Configuring a secret that supports TOTP
This example demonstrates how FortiPAM can be configured to support TOTP.
SSH secrets support TOTP auto-deliviery when launched.
To configure a secret that supports TOTP:
Limitations
- TOTP auto delivery only supports SSH target and RDP authentication.
- TOTP auto delivery for RDP needs the FortiAuthenticator agent running in the target machine and security level set to TLS.
- Password changer does not support public key + TOTP authentication.
- With TOTP, WebSSH only supports keyboard-interactive authentication method.
- With the non-proxy launcher or web launcher, TOTP code must be copied and entered manually.
- Do not enable the password changer for the SSH server with password + FortiToken authentication if the username, password, and FortiToken are from another LDAP server.