pkg.sopackage field notes

brew / 順位 1431

oath-toolkit を Homebrew でインストール

oath-toolkit のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install oath-toolkit

provider-native install command

概要

パッケージ概要

Tools for one-time password authentication systems

コマンドとエイリアス

  • oathtool
  • pskctool

履歴

プロジェクトの歴史と使われ方

OATH Toolkit is a long-running free software implementation of one-time password infrastructure. It provides shared C libraries, the oathtool and pskctool command-line tools, and a pam_oath module for integrating HOTP/TOTP authentication into Unix login stacks.

プロジェクトの歴史

Simon Josefsson introduced the OATH Toolkit publicly in January 2011 as software for OATH one-time password authentication, including oathtool and pam_oath. A May 2011 release announcement for version 1.10.0 points to the Nongnu project page, man pages, PAM documentation, API reference, signed release tarballs, and the Savannah project home.

The toolkit tracks the standards ecosystem around one-time passwords: HOTP from RFC 4226, TOTP from RFC 6238, and PSKC from RFC 6030. Later releases added support for HMAC-SHA256 and HMAC-SHA512 TOTP generation and validation APIs in version 2.6.0, and the project moved version-controlled source hosting to GitLab in version 2.6.2 before moving public Git hosting to Codeberg in version 2.6.13.

採用の歴史

OATH Toolkit spread through Unix package ecosystems because it solved a boring but durable operations problem: generating and validating standard OTP values and adding PAM-based OTP checks to existing systems. The input package record lists apk, Homebrew, Debian, Fedora, MacPorts, Nix, Arch, Ubuntu, and openSUSE package names, reflecting broad distribution rather than a single application community.

使われ方

Developers use liboath when embedding HOTP/TOTP validation in C applications, operators use oathtool for token generation and testing, pskctool handles Portable Symmetric Key Container data, and administrators use pam_oath to require OTP values during PAM authentication. A common deployment stores token records in a usersfile such as /etc/users.oath.

パッケージ好きにとっての重要性

The package is a classic security-toolchain package: small command-line utilities, a C library ABI, a PAM module, man pages, signed source releases, and long-term distro packaging. It also shows how standards-based authentication plumbing ages: compatibility fixes, crypto algorithm additions, build-system maintenance, and security advisories matter as much as new features.

タイムライン

  • 2005: RFC 4226 defined the HOTP algorithm.
  • 2010: RFC 6030 defined PSKC for symmetric key container data.
  • 2011: RFC 6238 defined TOTP.
  • 2011-01-20: Simon Josefsson published an introduction to OATH Toolkit.
  • 2015-05-19: OATH Toolkit 2.6.0 added TOTP support with HMAC-SHA256 and HMAC-SHA512 APIs.
  • 2016-08-27: OATH Toolkit 2.6.2 noted that version-controlled source moved to GitLab.
  • 2024-10-03: OATH Toolkit 2.6.12 addressed CVE-2024-47191 in pam_oath/liboath.
  • 2025-07-29: OATH Toolkit 2.6.13 moved Git hosting to Codeberg.

Related projects

  • OATH Toolkit is directly tied to the OATH HOTP/TOTP standards, Unix PAM, libxmlsec for PSKC-related functionality, and downstream distro packages such as Debian's oathtool/liboath-dev packages.

ソース

セキュリティ状態

リスクレベル: グリーン

narrow executable package without higher-risk signals.

リスク分類器

リスク グリーン · 信頼度 低 · appliance

理由

  • narrow executable package without higher-risk signals

信号

  • metadata:no-higher-risk-signals

インストール挙動

  • Homebrew bottle メタデータは記録されていません。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Credential files

Credential-bearing paths to review before unattended agent runs.

Unix
/etc/users.oath

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
oathtool実行可能ファイルインデックス済み実行可能ファイルローカル実行可能ファイルインデックスから検出されました。
pskctool実行可能ファイルインデックス済み実行可能ファイルローカル実行可能ファイルインデックスから検出されました。

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-08-03
マネージャ版2.6.14
マネージャ更新日2026-06-27
ローカルデータ不明
上流利用不可
検出された最新未検出
  • OK鮮度警告は生成されていません。

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:oath-toolkit
バージョン2.6.14
パッケージマネージャHomebrew
ホームページhttps://oath-toolkit.codeberg.page/
最終更新2026-06-27T14:40:16-04:00
Pulseupdated
Bottle未記録
サービス宣言なし

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • Nucleus package database
  • curated configuration and credential file locations
  • curated package history
  • pkgdb category and tag curation