Folks,
Now that an update to XEP-0388 has been published, I thought I'd
share what I've been trying to do with it. I'll be tidying up some
actual code this morning and making a PR into Openfire, but the
general idea is to use the tasks that can be required by a <continue/>
in SASL2 in order to provide two capabilities - 2FA using TOTP (or
Google Authenticator if you prefer) and enforced password changes.
These encompass three tasks:
1) PASSWORD-RESET
Wherein the client sends a response (optionally, an initial response)
containing the client's preferred new password. As usual for SASL2,
exchanges are base64-encoded (and potentially binary, though not in
this instance).
<!-- Server: -->
<continue>
<tasks>
<task>PASSWORD-RESET</task>
</tasks>
</continue>
<!-- Client: -->
<next task='PASSWORD-RESET'>
<initial-response>MTIzNDU=</initial-response>
</next>
<!-- Server might well go straight into the next bit: -->
2) TOTP-INIT
Wherein the server sends (first) a new TOTP URI in the Google format.
The client then (one assumes) hands it to the TOTP device via QR code
- please don't use the Google service to render your shared secret, by
the way - and then the client sends an ASCII rendering of the code. On
receipt, the server then stores the generated shared secret against
the user's account.
<!-- Server: -->
<continue>
<tasks>
<task>TOTP-INIT</task>
<tasks>
</continue>
<!-- Client: -->
<next task='TOTP-INIT'/>
<!-- Server: -->
<challenge>
SSBjYW4ndCByZW1lbWJlciB0aGUgVVJJIGZvcm1hdCBoZXJlLg==
</challenge>
<!-- Client: -->
<response>MTIzNDU2</response>
<!-- Server: -->
<success>
<authorization-identifier>[email protected]</authorization-identifier>
</success>
<stream:features>
<bind/>
</stream:features>
3) TOTP
Wherein the client sends (as an initial response if possible) a TOTP
code generating from a secret previously shared (possibly via
TOTP-INIT).
<!-- Server: -->
<continue>
<tasks>
<task>TOTP</task>
<tasks>
</continue>
<!-- Client: -->
<next task='TOTP'>
<initial-response>MTIzNDU2</initial-response>
<next>
<!-- Server: -->
<success>
<authorization-identifier>[email protected]</authorization-identifier>
</success>
<stream:features>
<bind/>
</stream:features>
So...
Anyone have comments? Think this should be done another way? Shall I
go ahead and write these up as a XEP or two?
Dave.
_______________________________________________
Standards mailing list
Info: https://mail.jabber.org/mailman/listinfo/standards
Unsubscribe: [email protected]
_______________________________________________