After enabling the custom password prompt via the setting, "pam.password.enter.mesg: Enter AD Password:"
, in the /etc/centrifydc/centrifydc.conf
file, the custom prompt does not appear when logging in via SSH. The custom prompt does appear when doing a non SSH authentication. (ie direct GUI login, dzdo/sudo)Cause:
In order for the custom prompt to display, the ChallengeResponseAuthentication
setting in the sshd_config
file needs to be set to yes.Resolution:
1. Edit the sshd_config
file. For stock ssh, the path is /etc/ssh/sshd_config
2. Make sure that the ChallengeResponseAuthentication
set to yes
3. Save the file.
4. Restart the sshd service.For example on RHEL 7.x, the following command could be used:
systemctl restart sshd
Centrify Enabled OpenSSH has the ChallengeResponseAuthentication setting set to yes by default.