Projects / RCDevs OpenOTP

RCDevs OpenOTP

RCDevs OpenOTP Server provides two-factor authentication with one-time passwords (OTP). It supports OATH RFC-4226 HOTP (Event-based) and TOTP (Time-based), OCRA (Challenge-based), Mobile-OTP, YubiKey Software/Hardware Tokens, SMSOTP, MailOTP, and OTP lists. It provides a SOAP/XML, RADIUS, and OpenID APIs and integrates into your LDAP (OpenLDAP, Novell, ActiveDirectory). It works with Web applications, VPNs, Linux PAM, Microsoft, and more. It is composed of the RCDevs WebADM server application, the OpenOTP SOAP service, the OpenOTP Radius Bridge, the User Self-service Desk, and Token Self-enrollemnt end-user Web application. VMWare appliances and Web demos are available.

Operating Systems

RSS Last announcement

Easy migrate from a two-factor solution to OpenOTP 18 Apr 2011

OpenOTP includes a new OTP Type (PROXY) to enable automatic forwarding of login requests to a third-party RADIUS server.
This functionality allow...

RSS Recent releases

  •  27 Sep 2013 22:43

    Release Notes: This release contains many fixes and new features. It supports expired passwords detection, SafeNet Tokens, additional APIs, OTP PIN codes, Token import via serial numbers, and more.

    •  23 Jan 2013 02:34

      Release Notes: This major release includes several important new features, including support for multiple Tokens per user, new OTP fallback methods, a new simpleLogin API, and a new RadiusBridge.

      •  02 Jan 2013 23:12

        Release Notes: This release adds support for geolocalization and IP location-based policies, adds a new XML-RPC API, improves logging, and fixes OCRA Tokens.

        •  22 Jul 2012 16:29

        Release Notes: SMSOTP and MailOTP support for sending OTPs to several numbers/addresses per-user. MailOTP subject can be customized. The user blocking management was enhanced. Blocking alerts were added. An HOTP resync problem was fixed. A PSKC export problem was fixed. New requests are optionally allowed when a session is already started after a delay of 5 seconds (the existing session is dropped the and user does not have to wait for the challenge timeout). A 'Service Name' setting was added for customizing the Google Authenticator display name. A Manager function was added for checking user blocking status.

        •  06 Mar 2012 22:24

        Release Notes: This version is fully compliant with WebADM 1.2 and supports the new WebADM Manager Interface. A JSON-RPC interface was added for the OpenOTP authentication API. SMS OTP supports concatenated SMS for messages longer than 140 chars. A HOTP manual resync issue was fixed. New requests are now allowed when a session exists after a delay of 10 seconds. The existing session is dropped and the user does not have to wait for the challenge timeout to expire.


        Project Spotlight


        AN advanced suite for optimization and reactor analysis.


        Project Spotlight


        A relational and transaction-based database system.