Giter Club home page Giter Club logo

Comments (4)

DuoKristina avatar DuoKristina commented on July 18, 2024

Hi @elitegoodguy,

What version of Duo Unix did you try this with? The most recent release?

Also, to make sure I understand your expectations, are you specifying a groupname or a !groupname?

groups=foo means only apply Duo 2FA to members of foo; users whose group membership does not include foo will bypass 2FA.

from duo_unix.

elitegoodguy avatar elitegoodguy commented on July 18, 2024

Sorry left that out... It's login_duo 1.12.0

That is correct I attempted groups=users,!wheel

For all users except for those in the wheel group. Maybe put the AD group that I am in? groups="Domain Users",!wheel ? I have not tried that yet.

from duo_unix.

elitegoodguy avatar elitegoodguy commented on July 18, 2024

I resolved it It was that it was allowing them through regardless of the group. You can either be included or excluded... If you are not in any group that's included you're automatically considered excluded and do not need to have 2fa. I found that once I added in a valid group name that I am 100% included then it works.

This works just fine for me because it says everyone on the domain needs duo 2fa to get into this server except for root. My login rules will lock it down further to restrict it to a certain group and allow root to login local only.

groups=domain\ users,!root

from duo_unix.

AaronAtDuo avatar AaronAtDuo commented on July 18, 2024

@elitegoodguy Looks like you go this working to your satisfaction, so I'll close this out. Let us know if you run into any other issues, and thanks for using Duo!

from duo_unix.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.