Overview
Duo authentication is required for all SeaWulf logins. You must approve a Duo request on one of your enrolled devices to complete login. If you haven't set up Duo yet, visit the Stony Brook Duo Security Enrollment page to register devices.
The DUO_PASSCODE environment variable
You can set the DUO_PASSCODE variable to pre-select your authentication method โ especially useful for file-transfer tools like SCP and SFTP:
| Value | Behavior |
|---|---|
push | Send a Duo push notification to your device |
phone | Phone callback authentication |
sms | Request a batch of SMS passcodes |
| numeric passcode | Use a code from Duo Mobile, SMS, or a hardware token |
push2 etc. | Append a number to target a specific enrolled device |
Configuration
Mac and Linux
Add to ~/.ssh/config:
Host *.seawulf.stonybrook.edu SendEnv DUO_PASSCODE
Then set the variable before login:
export DUO_PASSCODE=push
MobaXterm (Windows)
Set DUO_PASSCODE in the session settings, and configure the SSH-browser type as NONE to prevent repeated prompts.
VPN alternative
Tip: Connecting through Stony Brook's VPN authenticates Duo once, eliminating repeated prompts for subsequent SeaWulf logins through that connection.
Screenshots

Applies to