Duo Authentication Proxy

29 views
Skip to first unread message

Brian Epstein

unread,
Feb 2, 2021, 2:57:32 PM2/2/21
to springdale-users
Howdy Springdale Community,

I'm wondering if anyone else is using DuoSecurity's Authentication Proxy? They offer it as a tarball and we were interested in packaging it into an RPM. If there is interest, it may be something that we can collaborate on. If not, we'll just figure something out.

Their Linux installation guide is currently, download this tarball and compile it.

https://duo.com/docs/authproxy-reference

We have seen some RPMs, but not from any normally trusted repo or up to date, like this one.

https://github.com/jthiltges/duoauthproxy-rpm

Thanks,
ep

--
Brian Epstein <beps...@ias.edu> +1 609-734-8179
Manager, Network and Security, CISO Institute for Advanced Study
Key fingerprint = A6F3 9F5A 26C5 5847 79ED C34C C0E5 244A 55CA 2B78

Prentice Bisbal

unread,
Feb 2, 2021, 4:24:50 PM2/2/21
to springda...@googlegroups.com
We use Duo, too, and I was thinking of doing packaging it as an RPM,
too. I wouldn't trust Duo RPMs from an outside source. I don't see a
problem using a spec file from an outside source, though. At least that
you can look at and make sure they're not doing anything nefarious in it.

Prentice

On 2/2/21 2:57 PM, Brian Epstein wrote:
> Howdy Springdale Community,
>
> I'm wondering if anyone else is using DuoSecurity's Authentication Proxy? They offer it as a tarball and we were interested in packaging it into an RPM. If there is interest, it may be something that we can collaborate on. If not, we'll just figure something out.
>
> Their Linux installation guide is currently, download this tarball and compile it.
>
> https://duo.com/docs/authproxy-reference
>
> We have seen some RPMs, but not from any normally trusted repo or up to date, like this one.
>
> https://github.com/jthiltges/duoauthproxy-rpm
>
> Thanks,
> ep
>
--
Prentice Bisbal
Lead Software Engineer
Research Computing
Princeton Plasma Physics Laboratory
http://www.pppl.gov

Theresa Arzadon-Labajo

unread,
Feb 2, 2021, 4:35:20 PM2/2/21
to 'Prentice Bisbal' via springdale-users
It's weird that they have a repository that contains the duo_unix rpm,
but not the authentication proxy package.

https://duo.com/docs/duounix#linux-distribution-packages
<https://duo.com/docs/duounix#linux-distribution-packages>

http://pkg.duosecurity.com/

Brian Epstein

unread,
Feb 2, 2021, 5:13:43 PM2/2/21
to springdale-users
Hi Prentice,

Yeah, I totally agree about using the RPM from an outside source that isn't trusted. Glad to hear we are in good company with using the product, though.

Theresa, we said the same thing, why wouldn't they just package it up and put it in their repository. So weird.

Thanks,
ep

--
Brian Epstein <beps...@ias.edu> +1 609-734-8179
Manager, Network and Security, CISO Institute for Advanced Study
Key fingerprint = A6F3 9F5A 26C5 5847 79ED C34C C0E5 244A 55CA 2B78

--
You received this message because you are subscribed to the Google Groups "springdale-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to springdale-use...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/springdale-users/e6032679-081f-0028-b62f-c601c884dbf6%40pppl.gov.
Reply all
Reply to author
Forward
0 new messages