Re: opie bug or ..?

From: Michael Sierchio (kudzu_at_tenebras.com)
Date: 11/03/03

  • Next message: Doug White: "Re: evolution mail client"
    Date: Mon, 03 Nov 2003 10:20:00 -0800
    To: Sergey Sysoev <lists@avtf.org>
    
    

    Forgive the top-post -- I have independently verified this,
    suggest you open a PR. This is definitely a bug in opiepasswd.
    It is also present in RELENG_4_8.

    Regards, Michael

    Sergey Sysoev wrote:
    > Hi. I have a question related to freebsd opie implementation.
    > I am running 4.9-RELEASE and I've tried to setup opie.
    >
    > *** 1 *** opiepasswd/opiekey
    >
    > I've added user using `opiepasswd -c "ssa"`
    >
    > mx2# opiepasswd -c "ssa"
    > Adding ssa:
    > Only use this method from the console; NEVER from remote. If you are using
    > telnet, xterm, or a dial-in, type ^C now or exit with no password.
    > Then run opiepasswd without the -c parameter.
    > Using MD5 to compute responses.
    > Enter new secret pass phrase:
    > Again new secret pass phrase:
    >
    > ID ssa OTP key is 499 mx1759
    > WADE IFFY LAWN MEAD DANG BUB
    > mx2#
    >
    > And now I want to change it
    >
    > mx2# opiepasswd "ssa"
    > Updating ssa:
    > You need the response from an OTP generator.
    > New secret pass phrase:
    > otp-md5 499 mx17
    > Response:
    >
    > You see that seed equal 'mx17', using opiekey:
    >
    > mx2# opiekey 499 mx17
    > Using the MD5 algorithm to compute response.
    > Seeds must be greater than 5 characters long.
    > mx2#
    >
    > So it is not possible to update password in /etc/opiekey file, you
    > have to edit it manually and that add password again via 'opiepasswd'.
    >
    >
    >
    > *** 2*** opiekey
    >
    > opiekey could not generate response for zero sequence number when it
    > specified directly:
    >
    > mx2# opiekey -a 0 vo6199
    > Using the MD5 algorithm to compute response.
    > Sequence number 0 is not positive.
    >
    > but it works fine in case of:
    >
    > mx2# opiekey -n5 1 vo6199
    > Using the MD5 algorithm to compute response.
    > Reminder: Don't use opiekey from telnet or dial-in sessions.
    > Enter secret pass phrase:
    > 0: OAK SEW CULT FALL AX WAND
    > 1: BOUT AID SOOT BUT SIT BILK
    > mx2#
    >
    > *** 3 *** pam_opie.so, the most interesting thing
    >
    > After successful login with 0 sequence number, trying to do it again
    > (sequence number has been decreased, right?)
    >
    > mx2# ssh ssa@192.168.90.250
    > otp-md5 -1 (null) ext
    > Password:
    >
    > Is it impossible to calculate response to '-1' so trying to use any
    > password to skip pam_opie and login with next pam module. But here
    > login hangs and there is _no_way_ to login remotely because
    > pam_opie.so is the top line of pam.conf
    >
    > After about 1-2 minutes timeout it just says "Connection closed by 192.168.90.250"
    >
    >
    > *** 4 *** now just a question
    >
    > (In case of fix) After 0 or 1 seq. number it should recount from the
    > beginning, for example from 499, but I think that seed should be
    > automatically changed in that case for next 500 iterations otherwise
    > that is not one-time-passwords
    >
    >
    >
    > So... I think that is not good ... or am I mistaken?
    >
    >

    -- 
    "Well," Brahma said, "even after ten thousand explanations, a fool is no
      wiser, but an intelligent man requires only two thousand five hundred."
                     - The Mahabharata
    _______________________________________________
    freebsd-stable@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-stable
    To unsubscribe, send any mail to "freebsd-stable-unsubscribe@freebsd.org"
    

  • Next message: Doug White: "Re: evolution mail client"

    Relevant Pages

    • Re: opie bug or ..?
      ... This is definitely a bug in opiepasswd. ... > Enter new secret pass phrase: ... > You need the response from an OTP generator. ... > Sequence number 0 is not positive. ...
      (freebsd-questions)
    • Re: Handling outputs (yes, an *on* topic thread!)
      ... Perhaps, in the future, ordering a part would create as response for ... >> column that gives the sequence of messages, and rows within a message, by ... Anything else will be deleted when the user logs out ... Like I said, for the GUI, we're already using a table. ...
      (comp.lang.cobol)
    • 0590353334 - her context was numerous, joint, and qualifys in relation to the valley
      ... Julieta rents in response to ... Why does Ayub affect so exclusively, ... bizarre childhoods amid a sequence. ... Every corporate precise causes evidently publish as the flying ...
      (sci.crypt)
    • Re: I f I cant, no-one should
      ... knows, but no-one admits my Victory, due to this phrase. ... script will want to decipher it from one lone document, ... that if the Phaistos disk has "latent symmetries" and what you imagine ... I don't understand his response this time. ...
      (sci.lang)
    • Re: You be the judge
      ... More common sequence than this strong club sequence) ... opens 1H and hears a 1S response. ... What is South to rebid? ... waiting bid, a relay if you will, that functions in much the same way ...
      (rec.games.bridge)