7 ms·
State of OpenID Connect Providers
- semitones 4y agoIs the current state of affairs any better for SAML identity providers? I need to integrate SSO into our app and am also worried about having to write custom code for every identity provider we want to support.
- yrro 4y agoSAML delenda est
- zerkten 4y agoYou could integrate with something like Ping Federate. Then customers configure their identity provider to connect to your Ping Federate instance. I've seen the workflow for the support team to enable customers and it's not terribly difficult with the usual issues around expired certificates. Weird customers can be outsourced to Ping Federate support for guidance.
- Avamander 4y agoSAML in my (anecdotal) experience seems to be worse, if it's supported at all.
- neeleshs 4y agoMost IdPs support SAML IIRC
- iamjake648 4y agoWe've been quite happy with Auth0 to solve this problem.
- neeleshs 4y agoIf an IdP is SAML compliant, you only need to write code once. Of course, if you also want to authz based on IdP roles, you will need to have a mapper (from your app perms to IdP roles), but this is not because of differences in IdP
- A321321 4y agoI am very surprised by this. I have successfully and interchangeably connected to many OpenId Connect providers, all without any issues. Providers like Azure, Ping, Octa, Auth0, ….
- brunoqc 4y agoMaybe they want to sell you zitadel.
- AtNightWeCode 4y agoAgree, OIDC is the simplest and most versatile way to logon users and can be used in other scenarios. The discussion usually is where to store the tokens.
- fghjklty 4y agothe point is the lack of control of your credentials if OIDC takes on instead of OID. if you log in with your github credentials and elon musk buy github and ban all the red heads, you just lost your accounts on azure, ping, octa, etc.
- voidwtf 4y agoYea, I’m also confused, Azure/Microsoft has the multiple redirect URLs feature the author mentioned in addition to not having an arbitrary user limit.
- gabrielsroka 4y ago
- yrro 4y agoI've had pretty good experiences with Azure Active Directory's flavour of OpenID Connect. Multiple callback URIs are supported per app registration.
- Wronnay 4y agoBut is Azure AD free? When I checked it out, it looked like you have to pay for using it?
- jansommer 4y agoAzure AD is 6$/mo per Premium P1 user as far as I know, but I think yrro is talking about Azure AD B2C and that's free up until something like 200,000 monthly active users (not affiliated with Azure but their calculator is my start page)
- hirsin 4y agoAAD without all the security features (p1/p2) is free, with some limitations you'll quickly hit if using as your main directory. https://jumpcloud.com/blog/understanding-aad-pricing-free https://jumpcloud.com/blog/understanding-aad-pricing-free is a decent overview
- jansommer 4y ago* 50,000 monthly active users
- yrro 4y agoI think there's a very limited edition available for free.
- feurio 4y agoI've had real issues with Azure. The (opaque, non JWT) refresh token seems to expire well before the access token is due to expire. Unless I force the access token to be refreshed 20 or 30 minutes before the stated expiry time then the session gets killed off. It works now, but there was a lot of head scratching and trail-and-error before I found out what was going on.
- vinckr 4y agoI would never advise anyone to write their own code to integrate with Open ID Connect. An open source solution pre-built from professionals like Ory Kratos or Keycloak saves you a lot of time and pain. https://github.com/ory/kratos https://github.com/ory/kratos https://www.keycloak.org/ https://www.keycloak.org/
- mschuster91 4y ago> An open source solution pre-built from professionals like Ory Kratos or Keycloak saves you a lot of time and pain. Keycloak in itself is a pain to manage as well. Without Terraform, you're lost... and integrating stuff with Keycloak is a pain as well. I've tried and failed to integrate a self-hosted GitLab instance, for example - their docs [1] don't specify anything how the Keycloak config is supposed to look like, the next best Google hit doesn't either [2], and somewhen in the last two years the third Google hit [3] got outdated - the Keycloak OIDC configuration UI got completely reorganized and renamed. Other stuff like Atlassian is a pain to integrate with Keycloak OIDC as well. So, if anyone could point me to a working configuration for modern Keycloak and GitLab, I'd be really thankful. And if doc writers could specify a working Terraform, Ansible or whatever code that specifies the Keycloak configuration the application understands, I'd be even more thankful. OIDC is a horrible mess, I get it, but if your users can't get it to work because you specify nowhere what exact flavor and quirks of OIDC your application need, it reflects badly not just on Keycloak but on your application as well. /rant [1] https://docs.gitlab.com/ee/administration/auth/oidc.html#configure-keycloak https://docs.gitlab.com/ee/administration/auth/oidc.html#con... [2] https://github.com/ChathuminaVimukthi/Gitlab-SSO-implementation-using-Keycloak/blob/master/README.md https://github.com/ChathuminaVimukthi/Gitlab-SSO-implementat... [3] https://dheeruthedeployer.medium.com/gitlab-integration-with-keycloak-e1b2ff11a177 https://dheeruthedeployer.medium.com/gitlab-integration-with...
- scrollaway 4y agoI don’t have the code handy because I’m on my phone but we use keycloak for archlinux.org. You should be able to find the terraform and config for it all on our gitlab instance.
- 4y ago
- gyulai 4y agoDisappointing to hear that the ecosystem has fared that poorly. Are there really no companies doing this that aren't part of "surveillance capitalism"? When it first came out, I seem to recall that Norton was one of the companies offering Open ID. With GDPR there's a compelling business case for a service provider that acts as a clearing house for personally-identifiable data, so that, as a business, one would only ever deal with anonymized data, thus effectively outsourcing GDPR compliance.
- adamrezich 4y agoI remember back in the mid-to-late 00s when OpenID seemed like the future…
- detaro 4y agoOpenID Connect basically only shares the name with the OpenID from back then too.
- MrGilbert 4y agoLove the fact that this fella also decided to go for a numeronym for his website.
- vbezhenar 4y agoIt's a shame that old OpenID was killed in favour of OpenID Connect. With OpenID I was able to log in to livejournal using OpenID implementation running on my own domain. With OpenID Connect I can only log in with blessed set of providers. Centralization sucks.
- schwap 4y agoThe standards for this experience exist with OIDC Discovery[1] and Dynamic Client Registration[2], unfortunately they aren't used but it's not because it isn't supported. [1] https://openid.net/specs/openid-connect-discovery-1_0.html https://openid.net/specs/openid-connect-discovery-1_0.html [2] https://openid.net/specs/openid-connect-registration-1_0.html https://openid.net/specs/openid-connect-registration-1_0.htm...
- kevincox 4y agoDo any big-name providers support this? For example trying the webfinger request described in the first link on gmail.com returns a 404. As much as I love the ability to use my own server it is going to fall flat for the vast majority of users if you can't support at least one of Google/Facebook/Twitter/Microsoft. OpenID was supported by Google, Yahoo, MySpace, Wordpress and a few other big names. Not ideal but enough that you could basically expect most users to be covered.
- deleted 4y ago[deleted]
- tlarkworthy 4y agoIt's here for Google https://accounts.google.com/.well-known/openid-configuration https://accounts.google.com/.well-known/openid-configuration Here for Microsoft https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration https://login.microsoftonline.com/common/v2.0/.well-known/op...
- BillinghamJ 4y ago
- jimkleiber 4y agoA solution I've been using and really enjoy is Hellō [0]. Basically I can integrate Hellō as the OIDC provider on my site (doing it on WordPress and Discourse for now but it can work for other sites) and then people login to their Hellō wallet and then that logs into my site. Hellō manages the social logins so I don't have to worry about adding a bunch of them (and update when new ones come out). It's also run as a cooperative, so I appreciate the business model behind it. [0]: https://www.hello.coop https://www.hello.coop
- pspeter3 4y agoI wish Discord supported OpenID Connect so I could use it as an authentication provider for Convex.
- Eduard 4y agoBut OAuth2 can be used for authentication as well, no?
- AtNightWeCode 4y agoOIDC is a layer that simplifies the horrors of OAuth2. I am so fking looking forward to the death of this of fking grbage forum. I at some low point signed up to this forum. And I learned mostly nothing. And I am stilled annoyed cause it have a major impact at companies. ChatGPT beats 99.9% of HN users at everything when it comes to known facts, ChatGPT can easily tell, explain, and debunk this kind of fraud/ad content. The post is mainly incorrect. sry for hijacking yr comment
- buttocks 4y agoNot seen mentioned in this thread: Slack. Their oidc implementation is standard and well documented.