Re: Add support for Access-Challenge response for OTP/RADIUS
Alexander Bokovoy <[email protected]> Thu, 10 Jun 2021 18:15:58 +0300
| Newsgroups | gmane.comp.encryption.kerberos.devel |
|---|---|
| Message-ID | <[email protected]> |
On to, 10 kesä 2021, Greg Hudson wrote: >On 6/9/21 3:36 AM, Alexander Bokovoy wrote: >> - check if 'otp' string is present in the rock config >> - if it is present, check if it contains a challenge request flag >> - if challenge request flag is present, ask RADIUS server for the >> information and expect it to return Access-Challenge with the >> State attribute. >> - if Access-Challenge is missing, fail OTP processing >> - if Access-Challenge is present, set the challenge of the token >> info into the challenge value from the RADIUS packet > >This sounds reasonable. > >> What we also need is to preserve the state from Access-Challenge to be >> reused when client response would come back. > >Have a look at the set_cookie() and get_cookie() callbacks in the >kdcpreauth interface. You can find an example of their use in >plugins/preauth/spake/spake_kdc.c. Thanks, that looks like what we need. Pavel, does this clarify a question for you too? -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland _______________________________________________ krbdev mailing list [email protected] https://mailman.mit.edu/mailman/listinfo/krbdev