Description
Apache sites can require one-time password authentication through a server module. Administrators use it when protected web resources need an additional OTP-based login factor.
It changes authentication for web services. Time sync, secret storage, recovery procedures, and bypass rules must be tested before deployment.