4 ms·
> only enterprises care about SSO. Well that's just fundamentally not true any longer with OIDC. There are even simple OIDC auth plugins for reverse proxies no
by dugite-code 3y ago
> only enterprises care about SSO.
Well that's just fundamentally not true any longer with OIDC. There are even simple OIDC auth plugins for reverse proxies now. It's what I consider a fairly basic feature in this day and age and it's a shame every time it's disregard as simply an enterprise feature
You might have an argument with saml, because it's a right pain, but not OIDC
- IshKebab 3y agoI don't really follow. If you're setting this up for a couple of people you can just manually add accounts. It's probably even easier than setting up OIDC or whatever. It's only when you get to enterprise level and IT departments want centralised accounts that it matters. They really need SSO. Frankly I think it's a pretty great status quo. Consider the alternative, which is that the software would either not exist or be closed source.
- kuschku 3y agoIf only enterprises need SSO, please tell me how I'd set up WebAuthn 2FA for these services without SSO. Also, please explain how I'd change my password across this project, miniflux, seafile, postfix, dovecot, radicale, quassel, synapse and more all at the same time without SSO (in case the password got leaked) So far, using keycloak and adding SSO support to these apps seems certainly like an easier option even for setups with 3-5 users such as my own.
- dugite-code 3y agoHeck even in a single user environment like my homelab SSO is the simpler option.
- IshKebab 3y agoYou would do it manually. Not the end of the world if you have <10 accounts on all of those services. For an enterprise with hundreds of users, that would mean thousands or tens of thousands of accounts to manage manually. Totally impossible. It's a feature that's absolutely mandatory for enterprises, but "nice to have" for anyone else. That's why it's a great feature to use for price discrimination.
- kuschku 3y agoHow do I manually setup WebAuthn 2FA with this project? Please give me a guide. Because afaict, the only way to get proper 2FA with this project is by paying them for SSO.