Tino Lange
0aa34dc547
fix 'gateway used before assignement' error (code review by @cardonator)
2020-05-08 08:56:36 +02:00
Tino Lange
a4db9833a1
remove strange hex chars in docstring (probably an artifact from copy&paste)
2020-04-16 16:04:25 +02:00
Tino Lange
7d478c0e34
Implement '--show-list-of-gateways' option to display the list of gateways fetched from the portal - useful to see what values the 'gateway' option can take
2020-04-16 09:48:19 +02:00
Tino Lange
3946d55e59
Add some good ideas from @limitz404
2020-04-15 12:27:09 +02:00
Tino Lange
748749e78f
trim trailing whitespace
2020-04-14 11:53:46 +02:00
Tino Lange
fa5e58f333
allow to dance only with some concrete gateway when SAML is disabled at the portal (but not at the gateway)
2020-04-14 11:52:42 +02:00
Tino Lange
8f628a9f78
make the error message more verbose in case a SAML request is missing in the response
2020-04-14 11:51:47 +02:00
Daniel Lenski
fce587af61
Treat "Symantec VIP Access" as TOTP
...
Although not advertised as such, Symantec VIP Access is based on TOTP and
there is an open-source implementation for provisioning the tokens and
obtaining the TOTP secret at http://github.com/dlenski/python-vipaccess
2019-09-16 12:23:20 -07:00
Tino Lange
c9944a15c8
No functional changes, just document (commented out) more potential parameters for getconfig.esp (found in OpenConnect source code and docs)
2019-09-03 10:31:48 +02:00
Tino Lange
536a88f487
Bugfix: formatting of error message when send_req() fails
2019-09-03 10:30:21 +02:00
Tino Lange
c4e7498f4d
Feature: Allow Yubikey webauthn authentication, if configured as 2FA in Okta.
...
Just insert your YubiKey and press the blinking button, when asked to do so.
Needs `fido2` packages to work (`pip install fido2`).
2019-07-07 19:06:59 +02:00
Tino Lange
f0c785f19c
Bugfix: use unicode literals also on python2, this avoids errors with formatstring.format(...)
...
(see: https://stackoverflow.com/questions/3235386/python-using-format-on-a-unicode-escaped-string )
2019-07-04 00:02:18 +02:00
Tino Lange
54145a7545
Bugfix: guard case when error msg is not returned
2019-07-03 23:46:50 +02:00
Tino Lange
9ee875bf56
Some portals seem not to return root-ca entries, detect that and just continue
2019-06-14 12:58:30 +02:00
Tino Lange
ceeaebba6d
Do the "another_dance" at the desired gateway to obtain a cookie that is valid there
2019-06-13 17:17:58 +02:00
Tino Lange
d6a3863774
Add the committing people all to the copyright notice
2019-06-13 17:10:52 +02:00
Tino Lange
59af2acf8e
Shorten imports
2019-06-13 17:09:53 +02:00
Tino Lange
92a167d00e
Use stderr for error messages.
2019-06-13 16:59:18 +02:00
Tino Lange
d14109df28
do not close file, flush is enough for now - otherwise it might get deleted in case of the temp file solution
2019-06-12 12:53:55 +02:00
Tino Lange
15c5734878
- flush openconnect_certs file in between and finally close before giving to openconnect call
2019-06-12 11:06:44 +02:00
Tino Lange
412560eff7
- Add ssl cert verification for vpn and okta side, if configured
...
- new option `vpn_url_cert`
- new option `okta_url_cert`
- rename client certificate option to `client_cert` from `cert`
- totp: comment out ABCDEFGHIJKLMNOP secrets, default to not set (so you get asked)
- grab and display prelogin errors (for example: client certificate needed or such)
- new option `openconnect_certs` that points to a file to collect all given and collected server certificates, will be given to the final openconnect call (inspired by nicklans fork, thank you). If it is not set it will be a temp file.
- check all redirect and parsed urls if they point to an expected domain (either `okta_url` or `vpn_url`)
- learn `gateway` from getconfig call, if not set/overridden by config file
2019-06-11 14:31:23 +02:00
Tino Lange
fab69fe18c
Set certificate automatically also in openconnect call, if one is set in gp-okta.conf for the requests-dance
2019-06-07 09:37:21 +02:00
Tino Lange
0c1905092b
Fix: inconsistent spacing (tabs<->spaces)
2019-06-06 10:05:58 +02:00
Tino Lange
3d4ebf719f
Implement double authn login (via stateToken) needed for some corporate VPN setups.
...
The first authn call only returns the `sessionToken`, with the redirect later one gets the `stateToken` and afterwards need to do the authn call again for full authentication (and mfa).
2019-06-06 09:53:52 +02:00
Tino Lange
29527325fd
Implement config option cert to use a client certificate.
...
This fixes Issue https://github.com/arthepsy/pan-globalprotect-okta/issues/17 raised by @lvml.
(Note that if you need to specify a client certificate for the `vpn_url`, then most probably
you will also need to give the same certificate to the final `openconnect` call with `--certificate` via the `openconnect_args`)
2019-06-06 09:53:35 +02:00
Aaron Lindsay
5f24bc5ec6
Pass prelogin-cookie if portal-userauthcookie is empty
2019-06-04 14:04:32 -04:00
Aaron Lindsay
58c1d37f93
Add option for second round of Okta authentication
...
This appears to be required for my VPN
2019-06-04 14:04:32 -04:00
Andris Raugulis
7bcd9eb363
Add Okta transaction state (work around password expiration warning).
2019-02-14 03:40:11 +00:00
Andris Raugulis
2adb621e38
Debug HTTP headers.
2019-01-24 15:50:12 +02:00
Andris Raugulis
281aa34247
Do OKTA redirect dance until it is sucessful.
2019-01-24 15:02:20 +02:00
Andris Raugulis
7528cb8875
Fix relative URLs.
2019-01-24 14:41:16 +02:00
Andris Raugulis
76b2861a7c
Remove whitespace and fix style.
2019-01-24 14:28:22 +02:00
Andris Raugulis
f29ea6f0bb
Reduce code by using common send_req. Refactor get_redirect_url.
2019-01-24 14:18:23 +02:00
Andris Raugulis
d548cad653
Implement SMS verification.
2019-01-22 13:29:04 +00:00
Andris Raugulis
45ef74bca3
Implement MFA selection priority (by mfa_order, by line number, by value).
2019-01-22 13:19:28 +00:00
Tyler Christiansen
bc77639d3a
Fix raw_input to be input for py3, set input = raw_input for py2 compat
...
Fixes arthepsy/pan-globalprotect-okta#8
2019-01-10 18:20:09 -05:00
Andris Raugulis
1f8db7d309
Escape backslash in username and other fields, i.e., use single quote.
...
Add work-around for additional username input.
2018-10-08 00:12:59 +00:00
Andris Raugulis
73c88aeb16
Make openconnect_args optional also in code.
2018-09-06 17:09:40 +03:00
Johan Ström
4660d48151
Ignore SIGINT to allow proper cleanup on Ctrl-C
2018-09-06 15:12:50 +02:00
Johan Ström
9a0ec161de
Let openconnect output go to stdout
2018-09-06 15:12:38 +02:00
Andris Raugulis
36106a879a
Python 3 compatibility.
2018-09-04 18:34:41 +03:00
Andris Raugulis
1520db2cec
Hide cookie in process list (stop using shell=True).
2018-09-04 18:14:39 +03:00
Andris Raugulis
76597ea412
Request username/password if empty. Override configuration file
...
settings with environment variables (GP_*). Implement openconnect
command (for sudo/doas cases) and args (for custom vpnc scripts).
Implement execution.
2018-09-03 15:03:16 +03:00
Andris Raugulis
1df901118d
Add gateway support. Add workaround for newline bug in openconnect.
2018-09-03 13:40:29 +03:00
Andris Raugulis
b3201c402a
Add support for OKTA TOTP, fixing #2 .
2018-08-31 12:03:33 +00:00
Dan Lenski
2029f19353
Undo my mistake (I botched this in #1 , shame on me)
2018-08-30 17:35:13 -07:00
Daniel Lenski
f7fe9b5529
use openconnect-gp's new mechanism for specifying an alternative-secret field for the login form submission, instead of 'passwd'
...
This was added in the `fun_with_cookie` branch. See:
https://github.com/dlenski/openconnect/commits/fun_with_cookies
https://github.com/dlenski/openconnect/pull/98#issuecomment-380923571
2018-04-13 13:15:16 -07:00
Andris Raugulis
1856ec11a4
Use generic computer name.
2018-04-09 18:31:10 +03:00
Andris Raugulis
3552df6f14
Mask password input.
2018-04-09 17:38:20 +03:00
Andris Raugulis
49e76bd87f
Allow username, password and TOTP to be entered ineractively.
2018-04-09 17:35:07 +03:00