Last updated on September 30, 2026
MFA for Linux is a multi-layered approach to Linux user authentication. Linux MFA requires users to provide at least two distinct proofs of identity, called authentication factors, to gain access to their Linux system. While the first factor, a password, stays the same, MFA for Linux adds an extra step. This extra step requires the user to complete secondary authentication using a secure authentication method, such as Mobile Push or TOTP codes. Thanks to this, hackers cannot take control of an account even after they break the password.

Rublon MFA Safeguards Your Remote and Local Linux SSH and Desktop Logins
Similarly to remotely accessing Windows machines using Remote Desktop, you can also remotely access your Linux servers using SSH. The primary password-based authentication for an SSH client comes with all the drawbacks of passwords. In short, passwords are easy to compromise; a password can be stolen, cracked, or even guessed. Multi-Factor Authentication is a good solution that eliminates security risks connected with the low security level of passwords. Multi-Factor Authentication is a good way of solving the low security level of passwords.
Rublon MFA stays up to date with the latest in cybersecurity and delivers modern security solutions for your workforce. Be it Multi-Factor Authentication, Single Sign-On, or Access Policies. Rublon MFA follows well-tested and accepted formulas while also coming up with innovative solutions. On the one hand, years of experience. On the other hand, continuous striving for innovation. Rublon MFA benefits from both and acts both as a wise, experienced magician as well as an ambitious, creative apprentice. One thing is sure. Rublon MFA does magic.
But Rublon MFA is not a magic trick. It’s very much real. Rublon MFA integrates with Linux Desktop and Server distributions like CentOS, Debian, Ubuntu, and others to add Multi-Factor Authentication to every remote or local SSH login using a custom PAM module. In the first step, you provide your login credentials or log in using your private key. In the second step introduced by Rublon MFA, you get a Mobile Push login request on your phone. You can accept or deny the login attempt. Even if somebody knows your login credentials, they cannot log in because you will deny all their login attempts. Mobile Push is often our customers’ favorite because it is easy to use and requires a smartphone, significantly increasing security. However, you are free to pick any other authentication method.
Rublon MFA for Linux SSH
Install Rublon’s SSH PAM module to enable strong Multi-Factor Authentication for your Linux SSH logins.
Append Mode
Append Mode lets users select an authentication method or submit a passcode directly in the password field. For example, entering YourPassword,push requests a Mobile Push notification, while YourPassword,123456 submits a Mobile Passcode together with the password. Administrators enable Append Mode and configure the separator used between the password and the method or code. See the Append Mode configuration instructions.
Fewer separate authentication prompts make everyday logins faster and easier.
Offline Mode
Offline Mode lets users complete MFA with a Mobile Passcode from their authenticator app when the Linux machine cannot connect to the Rublon API. The connector verifies the code locally using a secret saved during a previous successful online login on the same machine. Administrators must enable Offline Mode, and the system must still verify the user’s password or other configured primary credentials. Offline Mode is available only for SSH sessions that support interactive passcode entry. See the Offline Mode requirements and configuration instructions.
This helps maintain access to Linux systems during Rublon API connectivity issues while keeping second-factor verification in place.
Supported Linux distributions
Rublon’s SSH PAM module supports the following Linux distributions:
- Debian (11, 12)
- Ubuntu (18.04, 20.04, 22.04, 24.04)
- Red Hat / CentOS / Alma / Rocky (8, 9) / Oracle Linux (8, 9)
- openSUSE Leap / SUSE Linux Enterprise Server 15 SP3
Rublon’s SSH PAM module also enables MFA for Veritas NetBackup.
Enforce Control Over Your Linux MFA SSH Logins
Rublon MFA protects your Linux SSH logins, enabling strong Multi-Factor Authentication. In addition to that, Rublon MFA offers a set of management tools to help you control how and when your users authenticate. The Rublon Admin Console is the command center for all your applications and users alike.
The Rublon Admin Console provides you with a set of management tools to supervise your entire organization, from deciding which users are to be bypassed or denied access, through viewing who logged in to which application and when, to managing hardware tokens for authentication methods such as YubiKey OTP.
And then, there is the concept of Policies, introduced as a solution to the challenge of Adaptive Authentication. In a nutshell, the Global Policy applies to all your applications by default. You can override the Global Policy by creating Custom Policies. An Administrator can assign Custom Policies to one or more applications, but each application can only have one custom policy. We have prepared an example that illustrates how creating a policy can solve a frequent problem.
Introduction
Companies rarely ever use Rublon MFA for just one application. Usually, organizations integrate a considerable number of applications and wish to define separate use cases for each application. Global settings for all applications are fine in simple scenarios, but prove insufficient in real-life situations. Rublon acknowledged this problem and implemented a way of defining different settings for different applications.
Challenge
Let’s assume you have the following three applications defined in the Rublon Admin Console:
- Linux SSH
- Array AG SSL VPN
- MikroTik VPN
And would like the following requirements to be satisfied:
- Logins to Linux SSH should be bypassed for users logging in from the following IP address range: 17.5.100.0-17.5.100.50.
- Only Mobile Push, Email Link, and SMS Passcode should be active authentication methods for users logging in to Linux SSH.
- Logins to other applications should not be bypassed regardless of the user’s IP address.
- All authentication methods should be active for users logging in to Array AG SSL VPN or MikroTik VPN.
To satisfy complex requirements like the above, a security system has to have a way to define detailed authentication behavior at the application level.
Solution
Rublon MFA allows you to define custom policies at the application level to fulfill all preceding requirements. One way to satisfy the first two requirements looks like this:
- Create a new Custom Policy named Linux SSH Policy.
- Click Authentication Methods and check Mobile Push, Email Link, and SMS Passcode. Uncheck every other method of authentication if necessary.
- Click Authorized Networks and type 17.5.100.0-17.5.100.50 in the text field.
- Click Save to create your Linux SSH Policy.
- Go to Applications, and assign Linux SSH Policy to your Linux SSH application.
The other two requirements can be fulfilled in the following way:
- Create a new Custom Policy named VPNs Policy.
- Enable all authentication methods in your VPNs Policy while leaving the Authorized Networks field empty.
- Click Save to create your VPNs Policy.
- Go to Applications, and assign VPNs Policy to your Array AG SSL VPN and MikroTik VPN applications.
Our Customers
These Rublon customers use Rublon MFA to protect SSH:
Related Posts
Rublon MFA for Linux SSH – Documentation
The Importance of Multi-Factor Authentication And Why You Should Get Rublon MFA