|
|
|
|
@ -4,8 +4,9 @@ What is this thing? |
|
|
|
|
|
|
|
|
|
This device is a hash-based-one-time-password (=HOTP, RFC 4226) generator. You |
|
|
|
|
can use them to make an existing authentication more secure or as a single |
|
|
|
|
authentication barrier to enter a system. You can easily do both on linux |
|
|
|
|
machines using the oath toolkit (http://www.nongnu.org/oath-toolkit/). |
|
|
|
|
authentication barrier to enter a system (although I wouldn't recoment that). |
|
|
|
|
You can easily do both on linux machines using the oath toolkit |
|
|
|
|
(http://www.nongnu.org/oath-toolkit/). |
|
|
|
|
|
|
|
|
|
How does it work? |
|
|
|
|
----------------- |
|
|
|
|
@ -18,7 +19,7 @@ sequence usually happens like this: |
|
|
|
|
3. Confirm the login by pressing the button on the device this will |
|
|
|
|
generate an ENTER-keystroke and the internal counter is icremented |
|
|
|
|
by one. |
|
|
|
|
4. Pressing the button again reset the device, and the sequence |
|
|
|
|
4. Pressing the button again resets the device, and the sequence |
|
|
|
|
repeats. Otherwise just unplug it. |
|
|
|
|
|
|
|
|
|
How to install the firmware? |
|
|
|
|
@ -35,12 +36,25 @@ It is recomended to take a secret of length 20 (longer secrets are supported but |
|
|
|
|
do not provide additional security). This is basically a sha1 digest. I usually |
|
|
|
|
do the following to generate secrets: |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
>head /dev/urandom | sha1sum |
|
|
|
|
11d64fc6fcff5f198976b86cc590fb58a04dc422 - |
|
|
|
|
|
|
|
|
|
The resulting define would be: |
|
|
|
|
|
|
|
|
|
type make. If the compilation runs well, you will end up with some .hex files: |
|
|
|
|
SECRET = -DSECLEN=20 -DSECRET="{0x11, 0xd6, 0x4f, 0xc6, 0xfc, 0xff, ...}" |
|
|
|
|
|
|
|
|
|
Once you're done simply type make. If the compilation runs well, you will end |
|
|
|
|
up with some .hex files: |
|
|
|
|
- The main file: hotp.hex (this goes to the flash) |
|
|
|
|
- The eeprom init: eeprom.hex (this goes to the internal eeprom) |
|
|
|
|
|
|
|
|
|
You can upload them by typing "make install". |
|
|
|
|
Now configure the server side: Provide the secret you just used, the initial |
|
|
|
|
counter value is 0 (Remember to keep a working terminal somewhere in case you |
|
|
|
|
lock yourself out). After doing this try to login, if it works you should |
|
|
|
|
remove the secret from the makefile and also prevent the microcontroller from |
|
|
|
|
beeing read. Do this by typing "make lock" |
|
|
|
|
|
|
|
|
|
Security considerations: |
|
|
|
|
------------------------ |
|
|
|
|
|
|
|
|
|
|