#sso — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #sso, aggregated by home.social.
-
Canop'Tips 💡 Connectez #Canopsis à votre fournisseur d'identité !
#OAuth2 et #OpenIDConnect natifs dans Canopsis :
✅ Connectez Canopsis à votre fournisseur d'identité
✅ Centralisez les accès, supprimez les mots de passe superflus
✅ Pilotez les droits depuis votre annuaire d'entrepriseCompatible GitHub, GitLab, Google et plus encore.
-
Хватит строить Kubernetes для пятнадцати человек
Я много лет занимался инфраструктурой. Потом перестал и ушёл в продукт — но привычка заглядывать: «А как у вас тут всё устроено?» осталась. И вот теперь я хожу к клиентам по совсем другим вопросам, а глаза всё равно выпадают.
https://habr.com/ru/articles/1069238/
#authentik #mailcow #nextcloud #planka #selfhosted #sso #oidc #docker #итинфраструктура_малого_бизнеса #keycloak
-
Infinito.Nexus 12.0: From a Single Server to a Scalable Sovereign Cloud
Infinito.Nexus 12.0 is one of the most significant releases in the project’s history. Until now, Infinito.Nexus focused primarily on automating complete open-source environments on a single Docker Compose host. Version 12.0 introduces Docker Swarm as a second deployment mode, enabling applications to run across multiple servers, scale horizontally and recover from node failures. This release combines capabilities that are rarely delivered by one automation platform: More than 75 automatically deployable open-source applications One Single Sign-On experience backed by a unified user database Horizontal scaling across multiple cloud servers Automated backup and continuously tested disaster recovery Support across Debian, Arch Linux and RHEL-family distributions Filesystem-independent operation across ext4, btrfs and ZFS Together, these changes transform Infinito.Nexus from an application installer into a comprehensive foundation for scalable, sovereign cloud infrastructure. […] -
Mmh.. #Gnome #Evolution doesn't seem to be able to load calendars from an #SSO-/#OIDC-gated resource. Don't like that at all.
(Gives a username/password field telling me that the Server replied 401 but with an HTML body which must be wrong, it thinks.)
-
Wer zugreifen darf, liegt in Authentik: Provider, Application, Policy Binding. Als Blueprint in YAML versioniert, statt in der Datenbank versteckt. Mit der cookie_domain auf der Hauptdomain gilt ein Login für alle Subdomains.
Ausnahmen braucht es trotzdem: APIs und Webhooks können mit einer HTML-Loginseite nichts anfangen.
Link in den Kommentaren.
#AIEngineering #SelfHosting #Security #SSO
https://systemebene.house-harkonnen.com/artikel/2-authentik-forward-auth-caddy
-
Ki vagy, mit tudsz, meddig érsz el vele — nem csak a homelabomra igaz, bármilyen rendszerre.
Mindent self-hosted SSO mögé kötöttem: passkey-vel jelentkezem be, minden más ezen keresztül hitelesít. Elméletben tiszta. Gyakorlatban kizártam magam a rendszeremből, találtam egy javítatlan upstream bugot, órákig kerestem egy félrevezető mezőt.
Buktatók, tanulságok:
https://brtkcs.com/source/2026/08/ki-vagyok-mit-tudok-mit-%C3%A9rek-el-sso-a-homelab-ben/
#selfhosted #sso -
🌟 LemonLDAP::NG 2.23.1 released!
ℹ️ Certificate based LDAP authentication and some bug fixes
➡️ https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-23-1-is-out/
#IAM #SSO #CAS #SAML #OpenIDConnect #OpenSource #LogicielLibre #Perl
-
🌟 LemonLDAP::NG 2.23.1 released!
ℹ️ Certificate based LDAP authentication and some bug fixes
➡️ https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-23-1-is-out/
#IAM #SSO #CAS #SAML #OpenIDConnect #OpenSource #LogicielLibre #Perl
-
redb.Identity: OAuth 2.1 / OpenID сервер на .NET, где протокол отделён от транспорта, по шине или вообще без сети
Есть три привычных способа сделать OAuth/OIDC в .NET, и каждый чем-то неудобен. Первый — ASP.NET -привязанные решения (Duende IdentityServer, ASP.NET Identity, сэмплы OpenIddict). Мощно, но каждый эндпоинт — это HTTP-middleware. Захотелось дёрнуть token из воркера или из консьюмера шины? Поднимай HTTP-листенер и ходи через loopback. Хочешь протестировать конвейер выдачи токена в изоляции? Готовь WebApplicationFactory . Второй — готовые IAM-платформы (Keycloak, Auth0, Okta). Богато по фичам, но это отдельный сервис со своим рантаймом, своей админкой, своей базой, своей моделью конфигурации и своим деплоем. Мультиарендно — да, встраиваемо — нет. Третий — написать своё . И в третий раз за десятилетие переизобрести Code+PKCE, ротацию refresh-токенов, хранение согласий, отзыв сессий, защиту от replay в MFA, ротацию JWKS, шаринг ключей между репликами и backchannel-logout по RFC 8417.
https://habr.com/ru/articles/1058700/
#OAuth_21 #OpenID_Connect #identity_server #аутентификация #SSO #OpenIddict #NET #C# #SCIM #MFA
-
The new @codeenigma #Drupal based portal for managing #OpenLDAP directories on the web is almost ready for show time. Finished it today, internal testing for a day or two, then LIVE. 🥳
The stack is an #OpenLDAP directory, #SimpleSAMLphp for #SSO, integrating #LinOTP for MFA and #Drupal for a smart, easy to use web interface. All components are #foss and it's a slick user management experience.
Huge hat tip to @matason too, who spent many hours getting the vast majority of this over the line. 🫡
-
The new @codeenigma #Drupal based portal for managing #OpenLDAP directories on the web is almost ready for show time. Finished it today, internal testing for a day or two, then LIVE. 🥳
The stack is an #OpenLDAP directory, #SimpleSAMLphp for #SSO, integrating #LinOTP for MFA and #Drupal for a smart, easy to use web interface. All components are #foss and it's a slick user management experience.
Huge hat tip to @matason too, who spent many hours getting the vast majority of this over the line. 🫡
-
Рунет без Google Login: что теперь делать с авторизацией
В России снова обсуждают вход на сайты через Google, Apple ID, GitHub и другие иностранные аккаунты. Повод — подписанный закон № 199-ФЗ от 26.06.2026 , который добавил в КоАП штрафы за нарушение правил авторизации пользователей. Но сам запрет появился не сейчас. Базовая норма пришла ещё с 406-ФЗ от 31.07.2023 и с 1 декабря 2023 года живёт в ч. 10 ст. 8 закона № 149-ФЗ «Об информации» . Новость 2026 года в том, что теперь за нарушение есть отдельная статья КоАП — 13.55 : для граждан 10–20 тысяч рублей, для должностных лиц 30–50 тысяч, для юрлиц 500–700 тысяч. Обычного пользователя за аккаунт Gmail или Apple ID штрафовать не собираются (возможно, тут надо бы добавить слово «пока»), штрафы адресованы владельцу сайта, приложения или информационной системы, если он даёт пользователю из России войти способом, который закон теперь не считает допустимым. Снаружи всё выглядит как борьба с иностранными кнопками входа. На деле это спор о том, кто держит ключ от аккаунта пользователя.
https://habr.com/ru/articles/1053664/
#авторизация #аутентификация #OAuth_20 #OpenID_Connect #SSO #passkey #149ФЗ #КоАП_1355 #российский_IdP #SIM_swap
-
Ich finalisiere gerade meinen Beitrag zum Seminar #Medienbildung - Bildungsmedien von @zesspress an der @unigoettingen mit dem Titel "Vernetztes Lernen - Vernetzung lernen: Wie kann ein Lernnetzwerk digital souverän gestaltet werden?"
➡️Kurs-Blog https://zess.uni-goettingen.de/medienbildung/2026/06/29/vlvl-vernetztes-lernen-vernetzung-lernen-wie-kann-ein-lernnetzwerk-digital-souveraen-gestaltet-werden/
📌Die Studierenden sollen zur Vorbereitung Ihren Account auf ac.social ( #mastodon Instanz der @gwdg ) erstellen - #sso sei Dank geht das per Klick #FediLZ #pln #digitalesouveränität #vlvl #ZESSMedienkompetenz @neuSoM -
Ich finalisiere gerade meinen Beitrag zum Seminar #Medienbildung - Bildungsmedien von @zesspress an der @unigoettingen mit dem Titel "Vernetztes Lernen - Vernetzung lernen: Wie kann ein Lernnetzwerk digital souverän gestaltet werden?"
➡️Kurs-Blog https://zess.uni-goettingen.de/medienbildung/2026/06/29/vlvl-vernetztes-lernen-vernetzung-lernen-wie-kann-ein-lernnetzwerk-digital-souveraen-gestaltet-werden/
📌Die Studierenden sollen zur Vorbereitung Ihren Account auf ac.social ( #mastodon Instanz der @gwdg ) erstellen - #sso sei Dank geht das per Klick #FediLZ #pln #digitalesouveränität #vlvl #ZESSMedienkompetenz @neuSoM -
Zoho ManageEngine ADSelfService Plus hit by CRITICAL CVE-2026-11374: predictable SSO tickets enable unauthenticated account takeover. No patch yet — monitor advisories and review exposure. https://radar.offseq.com/threat/cve-2026-11374-cwe-340-generation-of-predictable-n-3400726b0246539c #OffSeq #Zoho #Vuln #SSO #Infosec
-
LMAO, I just sat down to add a new application to my #Authentik #SSO... And bounced right off of all the options. Indeed time to move, I guess #KaniDM looks nice.
Yeah, moving from the baroque/enterprise clickable authentik/keycloak to "it's mostly CLI and purposefully few options" can cause some whiplash 😅 -
LMAO, I just sat down to add a new application to my #Authentik #SSO... And bounced right off of all the options. Indeed time to move, I guess #KaniDM looks nice.
Yeah, moving from the baroque/enterprise clickable authentik/keycloak to "it's mostly CLI and purposefully few options" can cause some whiplash 😅 -
Work computers. #sso
Have you ever entered your work password into a box simply because it popped up and you expect something in your flow will break if you don't acknowledge it, even though you can't be sure where the demand actually comes from? -
Work computers. #sso
Have you ever entered your work password into a box simply because it popped up and you expect something in your flow will break if you don't acknowledge it, even though you can't be sure where the demand actually comes from? -
-
-
Well, I just looked at git repo of #Authentik, and it has a bunch of activity by various LLMs. I guess time to intensify looking at alternatives.
-
Well, I just looked at git repo of #Authentik, and it has a bunch of activity by various LLMs. I guess time to intensify looking at alternatives.
-
#Jellyfin #SSO plugin https://github.com/9p4/jellyfin-plugin-sso has been archived ("I'm tired of working on this after all the years", which, fair).
But it looks like it was forked into https://github.com/eddymoulton/jellyfin-plugin-oidc and development contiues, limiting itself to #OIDC but without #SAML
Nice! -
#Jellyfin #SSO plugin https://github.com/9p4/jellyfin-plugin-sso has been archived ("I'm tired of working on this after all the years", which, fair).
But it looks like it was forked into https://github.com/eddymoulton/jellyfin-plugin-oidc and development contiues, limiting itself to #OIDC but without #SAML
Nice! -
@homelab OK, after playing around a tiny bit, it seems that the code for this exists in #KaniDM
- https://github.com/kanidm/kanidm/pull/2968
- https://github.com/kanidm/kanidm/pull/3535/
but what doesn't exist is ability to reach it and set that up for a user. Oh well. -
@homelab OK, after playing around a tiny bit, it seems that the code for this exists in #KaniDM
- https://github.com/kanidm/kanidm/pull/2968
- https://github.com/kanidm/kanidm/pull/3535/
but what doesn't exist is ability to reach it and set that up for a user. Oh well. -
Authentik is an open-source identity provider that brings single sign-on (SSO) to your self-hosted services.
Manage access to apps like Jellyfin, Immich, Nextcloud, Vaultwarden, and more from one place, with support for OAuth2, OIDC, SAML, LDAP, and other authentication standards.
A powerful tool for anyone running a homelab or self-hosted infrastructure.
👉 https://digitalescapetools.com/tools/tool.html?id=authentik
#OpenSource #SelfHosted #Authentik #SSO #Homelab #Privacy #FOSS
-
Authentik is an open-source identity provider that brings single sign-on (SSO) to your self-hosted services.
Manage access to apps like Jellyfin, Immich, Nextcloud, Vaultwarden, and more from one place, with support for OAuth2, OIDC, SAML, LDAP, and other authentication standards.
A powerful tool for anyone running a homelab or self-hosted infrastructure.
👉 https://digitalescapetools.com/tools/tool.html?id=authentik
#OpenSource #SelfHosted #Authentik #SSO #Homelab #Privacy #FOSS
-
🔐 voidauth/voidauth
Single Sign-On for Your Self-Hosted Universe
Provides SSO authentication and user management for self-hosted apps with OIDC, LDAP, MFA and passkeys
⭐ Stars: 2152
📅 Last Update: Jun 10, 2026https://github.com/voidauth/voidauth
#selfhosted #homelab #selfhost #selfhosting #opensource #sso #authentication
-
After trying #Keycloak for a while - trying to integrate it with ForgeJo for Single-Sign-On (#SSO), I wasn't really satisfied with Keycloak. Keycloak's error messages were too unhelpful. The documentation, too nebulous. I lurked in their forums a bit, but didn't really want to use Slack as some sort of depended-upon service. Whatever the Keycloak error messages said, the eventual solutions usually ended up being so disconnected with the error message, that it dawned on me that the Error messages were effectively "Red Herrings" - served only to throw me off the trail.
Keycloak had a vibe to it that I'd describe as "Enterprise Bozak". It had the *look* of professionalism - making a solid effort to *appear* attractive to higher-up management types - but it didn't really *deliver* the helpfulness I was expecting, to actually overcome technical hurdles encountered. I've set Keycloak aside for now, and I'm trying out #Authelia instead, with an LLDAP backend. They seem easier to work with, as the error messages were good so far: had more of a technical helpfulness. After several hours of tinkering, I've set up my first LLDAP/Authelia users, including registering a passkey. I'll next see if I can integrate the Authelia SSO to #ForgeJo.
#infosec #OpenSource -
I've installed Pocked ID recently and switched many of my self hosted services over to it, and I absolutely love it! It's pretty, it's fast, it works really well!
Pocket ID is an Open ID provider that you can use for self hosted Single Sign On.
I just wish more services supported it!
-
I've installed Pocked ID recently and switched many of my self hosted services over to it, and I absolutely love it! It's pretty, it's fast, it works really well!
Pocket ID is an Open ID provider that you can use for self hosted Single Sign On.
I just wish more services supported it!
-
SSO-Kräfte fretten Stützpunkt der Baltischen Flotte in Kronstadt
#Angriffskrieg #Europa #Ukraine #SSO #BaltischeFlotte #Stützpunkt #Kronstadt #Krieg #Russland #Drohnen #Kriegsverbrecher #Staatsterrorismus #Besatzer #Invasoren #Kampfverluste
-
SSO-Kräfte fretten Stützpunkt der Baltischen Flotte in Kronstadt
#Angriffskrieg #Europa #Ukraine #SSO #BaltischeFlotte #Stützpunkt #Kronstadt #Krieg #Russland #Drohnen #Kriegsverbrecher #Staatsterrorismus #Besatzer #Invasoren #Kampfverluste
-
New Release: We’ve extended c4k-keycloak with WebFinger support. Now, SSO via Tailscale works.
-
New Release: We’ve extended c4k-keycloak with WebFinger support. Now, SSO via Tailscale works.
-
Moved my last two applications from Keycloak to Authentik.
Having a simple way to say "This group of users is atuhorized to log in to this application" is literally the reason I switched.
-
In my #SSO / #IdM adventures, looks like if I wanted to allow people to use my hackerspace's #OIDC SSO to access my services, I can configure this in #Authentik, but not in #KaniDM 🤔
-
🌟 LemonLDAP::NG 2.23 released!
ℹ️ Improvements on CAS/SAML/OIDC, on 2FA management, hooks, Crowdsec and configuration
➡️ https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-23-0-is-out/
#IAM #SSO #CAS #SAML #OpenIDConnect #OpenSource #LogicielLibre #Perl
-
Grade festgestellt, wie kacke es ist, sein Admin-Passwort für #homeassistant vergessen zu haben. Super mühsam über USB-Tastatur und HDMI-Adapter in OBS irgendwie per befehl zurücksetzen...nervig. Wird Zeit überall #sso aufzusetzen. Jemand Tipps? Ich liebäugle mit #authenticate
-
#music #Ivasiuk #song #Ukraine #SSO
ССО 10 років і, пісня в їхньому виконанні https://youtu.be/NhrsPgpSx_g
А також вітання зі святом від автора https://youtu.be/AcdSdVV91ZA -
Logins voll im Griff! 🔐 #shipit
**authentik**: Die mächtige Open-Source Identity-Lösung für dein Homelab. Unterstützt OAuth2, SAML, LDAP & mehr. Sicher, flexibel & hübsch!
Link: https://github.com/goauthentik/authentik
#authentik #SSO #SelfHosted #Security #Homelab #OpenSource #RadioTux