Project ID: 118


Extremely unstable test field for FreeIPA two factor authentication. Read for design and details.

Installation Instructions

  1. Make sure to have updated Fedora 20, with updates-testing enabled as well as updates repo.

  2. Install packages (freeipa-server and sssd, krb5 and 389-ds-base and the rest will be pulled in), it is OK to just update, no need to re-install.

  3. SSSD in updates-testing for Fedora 20 enables FAST by default for IPA provider.

  4. SELinux policies should allow all needed transitions. If something still fails, switch to permissive and make sure to file bugs against FreeIPA:

    # setenforce 0
  5. Restart FreeIPA (systemctl restart ipa)

  6. Web UI now includes full support for OTP. You can create users and set them to use OTP, users can create own OTP tokens in self-service.

  7. When user has no OTP token but asked to login with OTP, until first token is created, user will be allowed to login with password.

  8. You can specify multiple auth types (or in Web UI):

    ipa user-mod user --user-auth-type={password,otp}
  9. Use FreeOTP (in Google Play) as a completely open source soft token.

  10. Currently password change in Web UI does not work if OTP token is enabled for the user.

Active Releases

The following unofficial repositories are provided as-is by owner of this project. Contact the owner directly for bugs or issues (IE: not bugzilla).

Release Architectures Repo Download

* Total number of packages downloaded in the last seven days.

Last Build

No builds...

Quick Enable

#> dnf copr enable abbra/freeipa-otp-unstable
More info about enabling Copr repositories

Other Actions