Commit Graph
4 Commits
Author SHA1 Message Date
Tino Lange 92a167d00e Use stderr for error messages. 2019-06-13 16:59:18 +02:00
Tino Lange d14109df28 do not close file, flush is enough for now - otherwise it might get deleted in case of the temp file solution 2019-06-12 12:53:55 +02:00
Tino Lange 15c5734878 - flush openconnect_certs file in between and finally close before giving to openconnect call 2019-06-12 11:06:44 +02:00
Tino Lange 412560eff7 - Add ssl cert verification for vpn and okta side, if configured
- new option `vpn_url_cert`
  - new option `okta_url_cert`
- rename client certificate option to `client_cert` from `cert`
- totp: comment out ABCDEFGHIJKLMNOP secrets, default to not set (so you get asked)
- grab and display prelogin errors (for example: client certificate needed or such)
- new option `openconnect_certs` that points to a file to collect all given and collected server certificates, will be given to the final openconnect call (inspired by nicklans fork, thank you). If it is not set it will be a temp file.
- check all redirect and parsed urls if they point to an expected domain (either `okta_url` or `vpn_url`)
- learn `gateway` from getconfig call, if not set/overridden by config file
2019-06-11 14:31:23 +02:00