security-basics November 2007 archive
Main Archive Page > Month Archives  > security-basics archives
security-basics: Re: How (best) to use web-from entry of an OTP/

Re: How (best) to use web-from entry of an OTP/OPIE password to control a PF-firewall?

From: Albert T <albert.t680333_at_nospam>
Date: Tue Nov 20 2007 - 01:50:20 GMT
To: "Sean Malloy" <spinelli85@gmail.com>


Sean

> The first idea that came to my mind was authpf. Unfortunately it does not
> meet your above requirements because it requires shell access. I think
> you might want to consider using authpf instead. Here is a link to the
> authpf section in the OpenBSD PF FAQ.
>
> http://www.openbsd.org/faq/pf/authpf.html
>
> And a link to the authpf(8) man page for OpenBSD 4.2 release.
>
> http://www.openbsd.org/cgi-bin/man.cgi?query=authpf&sektion=8&manpath=OpenBSD+4.2

I didn't know about AuthPF. Interesting.

But, as you point out, only shell access, right?

My remote users need to be able to access from "any Kinko's" (for example) where there's no guarantee of Shell access, but *always* a browser at hand.

AuthPF does look like it's worth learning about.

Thanks.

Albert