Direct per host
- PAM RADIUS module points at the Mideye Server
- Protects SSH, sudo, and console via PAM
- Simplest setup for a handful of hosts
SSH is the front door to your infrastructure, and admin accounts are the first target. Mideye adds a second factor to SSH, sudo, and console logins through standard PAM and RADIUS, with nothing installed beyond the PAM module.
Integration patterns
All three use the same standard components: the PAM RADIUS module on the host, and the Mideye Server as the RADIUS authentication server.
Privileged access
NIS2 expects strong authentication on remote and privileged access, and SSH to production servers is both. Mideye covers it with individually approved logins, and Assisted Login adds four-eyes approval where a single admin should not act alone. See the compliance mapping for the full picture.
FAQ
Configure the PAM RADIUS module on the host and point it at the Mideye Server. SSH password logins then require a second factor: a Mideye+ push, an SMS one-time code, or a hardware-token OTP. The same PAM stack covers sudo and console logins if you want them protected too.
PAM-based MFA applies to PAM-backed authentication such as passwords and keyboard-interactive logins. Pure public-key logins bypass PAM authentication by default; sshd can be configured to require both the key and a PAM-based second factor for a belt-and-braces setup.
Yes. A common pattern is a central FreeRADIUS proxy: hosts point their PAM RADIUS module at the proxy, and the proxy forwards authentication to the Mideye Server. One integration point, any number of hosts.
From a single bastion host to a full fleet behind a FreeRADIUS proxy, we will map the setup with your team.
We use cookies and analytics to improve your experience and understand how our site is used.Privacy Policy