Tino Lange 412560eff7 - Add ssl cert verification for vpn and okta side, if configured
- new option `vpn_url_cert`
  - new option `okta_url_cert`
- rename client certificate option to `client_cert` from `cert`
- totp: comment out ABCDEFGHIJKLMNOP secrets, default to not set (so you get asked)
- grab and display prelogin errors (for example: client certificate needed or such)
- new option `openconnect_certs` that points to a file to collect all given and collected server certificates, will be given to the final openconnect call (inspired by nicklans fork, thank you). If it is not set it will be a temp file.
- check all redirect and parsed urls if they point to an expected domain (either `okta_url` or `vpn_url`)
- learn `gateway` from getconfig call, if not set/overridden by config file
2019-06-11 14:31:23 +02:00
2018-04-09 16:40:36 +03:00
2018-09-07 01:06:19 +03:00

pan-globalprotect-okta

Command-line client for PaloAlto Networks' GlobalProtect VPN, integrated with OKTA. This utility will do the authentication dance with OKTA to retrieve portal-userauthcookie, which will be passed to OpenConnect with PAN GlobalProtect support for creating actual VPN connection. Compatible with Python 2 and 3. Tested on FreeBSD, Linux and MacOS X.

It also supports Google and OKTA two factor authentication and can work without user interaction, if initial TOTP secret is provided. Otherwise, it will ask for generated code.

To gather TOTP secret, there are two possibilities - either scan the provided QR code with normal QR code scanner and write down the secret. Or create backup from current OTP application in phone. Some applications have this feature, but some don't. For example, andOTP on Android do support this feature.

usage

This utility depends on requests and lxml Python libraries. If TOTP secret is being used, then pyotp is also required.

   ./gp-okta.py gp-okta.conf

docker

Build Docker image before running container:

docker build -t gp-okta .

Edit gp-okta.conf and launch Docker container:

sh run-docker.sh

configuration

Configuration file should be self-explanatory. Options can be overridden with GP_ prefixed respective environment variables, e.g., GP_PASSWORD will override password option in configuration file.

known issues

If openconnect returns with ioctl error, then this version has a bug, which requires to prefix stdin input with a newline. Set bug.nl=1 in configuration file to work-around this issue.

If openconnect returns with fgets (stdin): Resource temporarily unavailable error, then this version has a bug, which requires to prefix stdin input with a username. Set bug.username=1 in configuration file to work-around this issue.

S
Description
No description provided
Readme 329 KiB
Languages
Python 88.2%
Shell 9.8%
Dockerfile 1.7%
Nix 0.3%