Commit Graph

53 Commits

Author SHA1 Message Date
Tino Lange 92a167d00e Use stderr for error messages. 2019-06-13 16:59:18 +02:00
Tino Lange d14109df28 do not close file, flush is enough for now - otherwise it might get deleted in case of the temp file solution 2019-06-12 12:53:55 +02:00
Tino Lange 15c5734878 - flush openconnect_certs file in between and finally close before giving to openconnect call 2019-06-12 11:06:44 +02:00
Tino Lange 412560eff7 - Add ssl cert verification for vpn and okta side, if configured
- new option `vpn_url_cert`
  - new option `okta_url_cert`
- rename client certificate option to `client_cert` from `cert`
- totp: comment out ABCDEFGHIJKLMNOP secrets, default to not set (so you get asked)
- grab and display prelogin errors (for example: client certificate needed or such)
- new option `openconnect_certs` that points to a file to collect all given and collected server certificates, will be given to the final openconnect call (inspired by nicklans fork, thank you). If it is not set it will be a temp file.
- check all redirect and parsed urls if they point to an expected domain (either `okta_url` or `vpn_url`)
- learn `gateway` from getconfig call, if not set/overridden by config file
2019-06-11 14:31:23 +02:00
Tino Lange fab69fe18c Set certificate automatically also in openconnect call, if one is set in gp-okta.conf for the requests-dance 2019-06-07 09:37:21 +02:00
Tino Lange 0c1905092b Fix: inconsistent spacing (tabs<->spaces) 2019-06-06 10:05:58 +02:00
Tino Lange 3d4ebf719f Implement double authn login (via stateToken) needed for some corporate VPN setups.
The first authn call only returns the `sessionToken`, with the redirect later one gets the `stateToken` and afterwards need to do the authn call again for full authentication (and mfa).
2019-06-06 09:53:52 +02:00
Tino Lange 29527325fd Implement config option cert to use a client certificate.
This fixes Issue https://github.com/arthepsy/pan-globalprotect-okta/issues/17 raised by @lvml.

(Note that if you need to specify a client certificate for the `vpn_url`, then most probably
you will also need to give the same certificate to the final `openconnect` call with `--certificate` via the `openconnect_args`)
2019-06-06 09:53:35 +02:00
Aaron Lindsay 5f24bc5ec6 Pass prelogin-cookie if portal-userauthcookie is empty 2019-06-04 14:04:32 -04:00
Aaron Lindsay 58c1d37f93 Add option for second round of Okta authentication
This appears to be required for my VPN
2019-06-04 14:04:32 -04:00
Andris Raugulis 7bcd9eb363 Add Okta transaction state (work around password expiration warning). 2019-02-14 03:40:11 +00:00
Andris Raugulis 2adb621e38 Debug HTTP headers. 2019-01-24 15:50:12 +02:00
Andris Raugulis 281aa34247 Do OKTA redirect dance until it is sucessful. 2019-01-24 15:02:20 +02:00
Andris Raugulis 7528cb8875 Fix relative URLs. 2019-01-24 14:41:16 +02:00
Andris Raugulis 76b2861a7c Remove whitespace and fix style. 2019-01-24 14:28:22 +02:00
Andris Raugulis f29ea6f0bb Reduce code by using common send_req. Refactor get_redirect_url. 2019-01-24 14:18:23 +02:00
Andris Raugulis d548cad653 Implement SMS verification. 2019-01-22 13:29:04 +00:00
Andris Raugulis 45ef74bca3 Implement MFA selection priority (by mfa_order, by line number, by value). 2019-01-22 13:19:28 +00:00
Andris Raugulis c2e6663a60 Merge pull request #9 from supertylerc/fix-8/raw-input
Fix `raw_input` for py3
2019-01-22 13:37:30 +02:00
Tyler Christiansen bc77639d3a Fix raw_input to be input for py3, set input = raw_input for py2 compat
Fixes arthepsy/pan-globalprotect-okta#8
2019-01-10 18:20:09 -05:00
Andris Raugulis 1f8db7d309 Escape backslash in username and other fields, i.e., use single quote.
Add work-around for additional username input.
2018-10-08 00:12:59 +00:00
Andris Raugulis 263bd98b41 Fix typo in Dockerfile. 2018-09-07 01:06:19 +03:00
Andris Raugulis 73c88aeb16 Make openconnect_args optional also in code. 2018-09-06 17:09:40 +03:00
Andris Raugulis d397a4cc20 Merge pull request #5 from stromnet/cleanup-fix
Cleanup fix
2018-09-06 17:07:14 +03:00
Johan Ström 4660d48151 Ignore SIGINT to allow proper cleanup on Ctrl-C 2018-09-06 15:12:50 +02:00
Johan Ström 9a0ec161de Let openconnect output go to stdout 2018-09-06 15:12:38 +02:00
Andris Raugulis c445c828e9 Mention Python compatiblity. 2018-09-04 18:37:19 +03:00
Andris Raugulis 36106a879a Python 3 compatibility. 2018-09-04 18:34:41 +03:00
Andris Raugulis 1520db2cec Hide cookie in process list (stop using shell=True). 2018-09-04 18:14:39 +03:00
Andris Raugulis ac0066adad Add supported OS'es. 2018-09-04 17:10:36 +03:00
Andris Raugulis 9d8f69e895 Fix pulled Dockerfile. 2018-09-04 16:35:46 +03:00
Andris Raugulis 7e09f5771f Fix shebang and rename container and script. 2018-09-04 15:45:55 +03:00
Aivars Sterns 2c222deccb introduce docker and launch script (#4)
* Introduce docker and launch script
* warn if unbound not found
* output only on connect
* show new routes
2018-09-04 15:35:14 +03:00
Andris Raugulis a050e961a8 Fix mistake in option naming. 2018-09-03 19:05:13 +03:00
Andris Raugulis 11a7d1b9cb Make note about dependencies. 2018-09-03 18:54:39 +03:00
Andris Raugulis 6bff117654 Fix typo in option name. 2018-09-03 18:46:37 +03:00
Andris Raugulis dafd415029 Rework readme. 2018-09-03 18:44:42 +03:00
Andris Raugulis f677133a32 Add initial readme. 2018-09-03 18:39:38 +03:00
Andris Raugulis 51b8725260 Do not force sudo in default configuration. 2018-09-03 15:05:35 +03:00
Andris Raugulis 76597ea412 Request username/password if empty. Override configuration file
settings with environment variables (GP_*). Implement openconnect
command (for sudo/doas cases) and args (for custom vpnc scripts).
Implement execution.
2018-09-03 15:03:16 +03:00
Andris Raugulis 1df901118d Add gateway support. Add workaround for newline bug in openconnect. 2018-09-03 13:40:29 +03:00
Andris Raugulis b3201c402a Add support for OKTA TOTP, fixing #2. 2018-08-31 12:03:33 +00:00
Andris Raugulis 8dd32c4384 Merge pull request #3 from dlenski/patch-1
Undo my mistake (I botched this in #1, shame on me)
2018-08-31 13:14:55 +03:00
Dan Lenski 2029f19353 Undo my mistake (I botched this in #1, shame on me) 2018-08-30 17:35:13 -07:00
Andris Raugulis 6c56daca01 Merge pull request #1 from dlenski/master
use openconnect-gp's new mechanism for specifying a cookie field
2018-08-20 15:46:46 +03:00
Daniel Lenski f7fe9b5529 use openconnect-gp's new mechanism for specifying an alternative-secret field for the login form submission, instead of 'passwd'
This was added in the `fun_with_cookie` branch. See:

	https://github.com/dlenski/openconnect/commits/fun_with_cookies
	https://github.com/dlenski/openconnect/pull/98#issuecomment-380923571
2018-04-13 13:15:16 -07:00
Andris Raugulis fac7013918 Add a way to mark insecure zones. 2018-04-11 12:55:54 +03:00
Andris Raugulis 1856ec11a4 Use generic computer name. 2018-04-09 18:31:10 +03:00
Andris Raugulis 3552df6f14 Mask password input. 2018-04-09 17:38:20 +03:00
Andris Raugulis 49e76bd87f Allow username, password and TOTP to be entered ineractively. 2018-04-09 17:35:07 +03:00