mirror of
https://github.com/os-mnemo/pan-globalprotect-okta
synced 2026-07-31 07:44:38 +02:00
Treat "Symantec VIP Access" as TOTP
Although not advertised as such, Symantec VIP Access is based on TOTP and there is an open-source implementation for provisioning the tokens and obtaining the TOTP secret at http://github.com/dlenski/python-vipaccess
This commit is contained in:
+3
-2
@@ -172,7 +172,7 @@ def load_conf(cf):
|
||||
return conf
|
||||
|
||||
def mfa_priority(conf, ftype, fprovider):
|
||||
if ftype == 'token:software:totp':
|
||||
if ftype == 'token:software:totp' or (ftype, fprovider) == ('token', 'symantec'):
|
||||
ftype = 'totp'
|
||||
if ftype not in ['totp', 'sms', 'webauthn']:
|
||||
return 0
|
||||
@@ -382,7 +382,8 @@ def okta_mfa(conf, s, j):
|
||||
for f in sorted(factors, key=lambda x: x.get('priority', 0), reverse=True):
|
||||
#print(f)
|
||||
ftype = f.get('type')
|
||||
if ftype == 'token:software:totp':
|
||||
fprovider = f.get('provider')
|
||||
if ftype == 'token:software:totp' or (ftype, fprovider) == ('token', 'symantec'):
|
||||
r = okta_mfa_totp(conf, s, f, state_token)
|
||||
elif ftype == 'sms':
|
||||
r = okta_mfa_sms(conf, s, f, state_token)
|
||||
|
||||
Reference in New Issue
Block a user