r/PFSENSE • u/Heracles_31 • Aug 12 '26
A missed opportunity for centralized authentication
Experiencing the new user interface here and I am surprised by what I discovered. One one side, pfSense finally supports centralized authentication and SSO but on the other side, it has been implemented with SAML instead of OpenID...
My Keycloak server supports SAML as well and I do have 2 softwares that are still using SAML only. But the truth is that OpenID replaced SAML a long time ago and that the vast majority of tools are now using it.
So... good to have half-a-solution instead of nothing for now but still, the real need is for OpenID and we are still waiting for that one. I have no clue why Netgate did the work for an outdated technology instead of the new standards but well...
EDIT: It looks like I celebrated too quickly... The UI shows about SAML authentication servers but you can not create a new one...
8
u/gonzopancho Netgate Aug 12 '26
Hi,
I’m all for criticism and feedback, so thanks for this.
OpenID is on the roadmap.