1 1.1 christos TOTP OpenLDAP support 2 1.1 christos ---------------------- 3 1.1 christos 4 1.1 christos slapd-totp.c provides support for RFC 6238 TOTP Time-based One 5 1.1 christos Time Passwords in OpenLDAP using SHA-1, SHA-256, and SHA-512. 6 1.1 christos For instance, one could have the LDAP attribute: 7 1.1 christos 8 1.1 christos userPassword: {TOTP1}GEZDGNBVGY3TQOJQGEZDGNBVGY3TQOJQ 9 1.1 christos 10 1.1 christos which encodes the key '12345678901234567890'. 11 1.1 christos 12 1.1 christos It can also encode credentials consisting of a TOTP and a static 13 1.1 christos password. The format for this is: 14 1.1 christos 15 1.1 christos userPassword: {TOTP1ANDPW}GEZDGNBVGY3TQOJQGEZDGNBVGY3TQOJQ|<some_other_passwd> 16 1.1 christos 17 1.1 christos where <some_other_passwd> can be any scheme currently understood 18 1.1 christos by OpenLDAP. For example, using '{SHA}5en6G6MezRroT3XKqkdPOmY/BfQ=' 19 1.1 christos would encode the above TOTP with a static password of 'secret'. To 20 1.1 christos authenticate using this scheme, enter the static password immediately 21 1.1 christos followed by the TOTP, for example 'secret123456'. 22 1.1 christos 23 1.1 christos 24 1.1 christos Building 25 1.1 christos -------- 26 1.1 christos 27 1.1 christos 1) Customize the LDAP_SRC variable in Makefile to point to the OpenLDAP 28 1.1 christos source root. 29 1.1 christos 30 1.1.1.2 christos 2) Run 'make' to produce pw-totp.so 31 1.1 christos 32 1.1.1.2 christos 3) Copy pw-totp.so somewhere permanent. 33 1.1 christos 34 1.1 christos 4) Edit your slapd.conf (eg. /etc/ldap/slapd.conf), and add: 35 1.1 christos 36 1.1.1.2 christos moduleload ...path/to/pw-totp.so 37 1.1 christos 38 1.1 christos 5) This module replaces the function of the slapo-lastbind overlay. You 39 1.1 christos cannot use that overlay on the same database as this one. 40 1.1 christos 41 1.1 christos 6) Restart slapd. 42 1.1 christos 43 1.1 christos 44 1.1 christos Configuring 45 1.1 christos ----------- 46 1.1 christos 47 1.1 christos The {TOTP1}, {TOTP256}, {TOTP512}, {TOTP1ANDPW}, {TOTP256ANDPW}, 48 1.1 christos and {TOTP512ANDPW} password schemes should now be recognised. 49 1.1 christos 50 1.1 christos You can also tell OpenLDAP to use one of these new schemes when processing LDAP 51 1.1 christos Password Modify Extended Operations, thanks to the password-hash option in 52 1.1 christos slapd.conf. For example: 53 1.1 christos 54 1.1 christos password-hash {TOTP1} 55 1.1 christos 56 1.1 christos TOTP password schemes will only work on databases that have a rootdn and the 57 1.1 christos totp overlay configured: 58 1.1 christos 59 1.1 christos database mdb 60 1.1 christos rootdn "..." 61 1.1 christos ... 62 1.1 christos 63 1.1 christos overlay totp 64 1.1 christos 65 1.1 christos 66 1.1 christos 67 1.1 christos Testing 68 1.1 christos ------- 69 1.1 christos 70 1.1 christos The TOTP1 algorithm is compatible with Google Authenticator. 71 1.1 christos 72 1.1 christos --- 73 1.1 christos 74 1.1 christos This work is part of OpenLDAP Software <http://www.openldap.org/>. 75 1.1 christos 76 1.1.1.2 christos Copyright 2015-2024 The OpenLDAP Foundation. 77 1.1 christos Portions Copyright 2015 by Howard Chu, Symas Corp. 78 1.1 christos All rights reserved. 79 1.1 christos 80 1.1 christos Redistribution and use in source and binary forms, with or without 81 1.1 christos modification, are permitted only as authorized by the OpenLDAP 82 1.1 christos Public License. 83 1.1 christos 84 1.1 christos A copy of this license is available in the file LICENSE in the 85 1.1 christos top-level directory of the distribution or, alternatively, at 86 1.1 christos <http://www.OpenLDAP.org/license.html>. 87 1.1 christos 88