Skip to main content

libpam-hotp is a PAM (Pluggable Authentication Modules) module written in Python to authenticate users using an OTP (One Time Password) generated with the HOTP algorithm.

1. Installation

libpam-hotp depend of libpam-python which is packaged into all major distro. The module have been tested with Python 2.6, maybe it also work with 2.5, and certainly with 2.7 version.

After installing the dependencies, you can drop pam_hotp.py into /lib/security directory.

Next step is to setup PAM, and create a file with all your token seeds.

2. Configuration of PAM

libpam-hotp use libpam-python, the latter is actually the called module for PAM, thereby, your rule line will look like this:

auth [POLICY] pam_python.so pam_hotp.py [OPTIONS]

Available options are:

  • file: path to file that store user login - secret seeds mapping (default to /etc/hotp).

Example:

auth sufficient pam_python.so pam_hotp.py file=/etc/hotp_ssh

NOTE: This module only provide the AUTH mecanism.

3. Seeds file:

Seed file store the mapping between an user login and the secret seed code of user’s token.

Each line of this file is an association, each field is separated by an “:” char. The three first fields are mandatory:

  • User login

  • Secret seed code (encoded in hexadecimal form)

  • The number of seconds for a period (see your token datasheet)

You can add two additionals fields:

  • The maximum allowed number of drift periods

  • An hash, used to prompt an additionnal password to the user.

The hash is encoded with it salt with this format: SALT$HASH, hash function is SHA1(CONCAT(PASSWORD, SALT)).

Example:

Here is a complete example for the user stallman, with a token-period of 30 seconds, a maximum drift of 3 periods, and an additionnal password “richard”:

stallman:11223344556677889900AABBCCDDEEFF:30:3:6jsd3$1b6a67161e1cca2b1cd014c59b5bc907435cf8e7

Release files for libpam_hotp 0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for libpam_hotp 0.1
File Size Uploaded
libpam_hotp-0.1.tar.gz 2.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for libpam_hotp 0.1
File Interpreter ABI Platform
libpam_hotp-0.1-py2.6.egg Legacy Egg format - - Details

Total release size: 4.4 kB

Release files / libpam_hotp-0.1.tar.gz

Download URL libpam_hotp-0.1.tar.gz
Size 2.3 kB
Tags Source
SHA-256 checksum
How to use checksums
2d669c0dab66f0de43abfc64011a0af7559c81960dbbe8a581c1ffdf924ab9f1
BLAKE2b-256 checksum
How to use checksums
af894ee5b8b6ac26a5fd49bb0f48713014a9eeac8548a49f20d50897dfe8d6ce
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release files / libpam_hotp-0.1-py2.6.egg

Download URL libpam_hotp-0.1-py2.6.egg
Size 2.1 kB
Tags Egg
SHA-256 checksum
How to use checksums
a5d5269c134e5854390fa2f275474cda363910d365eeb6e117887e8099340b66
BLAKE2b-256 checksum
How to use checksums
d2466094a11f19b433612a8c1a61b5aeeff72eaa99955c226acd311bbe45ccf8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release history Release notifications | RSS feed

This release

0.1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page