From 8472b394ee44cd46cc36fd4fe0a4882364cab602 Mon Sep 17 00:00:00 2001 From: Sam Chudnick Date: Sat, 2 Jul 2022 15:35:50 -0400 Subject: Read options from config file Set a standardized configuration file location and read options from there. Allow for specifiying alternate location on command line. Options can still be specified on the command line, and any command line options take priority over those given in the configuration file. --- client/client.py | 64 +++++++++++++++++++++++++++++++------------------ pam/pam.py | 40 +++++++++++++++++++++++++++++-- server/mfad.py | 73 +++++++++++++++++++++++++++++++++++++++++++++++++------- 3 files changed, 143 insertions(+), 34 deletions(-) diff --git a/client/client.py b/client/client.py index b2429b6..1c7e155 100755 --- a/client/client.py +++ b/client/client.py @@ -4,6 +4,7 @@ import socket import time import argparse import sys +import os HEADER_LENGTH = 64 KEY_LENGTH = 64 @@ -11,6 +12,7 @@ DISCONNECT_LENGTH = ACK_LENGTH = 3 ACK_MESSAGE = "ACK" DISCONNECT_MESSAGE = "BYE" FORMAT = "utf-8" +import configparser def parse_arguments(): parser = argparse.ArgumentParser() @@ -18,7 +20,7 @@ def parse_arguments(): parser.add_argument("--port",type=int,help="Port to connect to") parser.add_argument("--config",type=str,help="Path to config file",\ default="/etc/mfa/mfa.conf") - parser.add_argument("--key",type=str,help="Client connection key",required=True) + parser.add_argument("--key",type=str,help="Client connection key") return parser.parse_args() def prompt_user(prompt): @@ -53,32 +55,48 @@ def init_connection(mfa_server, client_port, client_key): def read_config(config_file): - # Read config file for server and port info - # Return tuple (server,port) - server = "" - port = 0 - with open(config_file) as conf: - line = None - while line != "": - line = conf.readline() - if line.startswith("server ="): - server = line.split("=")[1].strip() - if line.startswith("port ="): - port = int(line.split("=")[1].strip()) - return (server,port) + parser = configparser.ConfigParser(inline_comment_prefixes="#") + parser.read(config_file) + return parser + + +def get_vars(args,confparser): + if not os.path.exists(args.config): + print("Unable to open config file") + sys.exit(1) + + server = None + port = None + key = None + + # Set values from config file first + if confparser.has_section("client"): + server = confparser.get("client","server",fallback=None) + port = confparser.get("client","port",fallback=None) + key = confparser.get("client","key",fallback=None) + + # Let command line args overwrite any values + if args.server: + server = args.server + if args.port: + port = args.port + if args.key: + key = args.key + + # Exit if any value is null + if None in [server,port,key]: + print("error: one or more items unspecified") + sys.exit(1) + + return server,port,key + def main(): # Get arguments, exit if unable to connect args = parse_arguments() - client_key = args.key - - # Read server and port from config file but allow command line options - # to override those settings - mfa_server, client_port = read_config(args.config) - if args.server != None: - mfa_server = args.server - if args.port != None: - client_port = args.port + confparser = read_config(args.config) + + mfa_server,client_port,client_key = get_vars(args,confparser) # Exit if invalid key is provided if len(client_key) != KEY_LENGTH: diff --git a/pam/pam.py b/pam/pam.py index 5a2fee8..5cb9f4d 100755 --- a/pam/pam.py +++ b/pam/pam.py @@ -3,6 +3,8 @@ import socket import argparse import time import sys +import configparser +import os # Sends authentication request to MFA server # Receive either pass or fail response from MFA server @@ -40,7 +42,6 @@ def init_connection(mfa_server, pam_port): while connection == None and timeout < timeout_length: try: connection = socket.create_connection((mfa_server,pam_port)) - print("connected to mfa server") return connection except (ConnectionError,ConnectionRefusedError): time.sleep(sleep_length) @@ -63,19 +64,54 @@ def read_config(config_file): port = int(line.split("=")[1].strip()) return (server,port) + +def read_config(config_file): + parser = configparser.ConfigParser(inline_comment_prefixes="#") + parser.read(config_file) + return parser + + +def get_vars(args,confparser): + if not os.path.exists(args.config): + print("Unable to open config file") + sys.exit(1) + + server = None + port = None + + # Set values from config file first + if confparser.has_section("pam"): + server = confparser.get("pam","server",fallback=None) + port = confparser.get("pam","port",fallback=None) + + # Let command line args overwrite any values + if args.server: + server = args.server + if args.port: + port = args.port + + # Exit if any value is null + if None in [server,port]: + print("error: one or more items unspecified") + sys.exit(1) + + return server,port + + def main(): authed = "0" failed = "1" # Get arguments args = parse_arguments() + confparser = read_config(args.config) + mfa_server,pam_port = get_vars(args,confparser) user = args.user service = args.service # Compile data to send to server # Read server and port from config file but allow command line options # to override those settings - mfa_server, pam_port = read_config(args.config) if args.server != None: mfa_server = args.server if args.port != None: diff --git a/server/mfad.py b/server/mfad.py index d045e14..46fc0cc 100755 --- a/server/mfad.py +++ b/server/mfad.py @@ -7,6 +7,8 @@ import threading import pyotp import sqlite3 import re +import configparser +import argparse ## Listens for authentication request from PAM module ## Recevies connection from client @@ -16,7 +18,7 @@ import re ## Return pass or fail response to PAM moudle -DB_NAME = "mfa.db" +DB_NAME = "" HEADER_LENGTH = 64 KEY_LENGTH = 64 DISCONNECT_LENGTH = ACK_LENGTH = 3 @@ -41,6 +43,22 @@ CLIENT_SECRET_INDEX = 2 # key and a tuple of (socket,(addr,port)) as the value client_connections = dict() +def parse_arguments(): + parser = argparse.ArgumentParser() + parser.add_argument("--address",type=str,help="Bind Address") + parser.add_argument("--pam-port",type=int,help="Port to listen for PAM requests") + parser.add_argument("--client-port",type=int,help="Port for client connections") + parser.add_argument("--database",type=str,help="Path to alternate database file") + parser.add_argument("--config",type=str,help="Alternate config file location",\ + default="/etc/mfa/mfa.conf") + return parser.parse_args() + + +def read_config(config): + parser = configparser.ConfigParser(inline_comment_prefixes="#") + parser.read(config) + return parser + def eval_mfa(client_key, mfa_methods, client_response): print("response: " + client_response) @@ -228,14 +246,14 @@ def listen_pam(addr, port): ################################################################################ -def create_db(): - with sqlite3.connect(DB_NAME) as conn: +def create_db(db): + with sqlite3.connect(db) as conn: c = conn.cursor() c.execute("""CREATE TABLE applications ( username text, hostname text, service text, - client_key text, + alias text, mfa_methods text )""") c.execute("""CREATE TABLE clients ( @@ -243,16 +261,53 @@ def create_db(): key text, totp_secret text )""") + conn.commit() + + +def get_vars(args,confparser): + if not os.path.exists(args.config): + print("Unable to open config file") + sys.exit(1) + + bind_addr = None + client_port = None + pam_port = None + database = None + + # Set values from config file first + if confparser.has_section("mfad"): + bind_addr = confparser.get("mfad","address",fallback=None) + client_port = confparser.get("mfad","client-port",fallback=None) + pam_port = confparser.get("mfad","pam-port",fallback=None) + database = confparser.get("mfad","database",fallback=None) + + # Let command line args overwrite any values + if args.address: + bind_addr = args.address + if args.client_port: + client_port = args.client_port + if args.pam_port: + pam_port = args.pam_port + if args.database: + database = args.database + + # Exit if any value is null + if None in [bind_addr,client_port,pam_port,database]: + print("error: one or more items unspecified") + sys.exit(1) + + return bind_addr, int(client_port), int(pam_port), database def main(): - global connection_list - bind_addr = "127.0.0.1" - pam_port = 8000 - client_port = 8001 + args = parse_arguments() + confparser = read_config(args.config) + + bind_addr, client_port, pam_port, DB_NAME = get_vars(args,confparser) if not os.path.exists(DB_NAME): - create_db() + print("Creating DB") + create_db(DB_NAME) clients = threading.Thread(target=listen_client,args=(bind_addr,client_port)) pam = threading.Thread(target=listen_pam,args=(bind_addr,pam_port)) -- cgit v1.2.3