Skip to Content

Passwords & 2FA

Strong password policies and two-factor authentication (2FA) are two critical lines of defense for protecting user accounts. This article explains how to configure password policies and enable two-factor authentication on Ubuntu 26.04.

Strong Password Policies

Installing Password Quality Check Tools

sudo apt install libpam-pwquality

Configuring Password Policies

Edit the password quality configuration file:

sudo nano /etc/security/pwquality.conf

Common configuration options:

# Minimum password length minlen = 12 # Minimum number of character classes (uppercase, lowercase, digits, special characters) minclass = 3 # Minimum number of uppercase letters ucredit = -1 # Minimum number of lowercase letters lcredit = -1 # Minimum number of digits dcredit = -1 # Minimum number of special characters ocredit = -1 # Number of characters that must differ from the old password difok = 5 # Prevent using the username as part of the password usercheck = 1 # Limit consecutive identical characters maxrepeat = 3 # Limit consecutive characters of the same class maxclassrepeat = 4 # Reject palindrome passwords palindrome = 1 # Reject common dictionary words dictcheck = 1

Configuring Password Expiration Policies

# Edit global settings sudo nano /etc/login.defs
# Maximum password age (days) PASS_MAX_DAYS 90 # Minimum password age (days) PASS_MIN_DAYS 7 # Password expiration warning days PASS_WARN_AGE 14 # Minimum password length PASS_MIN_LEN 12

Setting Password Policies for Specific Users

# Set maximum password age to 90 days sudo chage -M 90 username # Set minimum password age to 7 days sudo chage -m 7 username # Set 14-day expiration warning sudo chage -W 14 username # Immediately require password change sudo chage -d 0 username # View user password policy sudo chage -l username

Password History (Preventing Reuse of Old Passwords)

Edit the PAM configuration:

sudo nano /etc/pam.d/common-password

Find the line containing pam_unix.so and add the remember parameter:

password [success=1 default=ignore] pam_unix.so obscure use_authtok try_first_pass yescrypt remember=12

This prevents users from reusing any of their last 12 passwords.

Password Management Tools

Command-Line Password Manager: pass

# Install sudo apt install pass # Initialize (requires a GPG key) gpg --gen-key pass init "your-gpg-id" # Add a password pass insert email/gmail pass insert -m server/production # multi-line mode # View a password pass email/gmail # Generate a random password pass generate web/newsite 20 # List all passwords pass ls # Search pass find gmail

Using KeePassXC

# Install sudo apt install keepassxc # Or use snap sudo snap install keepassxc

KeePassXC is a feature-rich graphical password manager supporting:

  • Encrypted password database storage
  • Auto-fill passwords
  • TOTP two-factor authentication
  • Browser integration
  • SSH Agent integration

Google Authenticator (TOTP 2FA)

Installation and Initialization

# Install the PAM module sudo apt install libpam-google-authenticator # Run initialization as a regular user google-authenticator

Recommended choices during initialization:

Do you want authentication tokens to be time-based (y/n) y # Choose y for time-based tokens (TOTP) # A QR code will be displayed -- scan it with an authenticator app # Recommended apps: Google Authenticator, Authy, Microsoft Authenticator, FreeOTP Do you want me to update your "/home/user/.google_authenticator" file? (y/n) y Do you want to disallow multiple uses of the same authentication token? (y/n) y # Choose y to prevent token replay By default, a new token is generated every 30 seconds. Do you want to change the size of the time skew window? (y/n) n Do you want to enable rate-limiting? (y/n) y # Choose y to limit attempt frequency

Be sure to save the displayed emergency backup codes.

Enabling 2FA for Local Login

sudo nano /etc/pam.d/common-auth

Add at the end of the file:

auth required pam_google_authenticator.so nullok

The nullok parameter allows users who haven’t configured 2FA to log in normally. Remove it once all users are set up.

Enabling 2FA for SSH Login

# Edit PAM SSH configuration sudo nano /etc/pam.d/sshd

Add:

auth required pam_google_authenticator.so

Edit the SSH server configuration:

sudo nano /etc/ssh/sshd_config
# Enable keyboard-interactive authentication KbdInteractiveAuthentication yes # Require key + TOTP dual authentication AuthenticationMethods publickey,keyboard-interactive

Restart SSH:

sudo systemctl restart ssh

Enabling 2FA for sudo

sudo nano /etc/pam.d/sudo

Add after @include common-auth:

auth required pam_google_authenticator.so

This requires a verification code every time sudo is used.

Hardware Security Keys (FIDO2/U2F)

Supported Devices

Ubuntu 26.04 supports FIDO2/U2F security keys, such as:

  • YubiKey 5 Series
  • Google Titan Security Key
  • Feitian ePass FIDO
  • SoloKeys

Installation and Configuration

# Install the PAM U2F module sudo apt install libpam-u2f # Install management tools sudo apt install pamu2fcfg

Registering a Security Key

# Create configuration directory mkdir -p ~/.config/Yubico # Register the first key (insert the security key and touch it) pamu2fcfg > ~/.config/Yubico/u2f_keys # Register a backup key (append mode) pamu2fcfg -n >> ~/.config/Yubico/u2f_keys

Enabling Security Key for sudo

sudo nano /etc/pam.d/sudo

Add before @include common-auth:

auth sufficient pam_u2f.so

Enabling Security Key for Login

sudo nano /etc/pam.d/gdm-password

Add:

auth required pam_u2f.so

Enabling Security Key for SSH

OpenSSH 8.2+ natively supports FIDO2 keys:

# Generate a FIDO2 SSH key ssh-keygen -t ed25519-sk -C "your_email@example.com" # Or use a resident key (does not require the corresponding hardware key for the public key in .ssh/authorized_keys on the server) ssh-keygen -t ed25519-sk -O resident -C "your_email@example.com" # Deploy the public key to the server ssh-copy-id -i ~/.ssh/id_ed25519_sk.pub user@server

PAM Authentication Flow Configuration

Understanding PAM Control Flags

FlagDescription
requiredMust succeed; continues checking other modules on failure
requisiteMust succeed; returns immediately on failure
sufficientPasses immediately on success; continues checking on failure
optionalSuccess or failure does not affect the final result

Multi-Factor Authentication Combination Examples

Password + TOTP:

# /etc/pam.d/common-auth auth required pam_unix.so auth required pam_google_authenticator.so

Password + Security Key (security key optional):

auth required pam_unix.so auth sufficient pam_u2f.so auth required pam_google_authenticator.so

Account Lockout Policy

Configuring Failed Login Lockout

sudo nano /etc/pam.d/common-auth

Add at the beginning of the file:

auth required pam_faillock.so preauth silent deny=5 unlock_time=900 auth [default=die] pam_faillock.so authfail deny=5 unlock_time=900
sudo nano /etc/pam.d/common-account

Add:

account required pam_faillock.so

Parameter descriptions:

  • deny=5: Lock after 5 failures
  • unlock_time=900: Lock for 900 seconds (15 minutes)

Managing Lockout Status

# View a user's failed attempts sudo faillock --user username # Unlock a user sudo faillock --user username --reset # View all locked users sudo faillock

Best Practices

  1. Use passwords of 12 characters or more, including uppercase, lowercase, digits, and special characters.
  2. Use a different password for each service and use a password manager.
  3. Enable 2FA on all services that support it.
  4. Save backup codes and recovery keys securely.
  5. Register multiple security keys as backups.
  6. Change passwords periodically, but not too frequently (every 90 days is sufficient).
  7. Monitor failed login records to detect brute-force attacks early.
Last updated on