zdave / openconnect-gp-okta

OpenConnect wrapper which logs into a GlobalProtect gateway, authenticating with Okta
37 stars 27 forks source link

OAUTH2 not supported #23

Open aaronw2 opened 5 months ago

aaronw2 commented 5 months ago

My organization now requires oauth2 for logging in with 2 factor authentication via phone push notifications. This requires that a web browser open a page to handle this and this is not supported.

Also, my organization requires --csd-wrapper be passed to openconnect so I suggest a --csd-wrapper option to this.

aaronw2 commented 5 months ago

It seems that a recent update broke this. Yesterday, they updated the GP VPN server software, and now this is no longer working.

requests.exceptions.HTTPError: 503 Server Error: Service Unavailable for url: https://XXXXXXX.XXXXXXX.com:443/SAML20/SP/ACS