Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

1.79 x 10^12 furlongs per fortnight -- it's not just a good idea, it's the law!


devel / comp.protocols.kerberos / Re: help with OTP

SubjectAuthor
o Re: help with OTPKen Hornstein

1
Re: help with OTP

<mailman.76.1682545901.1964.kerberos@mit.edu>

  copy mid

https://www.rocksolidbbs.com/devel/article-flat.php?id=359&group=comp.protocols.kerberos#359

  copy link   Newsgroups: comp.protocols.kerberos
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!tncsrv06.tnetconsulting.net!.POSTED.mailman.mit.edu!not-for-mail
From: kenh@cmf.nrl.navy.mil (Ken Hornstein)
Newsgroups: comp.protocols.kerberos
Subject: Re: help with OTP
Date: Wed, 26 Apr 2023 17:51:29 -0400
Organization: TNet Consulting
Lines: 12
Message-ID: <mailman.76.1682545901.1964.kerberos@mit.edu>
References: <CAOLfK3WVppnk3eouiLTxhiR5gXQcCVd7K5xr_erP=y_RkeVpPw@mail.gmail.com>
<202304242225.33OMPJdw026540@hedwig.cmf.nrl.navy.mil>
<CAOLfK3XZF95-XoaW8y8cMrMETpWQNV-=EEkMyreo18WXH5M3sg@mail.gmail.com>
<CAJhaRZ+wc0N_YX06jdsh8iHTSn1dJoH3bn6q6Mm0V35h-8FARg@mail.gmail.com>
<CAOLfK3Xs9X25-jY+GjXqmNEOYbSNSVMXdBojX=k28FWqenWG+A@mail.gmail.com>
<CAJhaRZJP+Cz0RkSyOaWmjH5UHjye43k7B9G=dRechpN3Ad4qXg@mail.gmail.com>
<CAOLfK3VOZSNFhpkSKy5XsaA2mFUDVCGdjjZdna_O8M2RaAZPyw@mail.gmail.com>
<202304260001.33Q01xYH024064@hedwig.cmf.nrl.navy.mil>
<7586f99f-1c5e-f8c9-e128-eb457508556b@mit.edu>
<202304261528.33QFSGrc012160@hedwig.cmf.nrl.navy.mil>
<871qk61nfo.fsf@hope.eyrie.org>
<202304262151.33QLpVVl002264@hedwig.cmf.nrl.navy.mil>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="mailman.mit.edu:18.7.21.50";
logging-data="28254"; mail-complaints-to="newsmaster@tnetconsulting.net"
To: <kerberos@mit.edu>
Authentication-Results: mit.edu; dmarc=pass (p=reject dis=none)
header.from=cmf.nrl.navy.mil
Authentication-Results: mit.edu; arc=pass smtp.remote-ip=18.9.3.18
ARC-Seal: i=2; a=rsa-sha256; d=mit.edu; s=arc; t=1682545899; cv=pass;
b=Qv08vBaGBRWvWElE82qdl6sD04KZt6a9IbS+PlgOownyWDlb89l9deztzeY13jfrlE3cyOjcMLqc1hvQie1bhEh3OBnJqP1B2HmXLb0wlo7CAKdpi7ThoVIHv+1+NTDNHD/hSQacNxuWq1EabewzTj+eSV/zqWff4Ig5Z7KpjyCD0o0LgVPYrQZLxPdrrj6kKcj29FmYjCnovT9wbBzqBTj9HvMReSsbdZT1SFindlAr7wAH2x22SdtuHU2iFklEGTSwISgkaPXoLVqIl2RNzF/nQoFMt7ddHRfBrhXXJj5mY4nZsePkX9LPB4RUgpWRWK3kOxRFFs5AOSlr4QT+fQ==
ARC-Message-Signature: i=2; a=rsa-sha256; d=mit.edu; s=arc; t=1682545899;
c=relaxed/relaxed; bh=PweRub4FXfgbEgFGeA/sLCFdSdyvatLh+xtkORUYNog=;
h=DKIM-Signature:DKIM-Signature:Message-ID:From:To:Subject:
MIME-Version:Date;
b=Pkley0cVzk+v4bc5hl2s8+a3yXXRYfLjQeyXj78mUVNolBnoaF22l0ne4NEQoc/7oEqXADIsQUTmBJaZ7ZC8pb/Pp6dO9uZ8JQ7dyXY+1DpLQ/mNj0CkpqySx+r5ligyJHd3tu6RhUb3Hl9TjQB2qGvB+wkv9Q1G16DIVzA1UflL5zGnKWYKckt3s09g39MDnutryew0JPYO5//66G4KZ2Si3dQF4azGeQnRbf2ihd4xpORI3ac3ZLuTpLJLVJRfnHNxbzelrhyoNfIKJoSctEk3HIG+1wOakc8tk3I5POvJUEGddc0BuVuKKk+h4Db4qwzHW3V6GS5gxkCjxUCYOA==
ARC-Authentication-Results: i=2; mit.edu; dkim=pass (1024-bit key)
header.d=mitprod.onmicrosoft.com header.i=@mitprod.onmicrosoft.com
header.b=FklgjDKz;
dkim=pass (2048-bit key) header.d=nrl.navy.mil header.i=@nrl.navy.mil
header.b=MCEjCJYJ
Authentication-Results: mit.edu;
dkim=pass (1024-bit key) header.d=mitprod.onmicrosoft.com
header.i=@mitprod.onmicrosoft.com header.b=FklgjDKz;
dkim=pass (2048-bit key) header.d=nrl.navy.mil header.i=@nrl.navy.mil
header.b=MCEjCJYJ
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=WQvs960u/xE8V41F3v5cdjJTwNQ18cZ6Zjjo8Okz2D5wHhWh4BkyeycuQKRlqbtrqs1i+u9k33qemwRUfot71Xo/+/HPDUUV+/UyVEusHYLVeOvXLLrO6cPMl1WhJjpYGc+W2fbA1CX9ekO1jUFF7BwxLOIV988BKNrrQQbvMkJToOcjm4qrbWYTy+1zae/3vFW9dTvxabAkApx2+bszkb7YDemFzx9BcCUWK4QV6izAy/3z9HvPkVxVmSMFCoDS6IfFZzCy1P1rSEhlcARxI8QopyIfJgUa0e6Zk2kqTmELpTIFO7QNGcOmTUc9oi+JS3tnMRLjyb8jzx/GOppqSw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=PweRub4FXfgbEgFGeA/sLCFdSdyvatLh+xtkORUYNog=;
b=IHixqTAnnXHiy2TZMG/NaLRwQfCD2LpOT9ReGhJS8z+laJZPKp3W5LqNrXd0Nn4jrw7G/SMiQiuNv7rYXep21IkvdyDEI5yoshuplr5jY2yOCULWsbnt+4Y+RNu6ipH1Y1qRMQ9FNvu5Hh5L+Y4Cy27/kj697NSV7ERZynZOBvk3VKX2KuuL438QO9tsNVvO/+xdJiTIJLOPJK2lkozZAvhjFRNHQYaMBtJ8AUJ65oi1nL4/8F8alnC9N1JsjFY8kW2SNI4tUZQkZnyyCzvbk0TrpkT8/JeVKSSBU1DaoMlPwOONmMc200cCB0GUNQ9eM6wyBybPhtlN9BaYMLw4iw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is
140.32.59.234) smtp.rcpttodomain=mit.edu smtp.mailfrom=cmf.nrl.navy.mil;
dmarc=pass (p=reject sp=reject pct=100) action=none
header.from=cmf.nrl.navy.mil; dkim=pass (signature was verified)
header.d=nrl.navy.mil; arc=none (0)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=mitprod.onmicrosoft.com; s=selector2-mitprod-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=PweRub4FXfgbEgFGeA/sLCFdSdyvatLh+xtkORUYNog=;
b=FklgjDKz7g809+qWTVOwHIvYdXD0HgvvvPVRgy7wFRA3fTIa68+W+pOlOgc8f3KHnZuSKTPCKsYBRhnybczfX/wxQkDFSL09/ZbjOhtH5WK1LWV1FQCcwgNfnqy+iFDBsL1kQQgZOvsOWYqrA+HI0aW/hemHbBQy5rQ8QIwsZ7g=
Authentication-Results: spf=pass (sender IP is 140.32.59.234)
smtp.mailfrom=cmf.nrl.navy.mil; dkim=pass (signature was verified)
header.d=nrl.navy.mil;dmarc=pass action=none header.from=cmf.nrl.navy.mil;
Received-SPF: Pass (protection.outlook.com: domain of cmf.nrl.navy.mil
designates 140.32.59.234 as permitted sender)
receiver=protection.outlook.com; client-ip=140.32.59.234; helo=mf.dren.mil;
pr=C
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nrl.navy.mil;
h=message-id : from :
to : subject : in-reply-to : references : mime-version : content-type :
date; s=s2.dkim; bh=PweRub4FXfgbEgFGeA/sLCFdSdyvatLh+xtkORUYNog=;
b=MCEjCJYJlhEVbCM3a1ay9n0bSETUYgZ8sXnRmi1tllZIjdX0QgMnS177FP4XRJE2eOJQ
lFNeViYwHg5nzxJFnX/rnUoUmyiIR1zmCGXpAdD7ck/kpGSdCY1xCHV0Crnqs8ljRgLK
0KgoBrnLz7azsg0I9zgYR+4uLWqoPnWwxFrqwT8DFXswwvVCjfNbE3okWpdpY/pCpsZQ
Tx86J/jqyaiyhLOPeaaoyr0cvyhHqaQrz4/A1aswb1mLMpx+C5KPBjNDP8viruy1xcuA
nsWaUJHUMUfis2QHmSqBM8j9VV6/F2zLErv5KRC+0xRH4HMDSWKy+UeW9bBaGvImTwpY gw==
In-Reply-To: <871qk61nfo.fsf@hope.eyrie.org>
X-Face: "Evs"_GpJ]],xS)b$T2#V&{KfP_i2`TlPrY$Iv9+TQ!6+`~+l)#7I)0xr1>4hfd{#0B4
WIn3jU;bql;{2Uq%zw5bF4?%F&&j8@KaT?#vBGk}u07<+6/`.F-3_GA@6Bq5gN9\+s;_d
gD\SW #]iN_U0 KUmOR.P<|um5yP<ea#^"SJK;C*}fMI;Mv(aiO2z~9n.w?@\>kEpSD@*e`
X-NRLCMF-Spam-Score: () hits=0 User Authenticated
X-NRLCMF-Virus-Scanned:
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: DM6NAM11FT036:EE_|DM6PR01MB5865:EE_
X-MS-Office365-Filtering-Correlation-Id: a22b24cd-88f5-499d-810f-08db46a0667b
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-MS-Exchange-SenderADCheck: 0
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: mj4Boq4DVSusfKi3kEEqMzyqjADTWwktO1PnSVHI/giaMypXNF+kjecWHEBss/ASuVPtClD/pNunbKUz8W41czoCe0JiXqtA3HlUBIb5rz2zTOtC82m6SagRg/noqtnjkvlEY6lySEC7zzzEP+WwciG3RUx6dcivYB+W7958wWp0djUTyvAzk88rJF40v7hKkIBD5Hgi2+QWwtwsgCZN7O8TlYPCoQ8pntdqQz69idFu4hF6l5hHsMS8VBT3iJLsm7EeJo+njMByGy6ZzIb4dIW42FIipwCihOD2RH3Tsbf9NwLzWjRjf3LZ0G4H3RQAEJJ9wnPX1kil0ap3OLvON2VaEbDro5JvWfeGbCtxFiPzC/2cfLXvtWI5NCej1sumwrf4IC0rvBIPku8s1c99TyIB76UAuX5Zt/M74E2/RP/w4i1NOz6FZ3uEMd6QDwT/vGs5tYllYUF0w/pZriCWT7l6DcypuM5XJiwHT0+AY0W3z4lMa7rcGgAGHdBccveFz69xOXgWOfVxAYEDoEdG/Ovaxn/cBzcXcB/EKrT1N8isrfQ5Nh+UYPVpw+2+Dh/VoXwXny5qQCcOVXBcxbcqVTIJMFjYxtikwxWJG4ZSZVA=
X-Forefront-Antispam-Report: CIP:140.32.59.234; CTRY:US; LANG:en; SCL:1; SRV:;
IPV:NLI; SFV:NSPM; H:mf.dren.mil; PTR:mfe.dren.mil; CAT:NONE;
SFS:(13230028)(4636009)(396003)(136003)(39860400002)(346002)(376002)(451199021)(1076003)(26005)(498600001)(5660300002)(7116003)(8676002)(6862004)(2906002)(4744005)(786003)(86362001)(316002)(68406010)(70586007)(7636003)(356005)(3480700007)(956004)(426003)(336012);
DIR:OUT; SFP:1102;
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 26 Apr 2023 21:51:33.0201 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: a22b24cd-88f5-499d-810f-08db46a0667b
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: DM6NAM11FT036.eop-nam11.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM6PR01MB5865
X-OriginatorOrg: mitprod.onmicrosoft.com
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/options/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos/>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
X-Mailman-Original-Message-ID: <202304262151.33QLpVVl002264@hedwig.cmf.nrl.navy.mil>
X-Mailman-Original-References: <CAOLfK3WVppnk3eouiLTxhiR5gXQcCVd7K5xr_erP=y_RkeVpPw@mail.gmail.com>
<202304242225.33OMPJdw026540@hedwig.cmf.nrl.navy.mil>
<CAOLfK3XZF95-XoaW8y8cMrMETpWQNV-=EEkMyreo18WXH5M3sg@mail.gmail.com>
<CAJhaRZ+wc0N_YX06jdsh8iHTSn1dJoH3bn6q6Mm0V35h-8FARg@mail.gmail.com>
<CAOLfK3Xs9X25-jY+GjXqmNEOYbSNSVMXdBojX=k28FWqenWG+A@mail.gmail.com>
<CAJhaRZJP+Cz0RkSyOaWmjH5UHjye43k7B9G=dRechpN3Ad4qXg@mail.gmail.com>
<CAOLfK3VOZSNFhpkSKy5XsaA2mFUDVCGdjjZdna_O8M2RaAZPyw@mail.gmail.com>
<202304260001.33Q01xYH024064@hedwig.cmf.nrl.navy.mil>
<7586f99f-1c5e-f8c9-e128-eb457508556b@mit.edu>
<202304261528.33QFSGrc012160@hedwig.cmf.nrl.navy.mil>
<871qk61nfo.fsf@hope.eyrie.org>
 by: Ken Hornstein - Wed, 26 Apr 2023 21:51 UTC

>I worked through a bunch of this for pam-krb5 back in the day and made it
>support a set of reasonable things, including anonymous PKINIT to
>establish the FAST armor. People who are working in this area may find
>its source code useful to look at, although I think there have been
>improvements since then and what it does may no longer be best practice.
>
>https://github.com/rra/pam-krb5/blob/main/module/fast.c

Thanks, Russ! I will definitely use this as a starting point sometime
in the future.

--Ken

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor