2FA for "Desktop Sharing"

Hello.
Is it possible to use 2FA when connecting to “Desktop Sharing” ?
Is it possible to implement this via pam.d ?

For example, for the cockpit I added the line “auth required pam_google_authenticator.so” and after that, after entering the login and password, it asks for the 2FA code.
/etc/pam.d/cockpit

#%PAM-1.0
auth required pam_sepermit.so
auth substack password-auth
auth required pam_google_authenticator.so
auth include postlogin
auth optional pam_ssh_add.so


The pam.d directory contains these files:

atd
chfn
chsh
cockpit
config-util
crond
fingerprint-auth
login
other
passwd
password-auth
postlogin
remote
runuser
runuser-l
smartcard-auth
sshd
sssd-shadowutils
su
sudo
sudo-i
su-l
system-auth
vlock

but which one of them refers to “Desktop Sharing” I don’t know.

I found the following comment in the gnome remote desktop repo:

We could certainly have a pam_gnome_remote_desktop.so (or just add it to pam_gdm.so) that grabs the username and password from the system gnome-remote-desktop and passes it along to the other pam modules in a new gdm-remote-desktop pam service. There’s no reason we couldn’t get the username and password funneled through.

Further along in that thread, someone comments, “… due to NTLM being unsuitable for PAM and co. due to relying on NTLM hashes …”.

I’ve only quickly skimmed the thread, but my impression is that GNOME Remote Desktop does not (currently) work with PAM. But it looks like there might be some efforts along those lines that are in the works.

Okay, it’s a pity of course that this can’t be done.

I looked again and there might still be some hope if you can switch it to use VNC instead of RDP. It looks like VNC support is still compiled into gnome-remote-desktop (I’m still on Fedora Linux 40).

$ ldd /usr/libexec/gnome-remote-desktop-daemon | grep vnc
	libvncserver.so.1 => /lib64/libvncserver.so.1 (0x00007f53a477e000)

TigerVNC has a -pam_service option:

$ man xvnc | grep -A 2 pam
       -pam_service name, -PAMService name
              PAM service name to use when authentication users using any of the "Plain" se‐
              curity types. Default is vnc.

So if you can get GNOME Desktop Sharing to use VNC, there might be a way. It isn’t something I’ve ever attempted. If you succeed, let us know how you did it with a follow-up post here. :slightly_smiling_face:

hmm, thanks but no)
I had a lot of headaches days when I was looking for a modern, normal option to connect to the remote desktop of Wayland without using third-party clients and dinosaur programs)
I will stay with the current built-in solution of RDP.

I don’t like VNC at all, it’s slow, poor quality and most often requires x11, even if VNC will uses Wayland, I still won’t agree to it)