Home | History | Annotate | Line # | Download | only in totp
      1      1.1  christos TOTP OpenLDAP support
      2      1.1  christos ----------------------
      3      1.1  christos 
      4      1.1  christos slapd-totp.c provides support for RFC 6238 TOTP Time-based One
      5      1.1  christos Time Passwords in OpenLDAP using SHA-1, SHA-256, and SHA-512.
      6      1.1  christos For instance, one could have the LDAP attribute:
      7      1.1  christos 
      8      1.1  christos userPassword: {TOTP1}GEZDGNBVGY3TQOJQGEZDGNBVGY3TQOJQ
      9      1.1  christos 
     10      1.1  christos which encodes the key '12345678901234567890'.
     11      1.1  christos 
     12      1.1  christos It can also encode credentials consisting of a TOTP and a static
     13      1.1  christos password.  The format for this is:
     14      1.1  christos 
     15      1.1  christos userPassword: {TOTP1ANDPW}GEZDGNBVGY3TQOJQGEZDGNBVGY3TQOJQ|<some_other_passwd>
     16      1.1  christos 
     17      1.1  christos where <some_other_passwd> can be any scheme currently understood
     18      1.1  christos by OpenLDAP.  For example, using '{SHA}5en6G6MezRroT3XKqkdPOmY/BfQ='
     19      1.1  christos would encode the above TOTP with a static password of 'secret'.  To
     20      1.1  christos authenticate using this scheme, enter the static password immediately
     21      1.1  christos followed by the TOTP, for example 'secret123456'.
     22      1.1  christos 
     23      1.1  christos 
     24      1.1  christos Building
     25      1.1  christos --------
     26      1.1  christos 
     27      1.1  christos 1) Customize the LDAP_SRC variable in Makefile to point to the OpenLDAP
     28      1.1  christos source root.
     29      1.1  christos 
     30  1.1.1.2  christos 2) Run 'make' to produce pw-totp.so
     31      1.1  christos 
     32  1.1.1.2  christos 3) Copy pw-totp.so somewhere permanent.
     33      1.1  christos 
     34      1.1  christos 4) Edit your slapd.conf (eg. /etc/ldap/slapd.conf), and add:
     35      1.1  christos 
     36  1.1.1.2  christos moduleload ...path/to/pw-totp.so
     37      1.1  christos 
     38      1.1  christos 5) This module replaces the function of the slapo-lastbind overlay. You
     39      1.1  christos cannot use that overlay on the same database as this one.
     40      1.1  christos 
     41      1.1  christos 6) Restart slapd.
     42      1.1  christos 
     43      1.1  christos 
     44      1.1  christos Configuring
     45      1.1  christos -----------
     46      1.1  christos 
     47      1.1  christos The {TOTP1}, {TOTP256}, {TOTP512}, {TOTP1ANDPW}, {TOTP256ANDPW},
     48      1.1  christos and {TOTP512ANDPW} password schemes should now be recognised.
     49      1.1  christos 
     50      1.1  christos You can also tell OpenLDAP to use one of these new schemes when processing LDAP
     51      1.1  christos Password Modify Extended Operations, thanks to the password-hash option in
     52      1.1  christos slapd.conf. For example:
     53      1.1  christos 
     54      1.1  christos password-hash	{TOTP1}
     55      1.1  christos 
     56      1.1  christos TOTP password schemes will only work on databases that have a rootdn and the
     57      1.1  christos totp overlay configured:
     58      1.1  christos 
     59      1.1  christos database mdb
     60      1.1  christos rootdn "..."
     61      1.1  christos ...
     62      1.1  christos 
     63      1.1  christos overlay totp
     64      1.1  christos 
     65      1.1  christos 
     66      1.1  christos 
     67      1.1  christos Testing
     68      1.1  christos -------
     69      1.1  christos 
     70      1.1  christos The TOTP1 algorithm is compatible with Google Authenticator.
     71      1.1  christos 
     72      1.1  christos ---
     73      1.1  christos 
     74      1.1  christos This work is part of OpenLDAP Software <http://www.openldap.org/>.
     75      1.1  christos 
     76  1.1.1.2  christos Copyright 2015-2024 The OpenLDAP Foundation.
     77      1.1  christos Portions Copyright 2015 by Howard Chu, Symas Corp.
     78      1.1  christos All rights reserved.
     79      1.1  christos 
     80      1.1  christos Redistribution and use in source and binary forms, with or without
     81      1.1  christos modification, are permitted only as authorized by the OpenLDAP
     82      1.1  christos Public License.
     83      1.1  christos 
     84      1.1  christos A copy of this license is available in the file LICENSE in the
     85      1.1  christos top-level directory of the distribution or, alternatively, at
     86      1.1  christos <http://www.OpenLDAP.org/license.html>.
     87      1.1  christos 
     88