Hello.
Is it possible to use 2FA when connecting to “Desktop Sharing” ?
Is it possible to implement this via pam.d ?
For example, for the cockpit I added the line “auth required pam_google_authenticator.so” and after that, after entering the login and password, it asks for the 2FA code.
/etc/pam.d/cockpit
We could certainly have a pam_gnome_remote_desktop.so (or just add it to pam_gdm.so) that grabs the username and password from the system gnome-remote-desktop and passes it along to the other pam modules in a new gdm-remote-desktop pam service. There’s no reason we couldn’t get the username and password funneled through.
Further along in that thread, someone comments, “… due to NTLM being unsuitable for PAM and co. due to relying on NTLM hashes …”.
I’ve only quickly skimmed the thread, but my impression is that GNOME Remote Desktop does not (currently) work with PAM. But it looks like there might be some efforts along those lines that are in the works.
I looked again and there might still be some hope if you can switch it to use VNC instead of RDP. It looks like VNC support is still compiled into gnome-remote-desktop (I’m still on Fedora Linux 40).
$ man xvnc | grep -A 2 pam
-pam_service name, -PAMService name
PAM service name to use when authentication users using any of the "Plain" se‐
curity types. Default is vnc.
So if you can get GNOME Desktop Sharing to use VNC, there might be a way. It isn’t something I’ve ever attempted. If you succeed, let us know how you did it with a follow-up post here.
hmm, thanks but no)
I had a lot of headaches days when I was looking for a modern, normal option to connect to the remote desktop of Wayland without using third-party clients and dinosaur programs)
I will stay with the current built-in solution of RDP.
I don’t like VNC at all, it’s slow, poor quality and most often requires x11, even if VNC will uses Wayland, I still won’t agree to it)