From 29527325fda6b606e1411bda832026af99400bdc Mon Sep 17 00:00:00 2001 From: Tino Lange Date: Tue, 4 Jun 2019 09:21:36 +0200 Subject: [PATCH] Implement config option `cert` to use a client certificate. This fixes Issue https://github.com/arthepsy/pan-globalprotect-okta/issues/17 raised by @lvml. (Note that if you need to specify a client certificate for the `vpn_url`, then most probably you will also need to give the same certificate to the final `openconnect` call with `--certificate` via the `openconnect_args`) --- gp-okta.conf | 3 ++- gp-okta.py | 3 +++ 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/gp-okta.conf b/gp-okta.conf index c779b63..ac1b828 100644 --- a/gp-okta.conf +++ b/gp-okta.conf @@ -8,8 +8,9 @@ sms.okta = 0 totp.okta = ABCDEFGHIJKLMNOP totp.google = ABCDEFGHIJKLMNOP gateway = Manual ny1-gw.example.com +#cert = path-to-client-cert-as-unencrypted-pem-file.pem #openconnect_cmd = sudo openconnect -openconnect_args = # optional arguments to openconnect +openconnect_args = # optional arguments to openconnect, probably you might want to repeat the cert here (if used above) with --certificate=xxx execute = 0 # execute openconnect command another_dance = 0 # second round of authentication required bug.nl = 0 # newline work-around for openconnect diff --git a/gp-okta.py b/gp-okta.py index 453beef..e3e22c6 100755 --- a/gp-okta.py +++ b/gp-okta.py @@ -446,6 +446,9 @@ def main(): conf = load_conf(sys.argv[1]) s = requests.Session() + if conf.get('cert'): + s.cert = conf.get('cert') + s.headers['User-Agent'] = 'PAN GlobalProtect' saml_xml = paloalto_prelogin(conf, s) redirect_url = okta_saml(conf, s, saml_xml)