Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-7087: FTP hangs or asks for MFA if user is MFA enabled

29 June,16 at 09:21 PM


Applies to: 

DirectControl 5.3.0 and 5.3.1 on all supported Unix platforms.


Question: 

Why do FTP sessions fail to start when the user is required to use MFA? 
 
[root@aix61v2 15:20:05]ftp localhost
Connected to localhost.
220 aix61v2 FTP server (Version 4.2 Wed Oct 1 09:40:05 CDT 2008) ready.
Name (localhost:root): mac
331 Password required for mac.
Password:

^^ process hangs here.

Answer: 

Default FTP servers used by Unix operation systems do not support the second prompt from PAM. To workaround this issue, please use the pam.mfa.program.ignore parameter in /etc/centrifydc/centrifydc.conf 
Adding this parameter will prevent adclient from asking for MFA through PAM. 

AIX

pam.mfa.program.ignore: ftpd

Solaris
pam.mfa.program.ignore: proftpd

HPUX:
pam.mfa.program.ignore: ftpd
 

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.