Comment on The OpenSSH Bug That Wasn'tComments−feld11yThankfully my use of PAM is for 2FA with SSH when I don't have my key. So they wouldn't have been successful in pulling off a bruteforce anyway. But it's annoying that their attempts weren't being limited as it can waste resources...−currysausage11yYou wouldn't have a working config at hand for requiring TOTP (Google Authenticator) only for OpenSSH password logins on Debian, would you?
Comments
Thankfully my use of PAM is for 2FA with SSH when I don't have my key. So they wouldn't have been successful in pulling off a bruteforce anyway. But it's annoying that their attempts weren't being limited as it can waste resources...
You wouldn't have a working config at hand for requiring TOTP (Google Authenticator) only for OpenSSH password logins on Debian, would you?