Passwords & 2FA
Strong password policies and two-factor authentication (2FA) are two critical lines of defense for protecting user accounts. This article explains how to configure password policies and enable two-factor authentication on Ubuntu 26.04.
Strong Password Policies
Installing Password Quality Check Tools
sudo apt install libpam-pwqualityConfiguring Password Policies
Edit the password quality configuration file:
sudo nano /etc/security/pwquality.confCommon configuration options:
# Minimum password length
minlen = 12
# Minimum number of character classes (uppercase, lowercase, digits, special characters)
minclass = 3
# Minimum number of uppercase letters
ucredit = -1
# Minimum number of lowercase letters
lcredit = -1
# Minimum number of digits
dcredit = -1
# Minimum number of special characters
ocredit = -1
# Number of characters that must differ from the old password
difok = 5
# Prevent using the username as part of the password
usercheck = 1
# Limit consecutive identical characters
maxrepeat = 3
# Limit consecutive characters of the same class
maxclassrepeat = 4
# Reject palindrome passwords
palindrome = 1
# Reject common dictionary words
dictcheck = 1Configuring Password Expiration Policies
# Edit global settings
sudo nano /etc/login.defs# Maximum password age (days)
PASS_MAX_DAYS 90
# Minimum password age (days)
PASS_MIN_DAYS 7
# Password expiration warning days
PASS_WARN_AGE 14
# Minimum password length
PASS_MIN_LEN 12Setting Password Policies for Specific Users
# Set maximum password age to 90 days
sudo chage -M 90 username
# Set minimum password age to 7 days
sudo chage -m 7 username
# Set 14-day expiration warning
sudo chage -W 14 username
# Immediately require password change
sudo chage -d 0 username
# View user password policy
sudo chage -l usernamePassword History (Preventing Reuse of Old Passwords)
Edit the PAM configuration:
sudo nano /etc/pam.d/common-passwordFind the line containing pam_unix.so and add the remember parameter:
password [success=1 default=ignore] pam_unix.so obscure use_authtok try_first_pass yescrypt remember=12This prevents users from reusing any of their last 12 passwords.
Password Management Tools
Command-Line Password Manager: pass
# Install
sudo apt install pass
# Initialize (requires a GPG key)
gpg --gen-key
pass init "your-gpg-id"
# Add a password
pass insert email/gmail
pass insert -m server/production # multi-line mode
# View a password
pass email/gmail
# Generate a random password
pass generate web/newsite 20
# List all passwords
pass ls
# Search
pass find gmailUsing KeePassXC
# Install
sudo apt install keepassxc
# Or use snap
sudo snap install keepassxcKeePassXC is a feature-rich graphical password manager supporting:
- Encrypted password database storage
- Auto-fill passwords
- TOTP two-factor authentication
- Browser integration
- SSH Agent integration
Google Authenticator (TOTP 2FA)
Installation and Initialization
# Install the PAM module
sudo apt install libpam-google-authenticator
# Run initialization as a regular user
google-authenticatorRecommended choices during initialization:
Do you want authentication tokens to be time-based (y/n) y
# Choose y for time-based tokens (TOTP)
# A QR code will be displayed -- scan it with an authenticator app
# Recommended apps: Google Authenticator, Authy, Microsoft Authenticator, FreeOTP
Do you want me to update your "/home/user/.google_authenticator" file? (y/n) y
Do you want to disallow multiple uses of the same authentication token? (y/n) y
# Choose y to prevent token replay
By default, a new token is generated every 30 seconds.
Do you want to change the size of the time skew window? (y/n) n
Do you want to enable rate-limiting? (y/n) y
# Choose y to limit attempt frequencyBe sure to save the displayed emergency backup codes.
Enabling 2FA for Local Login
sudo nano /etc/pam.d/common-authAdd at the end of the file:
auth required pam_google_authenticator.so nullokThe nullok parameter allows users who haven’t configured 2FA to log in normally. Remove it once all users are set up.
Enabling 2FA for SSH Login
# Edit PAM SSH configuration
sudo nano /etc/pam.d/sshdAdd:
auth required pam_google_authenticator.soEdit the SSH server configuration:
sudo nano /etc/ssh/sshd_config# Enable keyboard-interactive authentication
KbdInteractiveAuthentication yes
# Require key + TOTP dual authentication
AuthenticationMethods publickey,keyboard-interactiveRestart SSH:
sudo systemctl restart sshEnabling 2FA for sudo
sudo nano /etc/pam.d/sudoAdd after @include common-auth:
auth required pam_google_authenticator.soThis requires a verification code every time sudo is used.
Hardware Security Keys (FIDO2/U2F)
Supported Devices
Ubuntu 26.04 supports FIDO2/U2F security keys, such as:
- YubiKey 5 Series
- Google Titan Security Key
- Feitian ePass FIDO
- SoloKeys
Installation and Configuration
# Install the PAM U2F module
sudo apt install libpam-u2f
# Install management tools
sudo apt install pamu2fcfgRegistering a Security Key
# Create configuration directory
mkdir -p ~/.config/Yubico
# Register the first key (insert the security key and touch it)
pamu2fcfg > ~/.config/Yubico/u2f_keys
# Register a backup key (append mode)
pamu2fcfg -n >> ~/.config/Yubico/u2f_keysEnabling Security Key for sudo
sudo nano /etc/pam.d/sudoAdd before @include common-auth:
auth sufficient pam_u2f.soEnabling Security Key for Login
sudo nano /etc/pam.d/gdm-passwordAdd:
auth required pam_u2f.soEnabling Security Key for SSH
OpenSSH 8.2+ natively supports FIDO2 keys:
# Generate a FIDO2 SSH key
ssh-keygen -t ed25519-sk -C "your_email@example.com"
# Or use a resident key (does not require the corresponding hardware key for the public key in .ssh/authorized_keys on the server)
ssh-keygen -t ed25519-sk -O resident -C "your_email@example.com"
# Deploy the public key to the server
ssh-copy-id -i ~/.ssh/id_ed25519_sk.pub user@serverPAM Authentication Flow Configuration
Understanding PAM Control Flags
| Flag | Description |
|---|---|
required | Must succeed; continues checking other modules on failure |
requisite | Must succeed; returns immediately on failure |
sufficient | Passes immediately on success; continues checking on failure |
optional | Success or failure does not affect the final result |
Multi-Factor Authentication Combination Examples
Password + TOTP:
# /etc/pam.d/common-auth
auth required pam_unix.so
auth required pam_google_authenticator.soPassword + Security Key (security key optional):
auth required pam_unix.so
auth sufficient pam_u2f.so
auth required pam_google_authenticator.soAccount Lockout Policy
Configuring Failed Login Lockout
sudo nano /etc/pam.d/common-authAdd at the beginning of the file:
auth required pam_faillock.so preauth silent deny=5 unlock_time=900
auth [default=die] pam_faillock.so authfail deny=5 unlock_time=900sudo nano /etc/pam.d/common-accountAdd:
account required pam_faillock.soParameter descriptions:
deny=5: Lock after 5 failuresunlock_time=900: Lock for 900 seconds (15 minutes)
Managing Lockout Status
# View a user's failed attempts
sudo faillock --user username
# Unlock a user
sudo faillock --user username --reset
# View all locked users
sudo faillockBest Practices
- Use passwords of 12 characters or more, including uppercase, lowercase, digits, and special characters.
- Use a different password for each service and use a password manager.
- Enable 2FA on all services that support it.
- Save backup codes and recovery keys securely.
- Register multiple security keys as backups.
- Change passwords periodically, but not too frequently (every 90 days is sufficient).
- Monitor failed login records to detect brute-force attacks early.