3 ms·
Because auth is super hard? Have you tried implementing SSO for arbitrary OAuth2 providers?
by staticassertion 5y ago
Because auth is super hard? Have you tried implementing SSO for arbitrary OAuth2 providers?
- 9dev 5y agoNo, but there are both open source libraries, and complete authorisation servers. If you trust Okta, you can trust these, and embed them in your infrastructure. Auth only gets super hard if you try to be smart and deviate from best practices.
- staticassertion 5y agoCan you link me to these open source libraries that will handle arbitrary oauth2 providers?
- m12k 5y agoThis seems to be one of the more popular ones: https://www.keycloak.org/ https://www.keycloak.org/
- staticassertion 5y agoThanks, I'l check keycloak out.
- 9dev 5y agoAs I wrote in a sibling comment: Keycloak, for one: https://www.keycloak.org https://www.keycloak.org I've also heard good things about Hydra: https://www.ory.sh/hydra/ https://www.ory.sh/hydra/ Depending on your needs, an SSO proxy like Vouch works well for internal services: https://github.com/vouch/vouch-proxy https://github.com/vouch/vouch-proxy There's also an abundance of libraries for different programming languages to implement authentication or authorisation, lots of them battle-tested by thousands of services. It's not like providing secure services is impossible without Okta.
- mdoms 5y agoThis is ridiculously reductive.
- 9dev 5y agoCould you expand a little? Of course a HN comment is not giving you full instructions on implementing custom authentication infrastructure, but that doesn't mean it's impossible or somehow "wrong" to do so, if you rely on established libraries and patterns.
- Karrot_Kream 5y agoOAuth2 is a really complicated standard and is complicated to get correct. I mentally compare it with SIP which also has several open-source implementations but still often ends up getting outsourced to others due to the sheer complexity of the thing. Though in OAuth2's case I'm willing to say it's complicated because security is complicated. With SIP I really don't know why lol.
- photon12 5y agoDoing user IP address change detections as part of a heuristic vector for account compromise is sometimes a best practice and sometimes a great way to generate a bunch of useless noise, but I know which is less likely to break UX by integrating such a feature.
- ta34634643 5y agoI agree with you on not outsourcing authentication etc to a big provider like Okta, but OAuth2/SSO can get ridiculously annoying in large organization/s. If it's one app that you're dealing with, no worries. If it's multiple operating systems, multiple legacy and new apps etc, its a headache. Not that Okta particularly helps with that either though, it's a problem full stop.
- njsubedi 5y agoWhy would I ever need to support arbitrary Oauth2 providers? As long as they're following the standards, a generic Oauth2 client should suffice. If they're misaligned with the standards I wouldn't be using their service.
- ryan_lane 5y agoI can tell you never have, because there's no such thing as a generic OAuth2 implementation. They're all slightly different and incompatible. SAML is what you really want in terms of making things works more generically, but even that is generally a nightmare as you still need mappings.
- njsubedi 5y agoI can tell you don't know about OpenID Connect. ;)