6 ms·
Most of the comments seem to confirm (all but one at time of writing) that this feature is more intended for corporate/business environments. Does anyone know i
by DoctorOW 1y ago
Most of the comments seem to confirm (all but one at time of writing) that this feature is more intended for corporate/business environments. Does anyone know if Vaultwarden has commercial users? By no means am I arguing against the inclusion of this feature, I'm just curious. Everywhere I've worked that was big enough to use SSO was also wary of selfhosting FOSS tools. I should clarify I don't consider myself working in tech, fwiw.
- prmoustache 1y agoMy company just started hosting an instance for its employees 2 months ago.
- Disposal8433 1y agoI'm a user, not an expert on all this but: SSO is indeed meant for a corporate environment, not for personal use. And from what I saw, companies would rather pay for a simple SSO provider than use any self-hosted solution. That means you either use Google or Microsoft, nothing else. LastPass is out of question due to the security issues in the past. I always advocate for Bitwarden but I'm not sure they can handle any kind of SSO yet. And Vaultwarden, being a fork of a not-so-famous-yet password vault (at least in the managers's world), is not a contender anywhere.
- stronglikedan 1y ago> That means you either use Google or Microsoft, nothing else. My fairly large (>20k) company uses Okta. That's just to say, be wary of issuing ultimatums.
- tracker1 1y agoI recall a happy/fun environment using Microsoft Entra (Azure AD) SSO, in order to sign into Okta SSO, in order to access Azure environment(s), among other apps. SSO Inception.
- maxwellg 1y agoSSO chaining is super common in large corporate environments. Different orgs might have their own SSO IDP, acquisitions often bring their own, etc. Once a provider is in use, it is quite difficult to tear out later while keeping everyone in their proper accounts in all the apps that tie in. Many apps are really bad at SSO migrations, or deduplicating multiple SSO identities to a single user account.
- threePointFive 1y agoMy company just implemented the SaaS Bitwarden with Google SAML on their Enterprise Plan. Very easy to set up, not too expensive ($6/user/month). Their compliance page made it much easier to sell to my manager who had to give the final approval: https://bitwarden.com/compliance/ https://bitwarden.com/compliance/. It is only used by my department so far and we're still doing manual invites rather than integrating with the SCIM features so I can't speak to that. My biggest annoyance is that, as an admin, unlocking the vault still prompts for the master password rather than letting me select SSO without logging all the way out.
- FuriouslyAdrift 1y agoPaid Bitwarden does SSO (SAML 2.0 or OIDC) https://bitwarden.com/help/about-sso/ https://bitwarden.com/help/about-sso/
- franga2000 1y agoThe whole "SSO is meant for enterprise" thing is sales bullshit. Big enterprises can't live without SSO, so everyone started charging extra for that to milk more money out of them, but this doesn't mean it's not hugely beneficial or "meant for" smaller orgs or even individuals. Anyone can spin up an Authentik/Authelia/Keycloak/whatever instance or even use Microsoft/Google if they already pay for it in a matter of minutes. The only reason people don't is because tons of apps make it annoyingly difficult to integrate SSO or don't offer it at all in the lower price tiers. If app installers started with "create a root user or paste the OIDC secret here", everyone and their dog would be running SSO. But that's not as profitable.
- ffsm8 1y agoVaultwarden is not a fork though? And also, in what world is SSO meant for enterprise? It's Single Sign On, not having to login separately for each service is perfect for any context of any size - wherever these services only have 1 user or 100 thousand.
- raybb 1y agoAs someone who manages the vault warden instance for a nonprofit with many volunteers but no fulltime employees I see this as a wonderful thing. Yes bitwarden has a nonprofit discount but no playing wack a mole with which of the 20+ volunteers are active at any moment to avoid getting a huge bill isn't worth it vs self hosting.
- prometheon1 1y agoI'm in a similar situation, having many volunteers does not mean we have the budget to pay 5-10 euros per month for all of them for all the tools needed for work. Self-hosting and managed hosting of open-source software are the best option for us, including SSO and password management
- preisschild 1y agoVaultwarden is a lot easier to self host than Bitwarden But like all community-made open source stuff, If you want to use it for "production" stuff you should invest in audits and contribute/fund development
- warkdarrior 1y agoI've been self-hosting Bitwarden (and giving them money) for a few years now, it is really easy with Docker and a reverse proxy. What kind of challenges did you encounter with Bitwarden?
- preisschild 1y agoLast time i checked you needed a MS SQL db...
- warkdarrior 1y agoIt is all included in their Docker compose file.
- preisschild 1y agoI use Kubernetes But also what about the whole lifecycle? I can easily deploy a HA Postgres cluster that is backed up for me. I'd have to do the same thing to back up BW.
- warkdarrior 1y agoDon't know much about HA (it looks like Bitwarden does this through Helm https://bitwarden.com/help/self-host-with-helm/ https://bitwarden.com/help/self-host-with-helm/), but backup is a matter of simply copying files: https://bitwarden.com/help/backup-on-premise/ https://bitwarden.com/help/backup-on-premise/
- cheema33 1y ago> Last time i checked you needed a MS SQL db... For real? That would mean a requirement for a software license that costs about $1,000 for the cheapest option.
- c0balt 1y agoI'm hosting it for our team at a public institute, we are strongly supportive of OSS and have interest in keeping our data on premise. Team of <10 though so hosting is trivial with NixOS. We also have almost no money available for purchasing software so official self-hosted bitwarden was not an option unfortunately (if we had money, that would've been the way to go).
- homebrewer 1y agoI support an installation for a couple hundred users. It's been working fine for several years now, including browser plugins and mobile clients. If the project goes under, it's easy to export everything and import into the official Bitwarden. (Whose server I really don't enjoy, it's very enterprise-y and heavy on resources for no real reason I could find.)
- kuschku 1y agoSSO is really important in the "few tools, many users" case, but just as important in the "many tools, few users" case. I'm self hosting dozens of tools, and without SSO I'd have to set up username, password, TOTP and WebAuthn for each and every one of them, my 2FA app would be 90% my own services. With SSO though, it's much simpler. I can just run an OIDC server and log into all my self-hosted services once, and I can use all of them. Vaultwarden is an exception to the rule though, as you can't really bootstrap that in the individual case. Another use case I'm currently exploring is for sharing netflix/prime/disney+ passwords with roommates, partners and friends. They just sign in with their Google/Apple/whatever account and get access to the shared streaming provider passwords.
- arjvik 1y agoWhat's your (OSS?) OIDC server of choice? Authelia? Authentik? Keycloak? (These are the three I see a lot about.) Something else?
- eloh 1y agoCan recommend Kanidm
- sp0ck 1y agoKanidm made some weird decision that ruled it out in one of big organisation I try to deploy it. Separate Radius password. For telco that’s half its use cases, and there is separate random password. Whole Network engineering department was like WTF ? You can’t have single password which is one of important reasons to have SSOA.
- mmcnl 1y agoI've used Authelia for a few years and it's great. It does exactly what I need/want. Not more, not less. It's also never failed me.
- gh02t 1y agoFor self hosting, PocketID is about as easy to set up and maintain as it gets.
- Timshel 1y agoStarted working (based on previous work already done) then maintaining the PR for my personal self-hosted stack. Had then some fun adding roles/groups support (not yet merged).
- toomuchtodo 1y agoSSO isn’t an enterprise feature, it is an access control and governance feature regardless of user population.
- rat9988 1y agoWho needs it except entreprises for the 99.99% usecase?
- arjvik 1y agoE.g. the homelab admin who doesn't want their family to have to create and manage accounts on 12 different self-hosted services.
- cyberax 1y agoSelf-hosters so you don't need to record 100 different passwords for your own services?
- mcpherrinm 1y agoEveryone from the single-user homelab to the biggest companies should have SSO.
- BirAdam 1y agoVaultwarden has been in use at two companies I’ve worked for, yeah. Modest, mid-size companies, one with a delusion of grandeur. While both didn’t care for self-hosting, the executives were wary, in both cases, of SaaS password management after LastPass.
- kriops 1y agoI’ve used it at a previous job. SMB, ca. 200(?) employees.
- chrissssdotcom 1y agoSame here! - 350-400 employees, but the main requirement was that it could be accessed with no internet. Came from Keepass, love it. SSO just makes it better.
- Gormo 1y ago> Does anyone know if Vaultwarden has commercial users? Yes, it does.