Overview

Duo authentication is required for all SeaWulf logins. You must approve a Duo request on one of your enrolled devices to complete login. If you haven't set up Duo yet, visit the Stony Brook Duo Security Enrollment page to register devices.

The DUO_PASSCODE environment variable

You can set the DUO_PASSCODE variable to pre-select your authentication method โ€” especially useful for file-transfer tools like SCP and SFTP:

ValueBehavior
pushSend a Duo push notification to your device
phonePhone callback authentication
smsRequest a batch of SMS passcodes
numeric passcodeUse a code from Duo Mobile, SMS, or a hardware token
push2 etc.Append a number to target a specific enrolled device

Configuration

Mac and Linux

Add to ~/.ssh/config:

Host *.seawulf.stonybrook.edu
  SendEnv DUO_PASSCODE

Then set the variable before login:

export DUO_PASSCODE=push

MobaXterm (Windows)

Set DUO_PASSCODE in the session settings, and configure the SSH-browser type as NONE to prevent repeated prompts.

VPN alternative

Tip: Connecting through Stony Brook's VPN authenticates Duo once, eliminating repeated prompts for subsequent SeaWulf logins through that connection.

Screenshots

MobaXTerm session settings showing SSH-browser type set to NONE for the DUO_PASSCODE environment variable, to prevent repeated authentication prompts
MobaXTerm session settings showing SSH-browser type set to NONE for the DUO_PASSCODE environment variable, to prevent repeated authentication prompts
Applies to All clusters