{"id":1748,"date":"2018-01-07T23:58:07","date_gmt":"2018-01-07T14:58:07","guid":{"rendered":"http:\/\/matoken.org\/blog\/?p=1748"},"modified":"2018-01-07T23:58:07","modified_gmt":"2018-01-07T14:58:07","slug":"gnu-social-2fa","status":"publish","type":"post","link":"https:\/\/matoken.org\/blog\/2018\/01\/07\/gnu-social-2fa\/","title":{"rendered":"GNU social\u306b2\u8981\u7d20\u8a8d\u8a3c\u3092"},"content":{"rendered":"<p><a name=\"preamble\"><\/a><\/p>\n<p>Mastodon\u306a\u3069\u3067\u306f\u4f7f\u3048\u308b2\u8981\u7d20\u8a8d\u8a3c\u3067\u3059\u304c\uff0cGNU social\u306b\u306f\u3042\u308a\u307e\u305b\u3093\uff0e<br \/>\n\u5148\u65e5 GNU social \u3092 nightly \u306b\u3057\u305f\u306e\u3067\u3053\u308c\u304c\u5229\u7528\u3067\u304d\u305d\u3046\u3067\u3059\uff0e<\/p>\n<ul>\n<li>\n<p>\n<a href=\"https:\/\/git.gnu.io\/gnu\/gnu-social\/merge_requests\/119\/commits\">[RFC] two-factor authentication support (!119) \u00b7 Merge Requests \u00b7 gnu.io \/ gnu-social \u00b7 GitLab<\/a>\n<\/p>\n<\/li>\n<li>\n<p>\n<a href=\"https:\/\/matoken.org\/blog\/2017\/12\/30\/gnu-social-nightly\/\">GNU social\u3092nightly\u306b\u3057\u3066\u307f\u308b \u2013 matoken&#8217;s meme<\/a>\n<\/p>\n<\/li>\n<\/ul>\n<p>Plugin\u5f62\u5f0f\u3067\u623b\u3059\u306e\u3082\u7c21\u5358\u305d\u3046\u3060\u3057\u8a66\u3057\u3066\u307f\u307e\u3057\u305f\uff0e<\/p>\n<p><b>backup<\/b><br \/>db\u3068\u30d5\u30a1\u30a4\u30eb\u3092\u30d0\u30c3\u30af\u30a2\u30c3\u30d7\u3057\u3066\u304a\u304d\u307e\u3059\uff0e<\/p>\n<table  class=\" table table-hover\" border=\"0\" bgcolor=\"#e8e8e8\" width=\"100%\" cellpadding=\"4\">\n<tr>\n<td>\n<pre><code>$ sudo -u www-data rsync -avv \/var\/www\/gnusocial.matoken.org\r\nrsync --stats -av --delete --link-dest=\/export\/backup\/micro\/gs\/www\/`\/bin\/date -d '1 day ago' +%Y%m%d`\/ \/var\/www\/gnusocial.matoken.org \/export\/backup\/micro\/gs\/www\/`\/bin\/date +\\%Y\\%m\\%d`\/\r\n$ sudo -u www-data tar cvf - \/export\/backup\/micro\/gs\/www\/`\/bin\/date +\\%Y\\%m\\%d`\/ &gt; \/export\/backup\/micro\/gs\/www\/`\/bin\/date +\\%Y\\%m\\%d`-2fa.tar.xz\r\n$ umask 0266 &amp;&amp; \/usr\/bin\/mysqldump --defaults-file=\/export\/backup\/micro\/gs\/db\/.my-backup.cnf --opt --all-databases --events | \/usr\/bin\/xz -9 &gt; \/export\/backup\/micro\/gs\/db\/`date +\\%Y-\\%M-\\%d_\\%H:\\%m:\\%S_\\%s_$$`-master2nightly.sql.xz<\/code><\/pre>\n<\/td>\n<\/tr>\n<\/table>\n<p><b>GNU social \u306e source \u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306b\u79fb\u52d5\u3057\u3066 2fa \u3092 marge \u3059\u308b<\/b><\/p>\n<table  class=\" table table-hover\" border=\"0\" bgcolor=\"#e8e8e8\" width=\"100%\" cellpadding=\"4\">\n<tr>\n<td>\n<pre><code>$ cd gnu-social\r\n$ git fetch https:\/\/git.gnu.io\/sstjohn\/gnu-social.git 2fa-beta\r\n$ git checkout -b sstjohn\/gnu-social-2fa-beta FETCH_HEAD\r\n$ git checkout nightly\r\n$ git merge --no-ff sstjohn\/gnu-social-2fa-beta\r\n$ git push origin nightly<\/code><\/pre>\n<\/td>\n<\/tr>\n<\/table>\n<p><b>\u52d5\u3044\u3066\u3044\u308bGNU social\u74b0\u5883\u306bcopy<\/b><\/p>\n<table  class=\" table table-hover\" border=\"0\" bgcolor=\"#e8e8e8\" width=\"100%\" cellpadding=\"4\">\n<tr>\n<td>\n<pre><code>$ sudo -u www-data rsync -avv --omit-dir-times --exclude=\".git*\" .\/ &lt;GNUSOCIAL_PATH&gt;\/<\/code><\/pre>\n<\/td>\n<\/tr>\n<\/table>\n<p><b>config.php\u306b\u4ee5\u4e0b\u306e\u884c\u3092\u8ffd\u52a0\u3057\u3066TwoFactorAuth plugin\u3092\u6709\u52b9\u306b\u3059\u308b<\/b><\/p>\n<table  class=\" table table-hover\" border=\"0\" bgcolor=\"#e8e8e8\" width=\"100%\" cellpadding=\"4\">\n<tr>\n<td>\n<pre><code>addPlugin('TwoFactorAuth');<\/code><\/pre>\n<\/td>\n<\/tr>\n<\/table>\n<p><b>\u52d5\u4f5c\u78ba\u8a8d<\/b><br \/>\u8a2d\u5b9a\u753b\u9762\u306e\u5de6\u5074\u306b 2FA \u3068\u3044\u3046\u9805\u76ee\u304c\u5897\u3048\u308b\uff0e<\/p>\n<div>\n<img decoding=\"async\" src=\"https:\/\/farm5.staticflickr.com\/4588\/39554232041_1d85c51a91_n.jpg\" style=\"border-width: 0;\" alt=\"https:\/\/farm5.staticflickr.com\/4588\/39554232041_1d85c51a91_n.jpg\"\/>\n<\/div>\n<p>\u300cRequire secondary authentication upon login\u300d\u306e\u30c1\u30a7\u30c3\u30af\u30dc\u30c3\u30af\u30b9\u306b\u30c1\u30a7\u30c3\u30af\u3092\u4ed8\u3051\u3066 <strong>SAVE<\/strong> \u30672FA\u304c\u6709\u52b9\u306b\u306a\u308b\uff0e<br \/>\n<strong>Default provider<\/strong> \u3067\u5e38\u7528\u3059\u308b2FA\u65b9\u5f0f\u3092\u9078\u629e\u3057\u3066\u304a\u304f\u3068\u4fbf\u5229\u3067\u3059\uff0e<\/p>\n<div>\n<img decoding=\"async\" src=\"https:\/\/farm5.staticflickr.com\/4633\/39524857262_899ae15086_n.jpg\" style=\"border-width: 0;\" alt=\"https:\/\/farm5.staticflickr.com\/4633\/39524857262_899ae15086_n.jpg\"\/>\n<\/div>\n<p>\u8a8d\u8a3c\u306b\u306f\uff0c\u300cFIDO 2.0\u300d\u300cTOTP\u300d\u300cU2F\u300d\u304c\u5229\u7528\u3067\u304d\u307e\u3059\uff0e<br \/>\n\u81ea\u5206\u306fTOTP\u3092\u5229\u7528\u3057\u3066\u3044\u307e\u3059\uff0eTOTP\u306e\u5834\u5408\u30b9\u30de\u30db\u30a2\u30d7\u30ea\u306eGoogle Autharicator\u306a\u3069\u304c\u4f7f\u3048\u307e\u3059\uff0eQR Code\u3084KEY\u3092\u4f7f\u3063\u3066\u30a2\u30d7\u30ea\u306b\u767b\u9332\u3057\u307e\u3059\uff0e<\/p>\n<div>\n<img decoding=\"async\" src=\"https:\/\/farm5.staticflickr.com\/4589\/38845402154_14ac40b77a_n.jpg\" style=\"border-width: 0;\" alt=\"https:\/\/farm5.staticflickr.com\/4589\/38845402154_14ac40b77a_n.jpg\"\/>\n<\/div>\n<p>\u81ea\u5206\u306f\u4fe1\u983c\u3067\u304d\u308b\u30b9\u30de\u30db\u3092\u6301\u3063\u3066\u3044\u306a\u3044\u306e\u3067oathtool\u3092\u4f7f\u3063\u3066\u9069\u5f53\u306ascript\u3092\u66f8\u3044\u3066\u4f7f\u3063\u3066\u3044\u307e\u3059\uff0e<\/p>\n<table  class=\" table table-hover\" border=\"0\" bgcolor=\"#e8e8e8\" width=\"100%\" cellpadding=\"4\">\n<tr>\n<td>\n<pre><code>$ oathtool --totp -b YJVHGFLJBWJAEROQVQ5MTIAKA2XVCUAH\r\n148825<\/code><\/pre>\n<\/td>\n<\/tr>\n<\/table>\n<p>\u30d0\u30c3\u30af\u30a2\u30c3\u30d7\u30b3\u30fc\u30c9\u3082\u4fdd\u5b58\u3057\u3066\u304a\u304d\u307e\u3057\u3087\u3046\uff0e<\/p>\n<div>\n<img decoding=\"async\" src=\"https:\/\/farm5.staticflickr.com\/4730\/39554339271_99efd6658b_n.jpg\" style=\"border-width: 0;\" alt=\"https:\/\/farm5.staticflickr.com\/4730\/39554339271_99efd6658b_n.jpg\"\/>\n<\/div>\n<p>\u3053\u306e\u72b6\u614b\u3067\u4e00\u65e6GNU social\u3092\u30ed\u30b0\u30a2\u30a6\u30c8\uff0c\u3044\u3064\u3082\u306eID\/PASSWORD\u3067\u30ed\u30b0\u30a4\u30f3\u3059\u308b\u30682FA\u306e\u8a8d\u8a3c\u753b\u9762\u306b\u306a\u308b\u306e\u3067\uff0c\u8a8d\u8a3c\u60c5\u5831\u3092\u5165\u529b\u3057\u3066\u30ed\u30b0\u30a4\u30f3\u3057\u307e\u3059\uff0e<br \/>\n\u65e2\u5b9a\u5024\u4ee5\u5916\u306e\u8a8d\u8a3c\u60c5\u5831\u3092\u7528\u3044\u305f\u3044\u5834\u5408\u306f\u300cTry another way to sign in.\u300d\u304b\u3089\u9078\u629e\u53ef\u80fd\u3067\u3059\uff0e<\/p>\n<div>\n<img decoding=\"async\" src=\"https:\/\/farm5.staticflickr.com\/4587\/39555314441_9b42544cc8_n.jpg\" style=\"border-width: 0;\" alt=\"https:\/\/farm5.staticflickr.com\/4587\/39555314441_9b42544cc8_n.jpg\"\/>\n<\/div>\n<p><b>bug?<\/b><br \/>\u8a8d\u8a3c\u5f8c\u771f\u3063\u767d\u306a\u753b\u9762\u82e5\u3057\u304f\u306f\u300cAythentication success!\u300d\u3068\u8868\u793a\u3055\u308c\u308b\u3051\u3069\u8a8d\u8a3c\u753b\u9762\u306b\u306a\u308a\u307e\u3059\uff0e\u591a\u5206\u30d0\u30b0\u3067\u3059\uff0eURL\u3092\u624b\u52d5\u3067\u7de8\u96c6\u3057\u305f\u3089\u30ed\u30b0\u30a4\u30f3\u3067\u304d\u3066\u3044\u307e\u3059\uff0e<\/p>\n<div>\n<img decoding=\"async\" src=\"https:\/\/farm5.staticflickr.com\/4736\/38658168725_4c15bc2765.jpg\" style=\"border-width: 0;\" alt=\"https:\/\/farm5.staticflickr.com\/4736\/38658168725_4c15bc2765.jpg\"\/>\n<\/div>\n<p><b>\u30b5\u30fc\u30c9\u30d1\u30fc\u30c6\u30a3\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u5bfe\u5fdc<\/b><br \/>\u30b9\u30de\u30db\u30a2\u30d7\u30ea\u306a\u3069\u3092\u5229\u7528\u3057\u3066\u3044\u308b\u5834\u5408\u306f\u30d1\u30b9\u30ef\u30fc\u30c9\u3092\u5909\u66f4\u3057\u306a\u3051\u308c\u3070\u3044\u3051\u307e\u305b\u3093\uff0e<br \/>\n2FA\u306e\u8a2d\u5b9a\u753b\u9762\u306e\u300cApplication Passwords\u300d\u306e\u300cADD APPLICATION\u300d\u30dc\u30bf\u30f3\u304b\u3089\u8ffd\u52a0\u3057\u307e\u3059\uff0e\u300cApplication name\u300d\u306b\u8b58\u5225\u7528\u306e\u9069\u5f53\u306a\u540d\u524d\u3092\u5165\u308c\u3066\uff0c\u300cGenerate\u300d\u30dc\u30bf\u30f3\u3067\u30d1\u30b9\u30ef\u30fc\u30c9\u304c\u751f\u6210\u3055\u308c\u307e\u3059\uff0e\u5fc5\u8981\u304c\u7121\u304f\u306a\u3063\u305f\u3089\u300cRevoke\u300d\u3067\u6d88\u3057\u307e\u3057\u3087\u3046\uff0e<\/p>\n<div>\n<img decoding=\"async\" src=\"https:\/\/farm5.staticflickr.com\/4637\/27779332399_189cde7bdc_n.jpg\" style=\"border-width: 0;\" alt=\"https:\/\/farm5.staticflickr.com\/4637\/27779332399_189cde7bdc_n.jpg\"\/>\n<\/div>\n<div>\n<img decoding=\"async\" src=\"https:\/\/farm5.staticflickr.com\/4590\/27779333139_0753ed2c8e_n.jpg\" style=\"border-width: 0;\" alt=\"https:\/\/farm5.staticflickr.com\/4590\/27779333139_0753ed2c8e_n.jpg\"\/>\n<\/div>\n<div>\n<img decoding=\"async\" src=\"https:\/\/farm5.staticflickr.com\/4588\/27779333639_68495ef93b_n.jpg\" style=\"border-width: 0;\" alt=\"https:\/\/farm5.staticflickr.com\/4588\/27779333639_68495ef93b_n.jpg\"\/>\n<\/div>\n<p>Android\u30a2\u30d7\u30ea\u306eTwidere\u3067\u306f\u8a8d\u8a3c\u60c5\u5831\u306e\u5909\u66f4\u753b\u9762\u304c\u898b\u5f53\u305f\u308a\u307e\u305b\u3093\u3067\u3057\u305f\uff0c\u30a2\u30ab\u30a6\u30f3\u30c8\u306e\u8ffd\u52a0\u3092\u3057\u3066\u4f55\u6642\u3082\u306ehost\/id\/\u65b0\u3057\u30442fa\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u30d1\u30b9\u30ef\u30fc\u30c9\u3092\u8a2d\u5b9a\u3059\u308b\u3068\u3059\u3067\u306b\u30a2\u30ab\u30a6\u30f3\u30c8\u304c\u3042\u308b\u3068\u304b\u8a00\u308f\u308c\u3066\u8a8d\u8a3c\u60c5\u5831\u304c\u66f8\u304d\u63db\u308f\u308a\u307e\u3057\u305f\uff0e<\/p>\n<p>\u3068\u3044\u3046\u611f\u3058\u3067\u3068\u308a\u3042\u3048\u305a\u5229\u7528\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3057\u305f\uff0e<br \/>\nGNU social\u3067\u306f\u7d50\u69cb\u9577\u304f\u653e\u7f6e\u3055\u308c\u3066\u3044\u308b\u306e\u3067\u66ab\u304f\u306f\u5165\u3089\u306a\u3044\u3088\u3046\u306a\u611f\u3058\u3067\u3059\u304b\u306d\uff0e<br \/>\n\u30d0\u30b0\u306fTOTP\u5229\u7528\u3057\u3066\u308b\u4eba\u304c\u5c45\u306a\u3044?Ubico YubiKey\u3068\u304b\u307b\u3057\u3044\u3067\u3059\u306d\uff0e<\/p>\n<div id=\"footer\">\n<div id=\"footer-text\">\n<iframe style=\"width:120px;height:240px;\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\" frameborder=\"0\" src=\"rcm-fe.amazon-adsystem.com\/e\/cm?lt1=_blank&#038;bc1=000000&#038;IS2=1&#038;bg1=FFFFFF&#038;fc1=000000&#038;lc1=0000FF&#038;t=matokensmeme-22&#038;o=9&#038;p=8&#038;l=as4&#038;m=amazon&#038;f=ifr&#038;ref=as_ss_li_til&#038;asins=B00LX8KZZ8&#038;linkId=e45190e0b23f16e2f7181dd5d805877f\"><\/iframe><iframe style=\"width:120px;height:240px;\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\" frameborder=\"0\" src=\"rcm-fe.amazon-adsystem.com\/e\/cm?lt1=_blank&#038;bc1=000000&#038;IS2=1&#038;bg1=FFFFFF&#038;fc1=000000&#038;lc1=0000FF&#038;t=matokensmeme-22&#038;o=9&#038;p=8&#038;l=as4&#038;m=amazon&#038;f=ifr&#038;ref=as_ss_li_til&#038;asins=B018Y1XXT6&#038;linkId=a6ec00d2717dd8e1adb60a0a8da55970\"><\/iframe><iframe style=\"width:120px;height:240px;\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\" frameborder=\"0\" src=\"\/\/rcm-fe.amazon-adsystem.com\/e\/cm?lt1=_blank&#038;bc1=000000&#038;IS2=1&#038;bg1=FFFFFF&#038;fc1=000000&#038;lc1=0000FF&#038;t=matokensmeme-22&#038;o=9&#038;p=8&#038;l=as4&#038;m=amazon&#038;f=ifr&#038;ref=as_ss_li_til&#038;asins=B077M5SF2K&#038;linkId=6eb9ebbfc6ac1385283aa150c30cde9a\"><\/iframe>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Mastodon\u306a\u3069\u3067\u306f\u4f7f\u3048\u308b2\u8981\u7d20\u8a8d\u8a3c\u3067\u3059\u304c\uff0cGNU social\u306b\u306f\u3042\u308a\u307e\u305b\u3093\uff0e \u5148\u65e5 GNU social \u3092 nightly \u306b\u3057\u305f\u306e\u3067\u3053\u308c\u304c\u5229\u7528\u3067\u304d\u305d\u3046\u3067\u3059\uff0e [RFC] two-factor authenti [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"webmentions_disabled_pings":false,"webmentions_disabled":false,"activitypub_content_warning":"","activitypub_content_visibility":"","activitypub_max_image_attachments":4,"activitypub_interaction_policy_quote":"anyone","activitypub_status":"","footnotes":""},"categories":[1],"tags":[297,271,298],"class_list":["post-1748","post","type-post","status-publish","format-standard","hentry","category-1","tag-2fa","tag-gnu-social","tag-totp"],"_links":{"self":[{"href":"https:\/\/matoken.org\/blog\/wp-json\/wp\/v2\/posts\/1748","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/matoken.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/matoken.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/matoken.org\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/matoken.org\/blog\/wp-json\/wp\/v2\/comments?post=1748"}],"version-history":[{"count":0,"href":"https:\/\/matoken.org\/blog\/wp-json\/wp\/v2\/posts\/1748\/revisions"}],"wp:attachment":[{"href":"https:\/\/matoken.org\/blog\/wp-json\/wp\/v2\/media?parent=1748"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/matoken.org\/blog\/wp-json\/wp\/v2\/categories?post=1748"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/matoken.org\/blog\/wp-json\/wp\/v2\/tags?post=1748"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}