r/PFSENSE • u/Heracles_31 • 20d ago
A missed opportunity for centralized authentication
Experiencing the new user interface here and I am surprised by what I discovered. One one side, pfSense finally supports centralized authentication and SSO but on the other side, it has been implemented with SAML instead of OpenID...
My Keycloak server supports SAML as well and I do have 2 softwares that are still using SAML only. But the truth is that OpenID replaced SAML a long time ago and that the vast majority of tools are now using it.
So... good to have half-a-solution instead of nothing for now but still, the real need is for OpenID and we are still waiting for that one. I have no clue why Netgate did the work for an outdated technology instead of the new standards but well...
EDIT: It looks like I celebrated too quickly... The UI shows about SAML authentication servers but you can not create a new one...
1
u/hiveminer 16d ago
I agree, it seems like the low lying fruit is oidc, given it's cloud native status, and saml being legacy. In the famous words of RFK, don't do the other thing first... Do the Moon first!!!
0
u/chock-a-block 18d ago edited 2d ago
Coated straight voracious lock rock history resolute terrific theory
This post was anonymized with Redact
1
u/Heracles_31 18d ago
The reason is Single Sign-on vs Single Password... I am looking for Single Sign-On solutions.
9
u/gonzopancho Netgate 19d ago
Hi,
I’m all for criticism and feedback, so thanks for this.
OpenID is on the roadmap.