---
title: "Securing SSH Access with YubiKey: A Step-by-Step Guide to Two-Factor Authentication"
description: Enhance your SSH login security with YubiKey 2FA. Learn how to configure and use this robust method for added protection.
image: https://blog.rheinwerk-computing.com/hubfs/2FA%20with%20YubiKey.png
---

[![Rheinwerk Computing Logo](https://blog.rheinwerk-computing.com/hubfs/computing_logo-header.svg)](https://blog.rheinwerk-computing.com/) [Blog](https://blog.rheinwerk-computing.com)

- Books 
    - Get an overview of our wide selection of books on every relevant computing topic. 
          - [General Computing](https://www.sap-press.com/rheinwerk-computing/general-computing/)
          - [DevOps](https://www.sap-press.com/rheinwerk-computing/devops/)
          - [Programming Languages](https://www.sap-press.com/rheinwerk-computing/programming-languages/)
          - [Security](https://www.sap-press.com/rheinwerk-computing/security/)
          - [Software Development](https://www.sap-press.com/rheinwerk-computing/software-development/)
- Book Subscription 
    - Get unlimited access to all Rheinwerk Computing books! 
          - [Programming Subscription](https://sap-press.com/subscriptions/)

[Cybersecurity](https://blog.rheinwerk-computing.com/tag/cybersecurity)

# Securing SSH Access with YubiKey: A Step-by-Step Guide to Two-Factor Authentication

![Rheinwerk Computing](https://blog.rheinwerk-computing.com/hubfs/RW-logo-300x300.png)  by [Rheinwerk Computing](https://blog.rheinwerk-computing.com/author/rheinwerk-computing)

Learn about enhancing your SSH login security with YubiKey, a robust two-factor authentication method using a USB security token for one-time password generation and seamless integration.

 

Instead of codes generated by a smartphone, you can use a *security token*, which looks like a USB flash drive, as a second factor in SSH login. Among other functions, the device simulates keyboard input as soon as you press a touch-sensitive button. (The computer to which the security token is connected regards the token as a USB keyboard.)

 

The string (which is intended as a *one-time password* \[OTP\]) consists of two parts: The first 12 characters always remain the same and are, in a sense, the public part of the key. The remaining characters are the actual password, which changes every time.

 

The string is generated based on a nonreadable key. Together with a symmetric key, which you can determine on the token manufacturer’s website, it’s possible to check whether a string matches your token.

 

We conducted our tests with the YubiKey 5 NFC model from Yubico. Comparable devices are also available from other providers, including Google (Titan Security Key).

 

To enable verification of your YubiKey one-time passwords, you’ll need to generate a key at [*https://upgrade.yubico.com/getapikey*](https://upgrade.yubico.com/getapikey). For this purpose, you must enter your email address and fill in another input field by touching the YubiKey. The website responds with an ID and the API key, both of which you’ll need for the configuration of the YubiKey PAM module.

## PAM Configuration

On the machine running the SSH server, you must install the yubico PAM module. For Ubuntu, Yubico provides a package source:

 

`add-apt-repository ppa:yubico/stable`

`apt update`

`apt install libpam-yubico`

 

For RHEL, there’s a suitable package in the EPEL package source:

 

`dnf install pam_yubico`

 

To make sure the PAM module will be used, you must add the following statement to the end of */etc/pam.d/sshd* in a single line and without the \\ character:

 

`# at the end of /etc/pam.d/sshd in a long line`

`auth required pam_yubico.so id=12345 key=apikey \`

`   authfile=/etc/yubikey-mappings mode=client`

 

Here, you replace 12345 with your ID and apikey with your API key. Both data originate from the website mentioned previously.

 

## Mapping File

For all users whose logins are to be verified via YubiKey, the Linux account name and the first 12 characters of the one-time password must be specified in a mapping file. You specify the location of this file during the PAM configuration:

 

`# File /etc/yubikey-mappings`

`michael:ccccnixgfask`

`peter:ccgsdkgalfja`

`...`

 

Make sure that you really specify exactly 12 characters and that you don’t include any spaces before or after the colon! If you have multiple YubiKeys that you choose to use, the syntax is name:key1:key2:key3 and so on.

 

## SSH Configuration

Finally, you only need to adjust the configuration of the SSH server so that the new authentication procedure will actually be used. You can do this in a similar way to using [Google Authenticator](https://blog.rheinwerk-computing.com/securing-linux-using-2fa-with-google-authenticator). In the following listing, however, 2FA is not activated in general, but only for selected accounts:

 

`# /etc/ssh/sshd_config`

`# Change existing setting`

`UsePAM                               yes`

`ChallengeResponseAuthentication      yes`

 

`# add at the end`

`Match User michael,peter`

`   AuthenticationMethods keyboard-interactive`

 

Before you activate the changes via systemctl reload sshd and then try them out, you should make sure that an active SSH connection to the server is always maintained. Otherwise, you’ll run the risk of locking yourself out in the event of a configuration error.

 

An SSH login to your server should now work as follows:

 

`ssh peter@a-company.com`

 

`Password:                **********   (regular password,`

`                    Input via keyboard)`

`YubiKey for 'peter':     ************ (OTP, input by`

`                    touching the YubiKey)`

## No Login without a Yubico Server

We want to make one more point here: every time you log on, pam\_yuboci contacts a server from Yubico and verifies that the OTP you provide actually matches your token. At the same time, the test prevents an OTP from being used more than once. You can find more technical background information on the procedure at [*https://developers.yubico.com/OTP/OTPs\_Explained.html*](https://developers.yubico.com/OTP/OTPs_Explained.html).

 

Yubico currently operates five OTP servers that are distributed around the world to ensure a relatively high level of redundancy. However, if these servers suddenly become unavailable due to a technical glitch, hacking attack, or network problem, you will no longer be able to log on. In this respect, it’s a good idea to not activate 2FA for all accounts of a server; leave a—less secure—emergency account with a normal login.

 

Editor’s note: This post has been adapted from a section of the book [*Hacking and Security: The Comprehensive Guide to Penetration Testing and Cybersecurity*](https://www.sap-press.com/hacking-and-security_5696/?utm_source=sappressblog&utm_medium=referral&utm_campaign=Blogs&utm_term=2425_chapter14_2&utm_content=2425) by Michael Kofler, Klaus Gebeshuber, Peter Kloep, Frank Neugebauer, André Zingsheim, Thomas Hackner, Markus Widl, Roland Aigner, Stefan Kania, Tobias Scheible, and Matthias Wübbeling.

## Recommendation

[![Hacking and Security](https://blog.rheinwerk-computing.com/hs-fs/hubfs/social-suggested-images/2425-Jan-05-2024-11-10-28-8506-PM-1-3-3-1.jpg?width=170&name=2425-Jan-05-2024-11-10-28-8506-PM-1-3-3-1.jpg)](https://www.sap-press.com/hacking-and-security_5696/?utm_source=sappressblog&utm_medium=referral&utm_campaign=Blogs&utm_term=2425_chapter14_2&utm_content=2425)

**Hacking and Security**

Uncover security vulnerabilities and harden your system against attacks! With this guide you’ll learn to set up a virtual learning environment where you can test out hacking tools, from Kali Linux to hydra and Wireshark. Then expand your understanding of offline hacking, external safety checks, penetration testing in networks, and other essential security techniques, with step-by-step instructions. With information on mobile, cloud, and IoT security you can fortify your system against any threat!

[Learn More](https://www.sap-press.com/hacking-and-security_5696/?utm_source=sappressblog&utm_medium=referral&utm_campaign=Blogs&utm_term=2425_chapter14_2&utm_content=2425)

![Rheinwerk Computing](https://blog.rheinwerk-computing.com/hubfs/RW-logo-300x300.png)

**by [Rheinwerk Computing](https://blog.rheinwerk-computing.com/author/rheinwerk-computing)**

Rheinwerk Computing is an imprint of Rheinwerk Publishing and publishes books by leading experts in the fields of programming, administration, security, analytics, and more.

[Cybersecurity](https://blog.rheinwerk-computing.com/tag/cybersecurity)

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png)](https://www.facebook.com/share.php?u=https%3A%2F%2Fblog.rheinwerk-computing.com%2Fsecuring-ssh-access-with-yubikey-a-step-by-step-guide-to-two-factor-authentication%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png)](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.rheinwerk-computing.com%2Fsecuring-ssh-access-with-yubikey-a-step-by-step-guide-to-two-factor-authentication%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fblog.rheinwerk-computing.com%2Fsecuring-ssh-access-with-yubikey-a-step-by-step-guide-to-two-factor-authentication%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fblog.rheinwerk-computing.com%2Fsecuring-ssh-access-with-yubikey-a-step-by-step-guide-to-two-factor-authentication%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=) [![Share on email](https://7528311.fs1.hubspotusercontent-na1.net/hub/7528311/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/email-color.png?width=24&name=email-color.png)](mailto:?subject=Check+out+https%3A%2F%2Fblog.rheinwerk-computing.com%2Fsecuring-ssh-access-with-yubikey-a-step-by-step-guide-to-two-factor-authentication%3Futm_medium%3Dsocial%26utm_source%3Demail&body=Check+out+https%3A%2F%2Fblog.rheinwerk-computing.com%2Fsecuring-ssh-access-with-yubikey-a-step-by-step-guide-to-two-factor-authentication%3Futm_medium%3Dsocial%26utm_source%3Demail)

### Comments

### Latest Blog Posts

[![Getting Started with AppArmor: Linux Security Made Simple](https://blog.rheinwerk-computing.com/hs-fs/hubfs/Getting%20Started%20with%20AppArmor_%20Linux%20Security%20Made%20Simple.jpg?height=600&name=Getting%20Started%20with%20AppArmor_%20Linux%20Security%20Made%20Simple.jpg)](https://blog.rheinwerk-computing.com/getting-started-with-apparmor-linux-security-made-simple)

[Cybersecurity](https://blog.rheinwerk-computing.com/tag/cybersecurity)

## [Getting Started with AppArmor: Linux Security Made Simple](https://blog.rheinwerk-computing.com/getting-started-with-apparmor-linux-security-made-simple)

[Read More](https://blog.rheinwerk-computing.com/getting-started-with-apparmor-linux-security-made-simple)

[![Securing Linux Using 2FA with Google Authenticator](https://blog.rheinwerk-computing.com/hs-fs/hubfs/Securing%20Linux%20Using%202FA%20with%20Google%20Authenticator.png?height=600&name=Securing%20Linux%20Using%202FA%20with%20Google%20Authenticator.png)](https://blog.rheinwerk-computing.com/securing-linux-using-2fa-with-google-authenticator)

[Cybersecurity](https://blog.rheinwerk-computing.com/tag/cybersecurity)

## [Securing Linux Using 2FA with Google Authenticator](https://blog.rheinwerk-computing.com/securing-linux-using-2fa-with-google-authenticator)

[Read More](https://blog.rheinwerk-computing.com/securing-linux-using-2fa-with-google-authenticator)

**Subscribe to our blog!**Get notified about future blog updates.

- <https://www.linkedin.com/showcase/rheinwerk-computing/>
- <https://www.youtube.com/channel/UChj-U-uWGM7qRlHXSFU93ew>
- <https://blog.rheinwerk-computing.com/rss.xml>

### The official Rheinwerk Computing Blog

Rheinwerk Computing is an imprint of Rheinwerk Publishing and publishes resources that will help you accelerate your computing journey. The Rheinwerk Computing Blog is designed to provide helpful, actionable information on a variety of topics, including programming, administration, security, and analytics!

### Blog Topics

- [All Topics](https://blog.rheinwerk-computing.com)
- [Programming Languages](https://blog.rheinwerk-computing.com/tag/programming-languages)
- [How To](https://blog.rheinwerk-computing.com/tag/how-to)
- [JavaScript](https://blog.rheinwerk-computing.com/tag/javascript)
- [DevOps](https://blog.rheinwerk-computing.com/tag/devops)
- [Python](https://blog.rheinwerk-computing.com/tag/python)
- [Web Development](https://blog.rheinwerk-computing.com/tag/web-development)
- [Featured](https://blog.rheinwerk-computing.com/tag/featured)
- [What Is?](https://blog.rheinwerk-computing.com/tag/what-is)
- [Cybersecurity](https://blog.rheinwerk-computing.com/tag/cybersecurity)
- [Software Development](https://blog.rheinwerk-computing.com/tag/software-development)

### Blog curated by

[![Rheinwerk Computing Logo](https://blog.rheinwerk-computing.com/hubfs/computing_logo-header.svg)](https://www.sap-press.com/rheinwerk-computing/) [Visit Rheinwerk Computing Store](https://www.sap-press.com/rheinwerk-computing/)

### About

- [Home](https://sap-press.com/)
- [About Us](https://sap-press.com/the-publisher/)
- [Contact](mailto:info@rheinwerk-publishing.com)
- [Legal Notes](https://sap-press.com/legal-notes/)
- [Privacy Policy](https://sap-press.com/privacy/)
- [Terms of Use](https://sap-press.com/terms/)

© 2026 Rheinwerk Publishing, Inc. | Change Privacy Options

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Rheinwerk Computing",
    "url" : "https://blog.rheinwerk-computing.com/author/rheinwerk-computing"
  },
  "dateModified" : "2025-12-17T14:02:37.685Z",
  "datePublished" : "2025-12-17T14:02:36.000Z",
  "headline" : "Securing SSH Access with YubiKey: A Step-by-Step Guide to Two-Factor Authentication",
  "image" : [ "https://blog.rheinwerk-computing.com/hubfs/2FA%20with%20YubiKey.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.rheinwerk-computing.com/securing-ssh-access-with-yubikey-a-step-by-step-guide-to-two-factor-authentication",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.rheinwerk-computing.com/hubfs/Logo-1.jpg"
    },
    "name" : "Rheinwerk Publishing, Inc."
  }
}
```