mokey handles authentication, password resets, and two-factor enrollment for FreeIPA accounts, so security reports are taken seriously.
Only the latest release receives security fixes.
Please do not open a public issue. Use GitHub's private vulnerability reporting ("Report a vulnerability" on the Security tab) instead.
Please include:
- A description of the vulnerability and its impact
- Steps to reproduce or a proof of concept
- Affected version(s) and configuration (TLS mode, Hydra enabled, storage driver, etc.)
You will get an answer within 7 days. A fix and advisory are published within 90 days, or sooner once a fix is available.
- Give the mokey service account only the role from the
README, not
admin. Keep the keytab readable by the mokey user only (chmod 640, owned by themokeygroup). - Serve mokey over HTTPS, either directly (
server.ssl_cert/ssl_key) or behind a TLS-terminating reverse proxy. - Behind a proxy, set
server.trusted_proxiesto the proxy's addresses. Otherwise every request appears to come from the proxy, and rate limiting and audit logs see a single client. - On internet-facing deployments, enable
accounts.hide_invalid_username_errorso the login form does not reveal which usernames exist, and keep the rate limits (server.rate_limit_*) on. - Set
token_secretandcsrf_secretexplicitly and keep them out of version control. Useredisorsqlite3storage in production;memoryloses sessions on restart. - Verify release artifacts against the signed
checksums.txt(see Verifying releases).
See the configuration reference for every option.