Blogged: Customizing a single client sign-in using parameters in Duende IdentityServer
data:image/s3,"s3://crabby-images/6df1f/6df1f4736aedb5c8119936b01c4966aa5c9f446a" alt=""
Blogged: Customizing a single client sign-in using parameters in Duende IdentityServer
The Umbraco OpenID Connect example package now runs on Umbraco 15.2.1.
#Umbraco #OpenSource #OpenIDConnect #Auth0 #composableDXP @umbraco
I’m *trying* to like #Python again, but PEP-761 requires #sigstore. #OpenPGP key management has issues, but this requires trusting #openidconnect from #Google & #Microsoft. Plus there’s a stated design goal of supporting automated signatures from private keys held by #GitHub.
Easier? Probably. Safer? Probably not. Security is about trust and the required certificate authorities haven’t earned mine over the past 20 years. As always, YMMV.
Blogged: ASP.NET Core delegated OAuth Token Exchange access token management
I love it when a service supports Open ID Connect, like the recently installed #Beszel.
#IAM #SSO #lemonldap #lemonldapng #CAS #SAML #OpenIDConnect #OpenSource #FreeSoftware #Perl
Blogged: ASP.NET Core user delegated access token management
https://damienbod.com/2025/01/15/asp-net-core-user-delegated-access-token-management/
Unlocking Cross-Cloud Access: Kubernetes OIDC Takes Center Stage
In a groundbreaking approach to cross-cloud access, Kubernetes OIDC emerges as a powerful tool for seamless communication between GKE and EKS. This article explores the intricate setup that enables po...
https://news.lavx.hu/article/unlocking-cross-cloud-access-kubernetes-oidc-takes-center-stage
Updated Microsoft Entra ID client examples in ASP.NET Core
https://github.com/damienbod/MicrosoftEntraIDAuthMicrosoftIdentityWeb
Updated .NET 9, Openiddict 6.0, Angular 19
https://github.com/damienbod/bff-openiddict-aspnetcore-angular
Back in April, I had to fight with Pac4j adding OpenID Connect to an application that, for the first time in many projects, had a public/anonymous section.
Out of frustration, I then created my own project, and now after months of procrastination, I'm releasing 1.0.0-rc-1
https://github.com/tbroyer/oidc-servlets
(and before you ask, the project at work isn't using this, it's still using Pac4j)
LemonLDAP::NG provides #authentication (#LDAP, #ActiveDirectory, #Kerberos, #Database, #SSL, #SocialNetworks, #CAS, #SAML, #OpenIDConnect, ...), authorization (access rules for applications based on attributes and groups) and accounting (user identity in logs).
#AskFedi: Which characters are legal in #OpenIDConnect subject identifiers?
Which document/spec/RFC defines the set of legal characters?
The #OIDC spec just says "The sub value is a case-sensitive string." #BangHeadHere
Please boost if you know someone who might know!
The Umbraco OpenID Connect example package now runs on Umbraco 15.1.0.
#Umbraco #OpenSource #OpenIDConnect #Auth0 #composableDXP @umbraco
Blogged: Using Entra External ID with an Auth0 OpenID Connect identity provider
Edit: This has been answered
I'm super confused after reading http://www.thread-safe.com/2012/01/problem-with-oauth-for-authentication.html and its take-home message that we should *not* be using #OAuth2 for authentication: that's what #OpenIDConnect is for.
If that's the case, why does #Forgejo, Gitea etc. allow OAuth2 to be used this way?
That blog post was from 2012 but I've seen the same advice in 2019 at https://github.com/zmartzone/lua-resty-openidc/issues/261#issuecomment-483841062 : “OAuth 2.0 cannot be used for user authentication”. (That GH issue is part of what I'm chasing down as part of dev work.)
Struggling to containerize Duende IdentityServer?
Part 2 of my series tackles a key challenge: making IdentityServer and client apps work in Docker!
Read more at:
https://nestenius.se/net/identityserver-in-docker-containers-part-2/
#LemonLDAPNG 2.16.4 (#LTS) has been released (#LemonLDAP / #LDAP / #LightweightDirectoryAccessProtocol / #WebSSO / #SingleSignOn / #SSO / #OpenIDConnect / #CAS / #OAuth / #OpenID / #REST / #SAML / #SOAP) https://lemonldap-ng.org/
#LemonLDAPNG 2.20.1 has been released (#LemonLDAP / #LDAP / #LightweightDirectoryAccessProtocol / #WebSSO / #SingleSignOn / #SSO / #OpenIDConnect / #CAS / #OAuth / #OpenID / #REST / #SAML / #SOAP) https://lemonldap-ng.org/
New Microsoft documentation: Configure OpenID Connect Web (UI) authentication in ASP.NET Core
Thanks Stephen Halter and Rick Anderson for your help in creating this.