Skip to content
This repository was archived by the owner on May 27, 2024. It is now read-only.
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 8 additions & 4 deletions bin/tacacs_client
Original file line number Diff line number Diff line change
Expand Up @@ -58,6 +58,8 @@ def parse_args():
authentication = command.add_parser('authenticate', help="authenticate against a tacacs+ server")
if not user_password:
authentication.add_argument('-p', '--password', required=False, help="user password")
authentication.add_argument('-i', '--chap-id', required=False, help="CHAP ID")
authentication.add_argument('-c', '--chap-challenge', required=False, help="CHAP Challenge")

authorization = command.add_parser('authorize', help="authorize a command against a tacacs+ server")
authorization.add_argument('-c', '--cmds', required=True, nargs='+', help="list of cmds to authorize")
Expand Down Expand Up @@ -108,11 +110,13 @@ def authenticate(cli, args):
if not vars(args).get('password'):
args.password = getpass.getpass('password for %s: ' % args.username)

chap_ppp_id = None
chap_challenge = None
chap_ppp_id = args.chap_id
chap_challenge = args.chap_challenge
if args.authen_type == TAC_PLUS_AUTHEN_TYPE_CHAP:
chap_ppp_id = six.moves.input('chap PPP ID: ')
chap_challenge = six.moves.input('chap challenge: ')
if chap_ppp_id == None:
chap_ppp_id = six.moves.input('chap PPP ID: ')
if chap_challenge == None:
chap_challenge = six.moves.input('chap challenge: ')
auth = cli.authenticate(args.username, args.password, priv_lvl=args.priv_lvl,
authen_type=args.authen_type, chap_ppp_id=chap_ppp_id,
chap_challenge=chap_challenge, rem_addr=args.rem_addr,
Expand Down
8 changes: 7 additions & 1 deletion tacacs_plus/authentication.py
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,8 @@
from .flags import (
TAC_PLUS_PRIV_LVL_MIN, TAC_PLUS_AUTHEN_LOGIN, TAC_PLUS_AUTHEN_SVC_LOGIN,
TAC_PLUS_AUTHEN_STATUS_PASS, TAC_PLUS_AUTHEN_STATUS_FAIL, TAC_PLUS_AUTHEN_STATUS_ERROR,
TAC_PLUS_AUTHEN_STATUS_GETPASS, TAC_PLUS_VIRTUAL_PORT, TAC_PLUS_VIRTUAL_REM_ADDR
TAC_PLUS_AUTHEN_STATUS_GETPASS, TAC_PLUS_VIRTUAL_PORT, TAC_PLUS_VIRTUAL_REM_ADDR,
TAC_PLUS_AUTHEN_STATUS_GETDATA
)


Expand Down Expand Up @@ -165,11 +166,16 @@ def error(self):
def getpass(self):
return self.status == TAC_PLUS_AUTHEN_STATUS_GETPASS

@property
def getdata(self):
return self.status == TAC_PLUS_AUTHEN_STATUS_GETDATA

@property
def human_status(self):
return {
TAC_PLUS_AUTHEN_STATUS_PASS: 'PASS',
TAC_PLUS_AUTHEN_STATUS_FAIL: 'FAIL',
TAC_PLUS_AUTHEN_STATUS_GETDATA: 'GETDATA',
TAC_PLUS_AUTHEN_STATUS_GETPASS: 'GETPASS',
TAC_PLUS_AUTHEN_STATUS_ERROR: 'ERROR'
}.get(self.status, 'UNKNOWN: %s' % self.status)
Expand Down
13 changes: 13 additions & 0 deletions tacacs_plus/client.py
Original file line number Diff line number Diff line change
Expand Up @@ -221,6 +221,19 @@ def authenticate(self, username, password, priv_lvl=TAC_PLUS_PRIV_LVL_MIN,
]))
if reply.flags == TAC_PLUS_CONTINUE_FLAG_ABORT:
reply.status = TAC_PLUS_AUTHEN_STATUS_FAIL
if authen_type == TAC_PLUS_AUTHEN_TYPE_ASCII and reply.getdata:
response = input(reply.server_msg)
packet = self.send(TACACSAuthenticationContinue(response),
TAC_PLUS_AUTHEN,
packet.seq_no + 1)
reply = TACACSAuthenticationReply.unpacked(packet.body)
logger.debug('\n'.join([
reply.__class__.__name__,
'recv header <%s>' % packet.header,
'recv body <%s>' % reply
]))
if reply.flags == TAC_PLUS_CONTINUE_FLAG_ABORT:
reply.status = TAC_PLUS_AUTHEN_STATUS_FAIL

return reply

Expand Down