Tino Lange
3946d55e59
Add some good ideas from @limitz404
2020-04-15 12:27:09 +02:00
Tino Lange
748749e78f
trim trailing whitespace
2020-04-14 11:53:46 +02:00
Tino Lange
fa5e58f333
allow to dance only with some concrete gateway when SAML is disabled at the portal (but not at the gateway)
2020-04-14 11:52:42 +02:00
Tino Lange
8f628a9f78
make the error message more verbose in case a SAML request is missing in the response
2020-04-14 11:51:47 +02:00
Tino Lange
c9944a15c8
No functional changes, just document (commented out) more potential parameters for getconfig.esp (found in OpenConnect source code and docs)
2019-09-03 10:31:48 +02:00
Tino Lange
536a88f487
Bugfix: formatting of error message when send_req() fails
2019-09-03 10:30:21 +02:00
Tino Lange
c4e7498f4d
Feature: Allow Yubikey webauthn authentication, if configured as 2FA in Okta.
...
Just insert your YubiKey and press the blinking button, when asked to do so.
Needs `fido2` packages to work (`pip install fido2`).
2019-07-07 19:06:59 +02:00
Tino Lange
f0c785f19c
Bugfix: use unicode literals also on python2, this avoids errors with formatstring.format(...)
...
(see: https://stackoverflow.com/questions/3235386/python-using-format-on-a-unicode-escaped-string )
2019-07-04 00:02:18 +02:00
Tino Lange
54145a7545
Bugfix: guard case when error msg is not returned
2019-07-03 23:46:50 +02:00
Tino Lange
9ee875bf56
Some portals seem not to return root-ca entries, detect that and just continue
2019-06-14 12:58:30 +02:00
Tino Lange
ceeaebba6d
Do the "another_dance" at the desired gateway to obtain a cookie that is valid there
2019-06-13 17:17:58 +02:00
Tino Lange
d6a3863774
Add the committing people all to the copyright notice
2019-06-13 17:10:52 +02:00
Tino Lange
59af2acf8e
Shorten imports
2019-06-13 17:09:53 +02:00
Tino Lange
92a167d00e
Use stderr for error messages.
2019-06-13 16:59:18 +02:00
Tino Lange
d14109df28
do not close file, flush is enough for now - otherwise it might get deleted in case of the temp file solution
2019-06-12 12:53:55 +02:00
Tino Lange
15c5734878
- flush openconnect_certs file in between and finally close before giving to openconnect call
2019-06-12 11:06:44 +02:00
Tino Lange
412560eff7
- Add ssl cert verification for vpn and okta side, if configured
...
- new option `vpn_url_cert`
- new option `okta_url_cert`
- rename client certificate option to `client_cert` from `cert`
- totp: comment out ABCDEFGHIJKLMNOP secrets, default to not set (so you get asked)
- grab and display prelogin errors (for example: client certificate needed or such)
- new option `openconnect_certs` that points to a file to collect all given and collected server certificates, will be given to the final openconnect call (inspired by nicklans fork, thank you). If it is not set it will be a temp file.
- check all redirect and parsed urls if they point to an expected domain (either `okta_url` or `vpn_url`)
- learn `gateway` from getconfig call, if not set/overridden by config file
2019-06-11 14:31:23 +02:00