How-to enforce Multifactor Authentication when someone uses SSH to access a server or container protected by ZeroLock™.
Ensuring usage of SSH-MFA two-factor authentication, requires a multi-step process simplified by the ZeroLock™ Management Console (ZMC).
Create and Add a New Rule
- In the ZeroLock Management Console (ZMC) go to the Control Policies | Rules page then click Actions | Add New Rule.
- On the Add New Rule screen, complete the items using the table below. When done click CREATE.
Rule Name
Authenticate all SSH connections
Description
This rule will force SSH MFA for all assigned Endpoints
Rule Type
SSH-MFA
IP Address
Leave as default
Day/Time
Leave as default
Start/End
Leave as default
Action
Authenticate

Create a New Control Policy
- As shown below, go to the Control Policies | Policies page and click Add New Policy.
- Using the table, complete the required entries.
Name
Force SSH Authentication
Description
This policy will force SSH authentication to all assigned endpoints.
Add Rules
Clicking the Add Rules button brings up the Policy Rules screen.
- Scroll down until you locate the newly created rule, Authenticate all SSH connections, and click the checkbox to select it.
- Next, click the Add Selected button which returns you to New Policy screen and select CREATE.
Create a New Endpoint Configuration Profile
- Go to the System Configuration | Config Profiles page and click Add New Profile.
- Using the table, complete the required entries.
Name
Force SSH MFA and default settings
Description
This configuration restricts authentication while using all other defaults.
Default Control Policy
Force SSH Authentication
- Click the CREATE button.
Assign the Configuration Profile to an Endpoint
- Select Endpoints from the menu then the endpoint(s) to which you want to assign the new configuration policy. Click on the Actions drop-down and select Set Endpoint Config(s).
- Select the new configuration: Force SSH MFA and default settings and click Set Configs.
- From the Endpoints screen you should be able to see the assigned Profile.
Test the SSH MFA Authentication Configuration
Attempt to SSH to the assigned endpoint and verify that the two-factor authentication is working.
