Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

Installation instructions

Warning: OTPme is alpha software. Do not use it in production. Expect breaking changes, incomplete features and bugs.

Full documentation is available at https://otpme.readthedocs.io.

Manpages can be installed with:

otpme-install-manpages

Install debian dependencies

apt-get install python3.11-venv gobjc++ python3-pybind11 python3-dev build-essential cmake gcc dbus-x11 freeradius freeradius-python3 libacl1-dev libnss-cache liboath0 liboath-dev libpcsclite1 libpq-dev libre2-9 libre2-dev libsystemd-dev pkg-config postgresql postgresql-server-dev-all pwgen pyflakes3 redis redis-server redis-tools libpcsclite-dev ykcs11 fuse3 libpam-python

Disable installed services

systemctl stop redis
systemctl disable redis
systemctl stop postgresql
systemctl disable postgresql
systemctl stop freeradius
systemctl disable freeradius

Install otpme

Add otpme system user

useradd -r -U -d /var/lib/otpme otpme

Enable nsswitch nsscache module

Edit /etc/nsswitch.conf and append 'cache' to the lines passwd, shadow and group.

Create python venv

python3 -m venv /opt/otpme
. /opt/otpme/bin/activate

Install otpme and dependencies

pip3 install cython

Pick the install variant matching what this machine should do:

Command Role
pip3 install otpme host — client + otpme-agent + PAM + nsscache + offline login. Default.
pip3 install 'otpme[backuphost]' backup host — backup server for nodes, shares and hosts.
pip3 install 'otpme[ssohost]' SSO portal host — front-end for the SSO/OIDC web portal. Holds no backend secrets, so it can be deployed into the DMZ.
pip3 install 'otpme[node]' node — full server install, all features.
pip3 install 'otpme[node,dev]' full server + dev tools (pytest, coverage, ruff).

The backuphost and ssohost roles are activated by setting BACKUP_SERVER resp. SSO_SERVER to True in /etc/otpme/otpme.conf.

Copy configuration files

cp -a /opt/otpme/lib/python3.11/site-packages/etc/otpme /etc/
cp -a /etc/otpme/otpme.conf.dist /etc/otpme/otpme.conf

Edit /etc/otpme/otpme.conf

POSTGRES_PG_CTL_BIN="/usr/lib/postgresql/15/bin/pg_ctl"

Create PYTHONPATH file with path to venv (e.g. /opt/otpme/lib/python3.11/site-packages/)

/etc/otpme/PYTHONPATH

Init your otpme realm

otpme-realm --api -ddee --color-logs -f init --ca-key-len 2048 --site-key-len 2048 --node-key-len 2048 --dicts english,en-top10000,common-passwords,us-female,us-male,us-surnames,abbreviations-it --id-ranges "uidNumber:s:100000-200000,gidNumber:s:100000-200000" yourrealm.tld yoursite localhost 127.0.0.1

Note: Scan the generated QRCode with the "Google Autenticator App" and note the PIN of the admin token.

Start OTPme daemons

otpme-controld start

Login with admin token

You need to input pin+otp.
otpme-tool login

Add optional U2F/fido2 attestation certificates from https://developers.yubico.com/FIDO/yubico-fido-ca-certs.txt.

wget https://developers.yubico.com/FIDO/yubico-fido-ca-1.pem
wget https://developers.yubico.com/FIDO/yubico-fido-ca-2.pem
otpme-site add_fido2_ca_cert yoursite yubico-fido-ca-1.pem
otpme-site add_fido2_ca_cert yoursite yubico-fido-ca-2.pem
otpme-site config yoursite check_fido2_attestation_cert True

Disable gpg-agent (systemd) to use yubikey/GPG card with the PAM module.

systemctl --global mask --now gpg-agent.service gpg-agent.socket gpg-agent-ssh.socket gpg-agent-extra.socket gpg-agent-browser.socket

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

otpme-0.3.0a237.tar.gz (6.7 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

otpme-0.3.0a237-py3-none-any.whl (7.2 MB view details)

Uploaded Python 3

File details

Details for the file otpme-0.3.0a237.tar.gz.

File metadata

  • Download URL: otpme-0.3.0a237.tar.gz
  • Upload date:
  • Size: 6.7 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.11.2

File hashes

Hashes for otpme-0.3.0a237.tar.gz
Algorithm Hash digest
SHA256 406a0fb2e117a2e7fc93b7e2d38c8f50b11bf9ef92dd851482484a627a03880f
MD5 b0569432b9f5a6f2e11ef8b43c48db92
BLAKE2b-256 389f11585292e96f20aa6cc174abc2f8e87d8bfe23dc54e65294a7e1ec99572d

See more details on using hashes here.

File details

Details for the file otpme-0.3.0a237-py3-none-any.whl.

File metadata

  • Download URL: otpme-0.3.0a237-py3-none-any.whl
  • Upload date:
  • Size: 7.2 MB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.11.2

File hashes

Hashes for otpme-0.3.0a237-py3-none-any.whl
Algorithm Hash digest
SHA256 a12bcdd2f2c91dde9eef50c6df492ed1d65c59a1466d209e722c6c45b208e9d8
MD5 39f428e60dfc30404381112e33d8d66b
BLAKE2b-256 d9004c29fd328e463a1e0a411e5ee3154bd8bb5dcb1441a29a4423081659a382

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

0.3.0a237 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page