.ini<\/p>\n<p>Ngjisim atje t\u00eb nj\u00ebjtin kod, si me instalimin n\u00eb debian 8 (p\u00ebrshkruar m\u00eb sip\u00ebr)<\/p>\n<p>n\u00eb thelb \u00ebsht\u00eb gjith\u00e7ka. (ende pa u testuar)<\/p>\n<p>Do t\u00eb l\u00eb m\u00eb posht\u00eb disa lidhje p\u00ebr konfigurimin e sistemeve, t\u00eb cilat shpesh k\u00ebrkojn\u00eb t\u00eb mbrohen me autentifikim me dy faktor\u00eb: <br \/>\nKonfigurimi i autentikimit me dy faktor\u00eb n\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/itsecforu.ru\/2017\/07\/28\/%D0%BA%D0%B0%D0%BA-%D0%B7%D0%B0%D1%89%D0%B8%D1%82%D0%B8%D1%82%D1%8C-apache2-%D1%81-%D0%BF%D0%BE%D0%BC%D0%BE%D1%89%D1%8C%D1%8E-linotp\/\">Apache2<\/a><\/noindex><\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/308988\/\">Konfigurimi me Cisco ASA<\/a><\/noindex>(aty p\u00ebrdoret nj\u00eb server tjet\u00ebr p\u00ebr gjenerimin e token\u00ebve, por konfigurimi i vet\u00eb ASA \u00ebsht\u00eb i nj\u00ebjt\u00eb).<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/panda\/blog\/337800\/\">VPN me autentikim me dy faktor\u00eb<\/a><\/noindex><\/p>\n<p>Configuration <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/270571\/\">autentikimi me dy faktor\u00eb n\u00eb ssh<\/a><\/noindex> (aty gjithashtu p\u00ebrdoret LinOTP) \u2013 faleminderit autorit. Atje gjithashtu mund t\u00eb gjeni gj\u00ebra interesante p\u00ebr konfigurimin e politikave t\u00eb LiOTP.<\/p>\n<p>Gjithashtu cms t\u00eb shum\u00eb faqeve mb\u00ebshtesin autentikimin me dy faktor\u00eb (P\u00ebr WordPress, LinOTP ka madje nj\u00eb modul t\u00eb ve\u00e7ant\u00eb n\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/LinOTP\/linotp-auth-wordpress\">github<\/a><\/noindex>), p\u00ebr shembull, n\u00ebse d\u00ebshironi t\u00eb b\u00ebni nj\u00eb seksion t\u00eb mbrojtur p\u00ebr punonj\u00ebsit e kompanis\u00eb suaj n\u00eb faqen tuaj korporate.<br \/>\nFakti i r\u00ebnd\u00ebsish\u00ebm! Mos e aktivizoni opsionin \"Google autenteficator\" p\u00ebr t\u00eb p\u00ebrdorur autentikimin e Google! QR kodi nuk lexohen k\u00ebshtu... (fakt i \u00e7uditsh\u00ebm)<\/p>\n<p>P\u00ebr shkruarjen e artikullit jan\u00eb p\u00ebrdorur informacionet nga artikujt e m\u00ebposht\u00ebm:<br \/>\n<noindex><a rel=\"nofollow\" href=\"https:\/\/itnan.ru\/post.php?c=1&amp;p=270571\">itnan.ru\/post.php?c=1&amp;p=270571<\/a><\/noindex><br \/>\n<noindex><a rel=\"nofollow\" href=\"http:\/\/www.digitalbears.net\/?p=469\">www.digitalbears.net\/?p=469<\/a><\/noindex> <\/p>\n<p>Faleminderit autor\u00ebve.<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/462523\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0421\u0435\u0433\u043e\u0434\u043d\u044f \u044f \u0445\u043e\u0447\u0443 \u043f\u043e\u0434\u0435\u043b\u0438\u0442\u044c\u0441\u044f, \u043a\u0430\u043a \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0441\u0435\u0440\u0432\u0435\u0440 \u0434\u0432\u0443\u0445\u0444\u0430\u043a\u0442\u043e\u0440\u043d\u043e\u0439 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438, \u0434\u043b\u044f \u0437\u0430\u0449\u0438\u0442\u044b \u043a\u043e\u0440\u043f\u043e\u0440\u0430\u0442\u0438\u0432\u043d\u043e\u0439 \u0441\u0435\u0442\u0438, \u0441\u0430\u0439\u0442\u043e\u0432, \u0441\u0435\u0440\u0432\u0438\u0441\u043e\u0432,ssh. \u041d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 \u0431\u0443\u0434\u0435\u0442 \u0440\u0430\u0431\u043e\u0442\u0430\u0442\u044c \u0441\u0432\u044f\u0437\u043a\u0430: LinOTP + FreeRadius. \u0417\u0430\u0447\u0435\u043c \u043e\u043d \u043d\u0430\u043c? \u042d\u0442\u043e \u043f\u043e\u043b\u043d\u043e\u0441\u0442\u044c\u044e \u0431\u0435\u0441\u043f\u043b\u0430\u0442\u043d\u043e\u0435, \u0443\u0434\u043e\u0431\u043d\u043e\u0435 \u0440\u0435\u0448\u0435\u043d\u0438\u0435, \u0432\u043d\u0443\u0442\u0440\u0438 \u0441\u0432\u043e\u0435\u0439 \u0441\u0435\u0442\u0438, \u043d\u0435 \u0437\u0430\u0432\u0438\u0441\u044f\u0449\u0435\u0435 \u043e\u0442 \u0441\u0442\u043e\u0440\u043e\u043d\u043d\u0438\u0445 \u043f\u0440\u043e\u0432\u0430\u0439\u0434\u0435\u0440\u043e\u0432. \u0414\u0430\u043d\u043d\u044b\u0439 \u0441\u0435\u0440\u0432\u0438\u0441 \u0432\u0435\u0441\u044c\u043c\u0430 \u0443\u0434\u043e\u0431\u0435\u043d, \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u043d\u0430\u0433\u043b\u044f\u0434\u0435\u043d, \u0432 \u043e\u0442\u043b\u0438\u0447\u0438\u0438 \u043e\u0442 \u0434\u0440\u0443\u0433\u0438\u0445 \u043e\u043f\u0435\u043d\u0441\u043e\u0440\u0441 \u043f\u0440\u043e\u0434\u0443\u043a\u0442\u043e\u0432, \u0430 \u0442\u0430\u043a \u0436\u0435 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u0435\u0442 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":27627,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-36873","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0421\u0435\u0433\u043e\u0434\u043d\u044f \u044f \u0445\u043e\u0447\u0443 \u043f\u043e\u0434\u0435\u043b\u0438\u0442\u044c\u0441\u044f, \u043a\u0430\u043a \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0441\u0435\u0440\u0432\u0435\u0440.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/server-dvuhfaktornoj-avtorizatsii-linotp\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0421\u0435\u0440\u0432\u0435\u0440 \u0434\u0432\u0443\u0445\u0444\u0430\u043a\u0442\u043e\u0440\u043d\u043e\u0439 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438 LinOTP | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0421\u0435\u0433\u043e\u0434\u043d\u044f \u044f \u0445\u043e\u0447\u0443 \u043f\u043e\u0434\u0435\u043b\u0438\u0442\u044c\u0441\u044f, \u043a\u0430\u043a \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0441\u0435\u0440\u0432\u0435\u0440.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/server-dvuhfaktornoj-avtorizatsii-linotp\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:14:26+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:14:26+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Serveri i autentikimit me dy faktor\u00eb LinOTP | ProHoster","description":"Sot d\u00ebshiroj t\u00eb ndaj si t\u00eb konfiguroj serverin.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/server-dvuhfaktornoj-avtorizatsii-linotp","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0421\u0435\u0440\u0432\u0435\u0440 \u0434\u0432\u0443\u0445\u0444\u0430\u043a\u0442\u043e\u0440\u043d\u043e\u0439 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438 LinOTP | ProHoster","og:description":"\u0421\u0435\u0433\u043e\u0434\u043d\u044f \u044f \u0445\u043e\u0447\u0443 \u043f\u043e\u0434\u0435\u043b\u0438\u0442\u044c\u0441\u044f, \u043a\u0430\u043a \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0441\u0435\u0440\u0432\u0435\u0440.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/server-dvuhfaktornoj-avtorizatsii-linotp","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:14:26+00:00","article:modified_time":"2019-10-31T19:14:26+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"36873","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-22 05:08:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:37:23","updated":"2026-01-22 05:08:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/36873","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=36873"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/36873\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/27627"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=36873"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=36873"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=36873"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}