Home | History | Annotate | Line # | Download | only in totp
README revision 1.1.1.1
      1 TOTP OpenLDAP support
      2 ----------------------
      3 
      4 slapd-totp.c provides support for RFC 6238 TOTP Time-based One
      5 Time Passwords in OpenLDAP using SHA-1, SHA-256, and SHA-512.
      6 For instance, one could have the LDAP attribute:
      7 
      8 userPassword: {TOTP1}GEZDGNBVGY3TQOJQGEZDGNBVGY3TQOJQ
      9 
     10 which encodes the key '12345678901234567890'.
     11 
     12 It can also encode credentials consisting of a TOTP and a static
     13 password.  The format for this is:
     14 
     15 userPassword: {TOTP1ANDPW}GEZDGNBVGY3TQOJQGEZDGNBVGY3TQOJQ|<some_other_passwd>
     16 
     17 where <some_other_passwd> can be any scheme currently understood
     18 by OpenLDAP.  For example, using '{SHA}5en6G6MezRroT3XKqkdPOmY/BfQ='
     19 would encode the above TOTP with a static password of 'secret'.  To
     20 authenticate using this scheme, enter the static password immediately
     21 followed by the TOTP, for example 'secret123456'.
     22 
     23 
     24 Building
     25 --------
     26 
     27 1) Customize the LDAP_SRC variable in Makefile to point to the OpenLDAP
     28 source root.
     29 
     30 2) Run 'make' to produce slapd-totp.so
     31 
     32 3) Copy slapd-totp.so somewhere permanent.
     33 
     34 4) Edit your slapd.conf (eg. /etc/ldap/slapd.conf), and add:
     35 
     36 moduleload ...path/to/slapd-totp.so
     37 
     38 5) This module replaces the function of the slapo-lastbind overlay. You
     39 cannot use that overlay on the same database as this one.
     40 
     41 6) Restart slapd.
     42 
     43 
     44 Configuring
     45 -----------
     46 
     47 The {TOTP1}, {TOTP256}, {TOTP512}, {TOTP1ANDPW}, {TOTP256ANDPW},
     48 and {TOTP512ANDPW} password schemes should now be recognised.
     49 
     50 You can also tell OpenLDAP to use one of these new schemes when processing LDAP
     51 Password Modify Extended Operations, thanks to the password-hash option in
     52 slapd.conf. For example:
     53 
     54 password-hash	{TOTP1}
     55 
     56 TOTP password schemes will only work on databases that have a rootdn and the
     57 totp overlay configured:
     58 
     59 database mdb
     60 rootdn "..."
     61 ...
     62 
     63 overlay totp
     64 
     65 
     66 
     67 Testing
     68 -------
     69 
     70 The TOTP1 algorithm is compatible with Google Authenticator.
     71 
     72 ---
     73 
     74 This work is part of OpenLDAP Software <http://www.openldap.org/>.
     75 
     76 Copyright 2015-2021 The OpenLDAP Foundation.
     77 Portions Copyright 2015 by Howard Chu, Symas Corp.
     78 All rights reserved.
     79 
     80 Redistribution and use in source and binary forms, with or without
     81 modification, are permitted only as authorized by the OpenLDAP
     82 Public License.
     83 
     84 A copy of this license is available in the file LICENSE in the
     85 top-level directory of the distribution or, alternatively, at
     86 <http://www.OpenLDAP.org/license.html>.
     87 
     88