10 ms·
How Open ID Connect Works
- simonw 3y agoThis is a really useful guide, but it's still not enough... every time I read something like this I get to a bit like this: "Create a role on AWS, add trust policy specifying which github org+repo are allowed to access this AWS role. Create an identity provider for github actions." I think need a full video of clicking around in the AWS console here, because the idea of having to figure out how to do that myself is horrifying to me.
- iacguy 3y agoTrue. Will try to add a loom video to this article
- g_p 3y agoI've seen the same issue with instructions for how to configure Keycloak as an OIDC provider - given Keycloak has so many options (some of which might well be security significant), you'd almost want a step by step explicit statement of what every setting should be, to get to a tested, validated and secure configuration. Which flow and service/grant etc seems to matter a lot, and be a good example where you'd want a very clear playbook of step by step instructions that you can hand off to someone else to unambiguously follow.
- simonw 3y agoI've been wanting to setup GitHub Actions to use OIDC with Google Cloud (for deploying to Cloud Run) for a couple of years now, but I find the documentation completely inscrutable: https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/configuring-openid-connect-in-google-cloud-platform https://docs.github.com/en/actions/deployment/security-harde...
- sigwinch28 3y agoThe gist of it (pun intended) is that GitHub issues GitHub-issued (not issued by your cloud provider!) OIDC tokens to your job runs, and then your job exchanges those tokens for permissions with your cloud provider, which you have configured to trust tokens from GitHub. From experience, OIDC authentication to cloud providers from GitHub actions boils down to: 1. Get your GitHub actions workflow to be able to work with its own (GitHub) tokens by configuring workflow permissions. 2. Configure your cloud provider to verify tokens issued by GitHub actions OIDC server thingymabob (technical term). 3. Configure your cloud provider to grant permissions in that cloud provider (or issue its own tokens with those permissions) based on certain values in the verified GitHub tokens that is presented with. If your cloud provider trusts GitHub, then it can treat the values in the token (workflow name, branch run from, owner and name of GitHub repo) as trusted. 4. Use a GitHub action from your cloud provider to do the negotiation with your cloud provider when your job runs, performing the exchange configured in (3).
- simonw 3y agoFor me to follow that procedure I really do need meticulous step-by-step instructions, with a full set of screenshots for every interaction I need to have with any of the web consoles involved. If I ever get up enough courage to do this myself I'll take and publish those screenshots, but I'll probably continue to drag my heels for a few more years.
- j33zusjuice 3y agoJesus. We fucked with keycloak for like a minute at one of my past jobs where we used FreeIPA. Gave up, and just didn’t use that functionality beyond whatever default stuff it m if it do. IAM is hard. I kind of enjoy it, but there’s always a hundred other things I’m accountable for managing.
- jcadam 3y agoWhat you're supposed to do is have an alcohol-fueled all-night session of modifying values in your Keycloak realm settings one at a time until it works. Then, you export the realm file and tell everyone not to mess with it.
- jcadam 3y agoEnabling devs to do development work on their local machines with Keycloak in the stack is... fun /s.
- ParetoOptimal 3y ago>I think need a full video of clicking around in the AWS console here, because the idea of having to figure out how to do that myself is horrifying to me. Or even better, was CLI commands or terraform.
- simonw 3y agoCLI commands would be OK. Terraform wouldn't, because then I'll have to learn enough Terraform to run it - I'd rather minimize the number of extra tools I have to figure out here.
- deleted 3y ago[deleted]
- sakopov 3y agoIt's not terribly difficult. I just threw a quick gist to help with this OIDC for Github in AWS - https://gist.github.com/sakopov/a66ef55f9713649e7d7b9b4a91d64be2 https://gist.github.com/sakopov/a66ef55f9713649e7d7b9b4a91d6...
- simonw 3y agoThanks for that, that's actually really useful - though I don't use cloudformation yet so I'd have to learn enough of that to put this into action. Love that you have to just happen to know about "1b511abead59c6ce207077c0bf0e0043b1382612" as the magical "known thumbprint" for GitHub!
- sakopov 3y agoNo worries, glad it's helping. AWS Console will automatically discover the thumbprint when adding a new provider, so I just grabbed it from there.
- spapas82 3y agoGreat work! If you wanna understand how Open ID Connect works using only HTTP requests/responses based on the specification (https://openid.net/specs/openid-connect-core-1_0.html https://openid.net/specs/openid-connect-core-1_0.html) I've written an article here: https://spapas.github.io/2023/11/29/openid-connect-tutorial/ https://spapas.github.io/2023/11/29/openid-connect-tutorial/
- igor47 3y agoThanks, your article is what I was hoping for when I clicked the OP. I've been putting all my self hosted services behind OIDC recently using Authentic and I've been wanting to actually understand how the flow works under the hood, this really helped
- EvanAnderson 3y agoIs it "keycloak.example.com" or "kc.example.gr"? > ...and your keycloak server is hosted on https://keycloak.example.com https://keycloak.example.com. This realm will have a base url with the value: https://kc.example.gr/realms/sample-realm/ https://kc.example.gr/realms/sample-realm/...
- spapas82 3y agoAh thanks for catching this!
- munchbunny 3y agoOIDC (and the rest of the OAuth umbrella of stuff) is one category where every time I have to work with the protocols I think "there must be a less confusing way" and then have a failure of imagination for a simpler way to accomplish the same thing. I think it's because the protocols are conceptually simple, but the cryptographic parts, especially the PKI parts, make them intricate to understand exactly who is attesting or validating exactly what.
- shadowbanned4 3y agoI hand-wrote the largest OIDC deployment in the world, after experimenting with other libraries. It is awful. Do not use OpenID, do not use OIDC.
- Craighead 3y ago[dead]
- taeric 3y agoDo you have a recommendation on what to use instead?
- shadowbanned4 3y agoHTTP basic auth, TLS with client certs.
- dboreham 3y agoThose things don't do what OIDC does?
- shadowbanned4 3y agoThey do them with much less complexity than OIDC.
- 3y ago
- bob1029 3y agoI stopped spending mental cycles trying to parse these standards after taking myself on a ride with a completely DIY SAML service provider implementation. Today, we use OIDC & SAML to authenticate all of the things. But, I cannot explain how any of it works in terms of detailed protocol, certificate chains, etc. We actually have no in-house configuration along this axis because we only use products, such as web function runners, that live inside the IdP's platform. These can be trivially opted-in for MFA authentication with a single dropdown election if you are using Azure. If your mission is to build your own IdP platform and/or SP client libraries, then it totally makes sense to dive into this rabbit hole. Otherwise, make it someone else's problem. An occasional headline in the news about a token not expiring in time, etc, is not worth chasing unless you intend to compete directly with these providers and build your own identity platform. If Microsoft can get it wrong sometimes, so will you.
- mrweasel 3y agoI've been working with Pythons Social Auth, because I didn't want to spend brain power trying to figure out exactly how OIDC works. Still that isn't enough, because OIDC isn't always implemented the same. E.g. Apparently you can return OIDC claims in two ways, nested or flat, but most clients do understand that, so if your server don't know how to do flat and your client only does flat, then you have a problem.
- patmorgan23 3y agoYeah, lots of problems also come from JWT being a garbage Standard that doesn't actually standardize how to format a token.
- uxp8u61q 3y agoSince OP seems to be the website author... You should remove or alter the ::selection style in your CSS. In dark mode, selecting text makes it illegible (white on white).
- cod1r 3y agoI've recently been looking into passkeys and it seems much simpler than this.
- Manouchehri 3y agoPersonally, I would be worried about losing access to an account if I only relied on a passkey.
- jeroenhd 3y agoI don't really understand this problem. Just click the "forgot password" link (perhaps "lost passkey" for passkey-first services?).
- tesdinger 3y agoHow can I backup a passkey on a sheet of paper?
- jeroenhd 3y agoPasskeys and OIDC are not directly related. If all you want is "authenticate to AWS" then yes, passkeys would work, but so would a simple password, or a TLS client certificate, or whatever other technology you like for authentication. OIDC works for things like "use my employer's login to get access to AWS resources without having a separate AWS password". For certain OIDC authentication implementations, you can actually use passkeys. Standard passkeys should work perfectly fine with Keycloak's WebAuthn implementation, for example, either as a second factor or as the first factor in the login flow.
- xvinci 3y agoMaybe I am really missing something seeing how other comments didnt mention it, but is this REALLY explaining how OIDC works? I don't see it.
- krooj 3y agoNo, there's no explanation.
- deathanatos 3y agoNo. This is more like a "how to configure an OIDC integration between Github Actions & AWS" tutorial. It uses OIDC, but "How [OIDC] works" is too broad of a title for what the article ends up covering, IMO.
- smalu 3y agoI do not known why OIDC has so many bad comments here. At my $company we are using Keycloak for multi-realm (multi-tenant) authentication of users and clients (applications). Yes, the learning curve is long for OIDC and even longer for Keycloak. The FreeMaker Template Engine is awful compared to Twig. Updates of Keycloak can break something, so better have proper test/stagging environment. But this is the tax for not implement something, that is not in core domain of organization. OIDC solves problems for OAuth2 like "every Identity Provider has different endpoints" with OpenID Connect Discovery (/.well-known/openid-configuration).
- carstenhag 3y agoAnd then in real life I have to use the idm of 5 car manufacturers. Their devs being in South korea, China, US, Italy (we are in Germany). Impossible to manage meetings. Impossible to adhere to the standard. Impossible to demand that they use the well-known config. Impossible to agree on a good UX (by using sane config values for token validity).
- chucke 3y ago> OIDC solves problems for OAuth2 like "every Identity Provider has different endpoints" with OpenID Connect Discovery Not really: https://www.rfc-editor.org/rfc/rfc8414.html https://www.rfc-editor.org/rfc/rfc8414.html
- starttoaster 3y agoThis doesn't really explain how OIDC works, it just explains the flow of requests a user would see if they're setting up OIDC for authentication between two systems for the first time. But beyond that, I'd say in future blog posts it would look a bit more professional to use some kind of architecture diagram making software, rather than somebody's napkin drawings. It's a little more difficult than it needs to be deciphering these graphics. To be entirely honest, I'd settle for mspaint-level quality if none of the free diagram making tools out there catch your eye.
- mooreds 3y agoThis was a nice overview of why you'd use OIDC to get short lived access tokens (in the pure sense, not in the OAuth sense) with a heavy emphasis on AWS. Not really an overview of OIDC, though.