From 0ce6c26535760971c0988c9c27ab71251e619d42 Mon Sep 17 00:00:00 2001 From: Elijah Perrault Date: Tue, 8 Feb 2011 19:30:46 -0700 Subject: [PATCH] Added documentation for the three auth methods Auto supports: Plaintext, CertFP and SASL. --- doc/AUTH | 71 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 71 insertions(+) create mode 100644 doc/AUTH diff --git a/doc/AUTH b/doc/AUTH new file mode 100644 index 0000000..6a52768 --- /dev/null +++ b/doc/AUTH @@ -0,0 +1,71 @@ +Auto 3.0: IRC Authentication Methods +------------------------------------------------------------------------------- + +Auto comes packaged with three methods of authenticating to IRC auth services +(e.g. NickServ). + +- Plaintext IRC Message + +This is the simplest, most basic method, and is discouraged. It works by adding +idstr to the server block you're going to use this with. + +idstr should be set to the string that must be sent to identify. Like so: + +For a network using NickServ but has no NS alias: +idstr "PRIVMSG NickServ :IDENTIFY "; + +If the network has an NS alias, this is better: +idstr "NS IDENTIFY "; + +- Certificate Fingerprint (CertFP) + +This is a much securer method of authentication than plaintext. It requires you +connect to the target network using SSL. + +First you need to generate a certificate, please run bin/genssl and answer the +questions, it will then print "Done. Fingerprint: . Consult the network for the exact +command. + +After adding the fingerprint to the bot's account on auth services, add the +following config options to the server block you're using this with: + +certfp 1; +certfp_cert ".cert"; +certfp_key ".key"; + +If you specified a password for the keyfile during certification generation +(if you used bin/genssl, ignore this), specify it like so: + +certfp_pass ""; + + is the network name you gave to bin/genssl. + +Now you can connect to the network (with SSL) and it should identify +automatically and securely. + +- SASL (Simple Authentication and Security Layer) + +This is another method of authentication that is securer than plaintext. It +requires that Auto be built with the --enable-sasl option. + +Currently, some networks do not support SASL authentication, consult the +network about this before using SASL. + +Using SASL is simple, simply add SASLAuth to module autoload and add the +following to the server block you're using it with: + +sasl_username ""; +sasl_password ""; +sasl_timeout ; + +Usually you'll want to set to 20. The others are straightforward. + +Now connect to the network and you should automatically authenticate using +SASL. + +Support for DH-Blowfish SASL is coming soon.