cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1547
Views
2
Helpful
4
Replies

Access on offline linux

Felipe_Cecatto
Level 1
Level 1

Hi! I’ve been testing Pam DUO on my CentOS 8 and I would like to know if is there any support for offline linux systems or if are there any sort of configurations that could handle this offline situations?

4 Replies 4

Amy2
Level 5
Level 5

Hi @Felipe_Cecatto, and welcome to the Duo Community! I understand that you’re wondering about Duo support for offline authentication with Linux.

We do not currently support offline for Linux. However, we continue to track customer demand for this feature, so I encourage you to contact either Duo Support, or your Customer Success Manager or Account Executive if you are a Duo Care customer, to add your name to the official feature request for this. Thank you!

joseph.gerdeman
Level 1
Level 1

I have contacted Duo support twice for this feature. It getting to the point where I may have to consider finding another provider for 2FA… It’s unfortunate because I have really enjoyed Duo’s feature set and support thus far.

mmic-bjohnson
Level 1
Level 1

The lack of offline support for Linux is proving to be a real thorn in our side, too.

We use the "fail-closed" approach, since not doing so is certifiably insane from a security standpoint (since somebody can merely disconnect from the network to completely bypass DUO otherwise), which prevents us from logging into machines that are in "lights-out" mode.

Oracle Database Appliances, for example, utilize ILOM for innumerable administrative tasks, and we're unable to log into them when failing closed.

We, too, will need to look for another product if this cannot be implemented in the relatively near future.

@mmic-bjohnson Have you contacted a Duo account manager, customer success manager, or Duo Support to upvote the feature request for offline authentication in Duo Unix? Our product managers evaluate feature request engagement when making prioritization decisions.

If you do reach out, be sure to mention the particular *nix distros you use, as it looks like they're interested in that information.

Duo, not DUO.
Quick Links