Commit Graph

98 Commits

Author SHA1 Message Date
Andris Raugulis f91eb3843a Fix temporary certificate file removal, mentioned in #21. 2020-05-25 22:28:55 +00:00
Andris Raugulis f0a3c8ec2c Rework certificate verification. 2020-05-25 22:24:49 +00:00
Andris Raugulis b53657b767 Do not use client certificate, if not specified. 2020-05-25 19:52:18 +00:00
Andris Raugulis 15d03e2ca2 Fix usage of client certificates, as noted in #21. 2020-05-25 18:04:52 +00:00
Andris Raugulis b977409ae0 Write bytes, not str. 2020-05-23 01:19:57 +00:00
Andris Raugulis bc46b987d6 Rename example URLs. 2020-05-23 01:16:43 +00:00
Andris Raugulis 69ebe59400 Add flush(). 2020-05-23 01:13:21 +00:00
Andris Raugulis 9eea095bda Rework certificate parts. Use different client certificates.
Reshape and reword configuration file.
2020-05-23 01:06:52 +00:00
Andris Raugulis 3e6b63285c Ignore ".mypy_cache" directory. 2020-05-22 22:47:08 +00:00
Andris Raugulis 28ad0ddbe5 Finish up MyPy type checking. While there, refactor a bit. 2020-05-22 22:45:24 +00:00
Andris Raugulis d5d83bb009 Add simple MyPy typing. All good, except file handle in conf. 2020-05-21 23:14:57 +00:00
Andris Raugulis 2938e4d8dc Prospector fixes. 2020-05-21 19:50:21 +00:00
Andris Raugulis 518ce1ba67 Fix link in readme. 2020-05-21 18:58:48 +00:00
Andris Raugulis d1c5040b9d Update readme. 2020-05-21 18:57:52 +00:00
Andris Raugulis f70bca8245 Update know issues section. 2020-05-21 18:34:52 +00:00
Andris Raugulis 5845d335bf Update know issues section. 2020-05-21 18:33:36 +00:00
Andris Raugulis 782f71cfb2 Python3 fixes. 2020-05-21 18:27:13 +00:00
Andris Raugulis 679018c6f9 Fix OpenConnect 8.05+ compatibility by implementing new feature:
- auto-detect openconnect version and required stdin pipe format
- support manual format specification (for future openconnect bugs)
- remove "bug.*" configuration options as they are unnecessary now
2020-05-21 18:21:22 +00:00
Andris Raugulis b5dffd6ab2 Do not error out, when OKTA redirects to unknown (nearest) "gateway" portal. 2020-05-21 16:32:34 +00:00
Andris Raugulis 011dc55493 Add more debugging. 2020-05-21 16:14:03 +00:00
Andris Raugulis 0857d9d5ee Merge pull request #20 from siers/master
shell.nix for NixOS
2020-05-21 17:28:35 +03:00
Andris Raugulis 2a1fb948fc Use gateway as choice in openconnect and gateway_url as direct authentication URL.
Rename `--show-list-of-gateways` to `--list-gateways` and fix it (sometimes gateways can be listed only after authentication).
Reorder configuration file to be more sane.
2020-05-21 14:21:54 +00:00
Andris Raugulis ba14b46d7d Merge pull request #19 from coldcoff/master
Several improvements for `gp-okta.py`
2020-05-21 13:18:32 +03:00
Andris Raugulis a808b2486d Add ChangeLog. 2020-05-21 09:36:31 +00:00
Tino Lange 7fbaeee604 support 'push' also in mfa_priority 2020-05-08 09:35:06 +02:00
Tino Lange d9c3b2198c merge PR https://github.com/arthepsy/pan-globalprotect-okta/pull/14 from @sirmax 2020-05-08 09:17:18 +02:00
Tino Lange 0aa34dc547 fix 'gateway used before assignement' error (code review by @cardonator) 2020-05-08 08:56:36 +02:00
siers 27f1538188 shell.nix for NixOS 2020-04-24 14:45:55 +03:00
Tino Lange a4db9833a1 remove strange hex chars in docstring (probably an artifact from copy&paste) 2020-04-16 16:04:25 +02:00
Tino Lange 7d478c0e34 Implement '--show-list-of-gateways' option to display the list of gateways fetched from the portal - useful to see what values the 'gateway' option can take 2020-04-16 09:48:19 +02:00
Tino Lange 3946d55e59 Add some good ideas from @limitz404 2020-04-15 12:27:09 +02:00
Tino Lange 748749e78f trim trailing whitespace 2020-04-14 11:53:46 +02:00
Tino Lange fa5e58f333 allow to dance only with some concrete gateway when SAML is disabled at the portal (but not at the gateway) 2020-04-14 11:52:42 +02:00
Tino Lange 8f628a9f78 make the error message more verbose in case a SAML request is missing in the response 2020-04-14 11:51:47 +02:00
coldcoff 76a895d3ff Merge pull request #2 from dlenski/Symantec_VIPAccess_is_TOTP
Treat "Symantec VIP Access" as TOTP
2020-01-30 08:57:53 +01:00
Daniel Lenski fce587af61 Treat "Symantec VIP Access" as TOTP
Although not advertised as such, Symantec VIP Access is based on TOTP and
there is an open-source implementation for provisioning the tokens and
obtaining the TOTP secret at http://github.com/dlenski/python-vipaccess
2019-09-16 12:23:20 -07:00
Tino Lange c9944a15c8 No functional changes, just document (commented out) more potential parameters for getconfig.esp (found in OpenConnect source code and docs) 2019-09-03 10:31:48 +02:00
Tino Lange 536a88f487 Bugfix: formatting of error message when send_req() fails 2019-09-03 10:30:21 +02:00
Tino Lange c4e7498f4d Feature: Allow Yubikey webauthn authentication, if configured as 2FA in Okta.
Just insert your YubiKey and press the blinking button, when asked to do so.
Needs `fido2` packages to work (`pip install fido2`).
2019-07-07 19:06:59 +02:00
Tino Lange f0c785f19c Bugfix: use unicode literals also on python2, this avoids errors with formatstring.format(...)
(see: https://stackoverflow.com/questions/3235386/python-using-format-on-a-unicode-escaped-string)
2019-07-04 00:02:18 +02:00
Tino Lange 54145a7545 Bugfix: guard case when error msg is not returned 2019-07-03 23:46:50 +02:00
Tino Lange 9ee875bf56 Some portals seem not to return root-ca entries, detect that and just continue 2019-06-14 12:58:30 +02:00
Tino Lange ceeaebba6d Do the "another_dance" at the desired gateway to obtain a cookie that is valid there 2019-06-13 17:17:58 +02:00
Tino Lange d6a3863774 Add the committing people all to the copyright notice 2019-06-13 17:10:52 +02:00
Tino Lange 59af2acf8e Shorten imports 2019-06-13 17:09:53 +02:00
Tino Lange 92a167d00e Use stderr for error messages. 2019-06-13 16:59:18 +02:00
Tino Lange d14109df28 do not close file, flush is enough for now - otherwise it might get deleted in case of the temp file solution 2019-06-12 12:53:55 +02:00
Tino Lange 15c5734878 - flush openconnect_certs file in between and finally close before giving to openconnect call 2019-06-12 11:06:44 +02:00
Tino Lange 412560eff7 - Add ssl cert verification for vpn and okta side, if configured
- new option `vpn_url_cert`
  - new option `okta_url_cert`
- rename client certificate option to `client_cert` from `cert`
- totp: comment out ABCDEFGHIJKLMNOP secrets, default to not set (so you get asked)
- grab and display prelogin errors (for example: client certificate needed or such)
- new option `openconnect_certs` that points to a file to collect all given and collected server certificates, will be given to the final openconnect call (inspired by nicklans fork, thank you). If it is not set it will be a temp file.
- check all redirect and parsed urls if they point to an expected domain (either `okta_url` or `vpn_url`)
- learn `gateway` from getconfig call, if not set/overridden by config file
2019-06-11 14:31:23 +02:00
Tino Lange fab69fe18c Set certificate automatically also in openconnect call, if one is set in gp-okta.conf for the requests-dance 2019-06-07 09:37:21 +02:00