Hello, everyone. I am planning to set up Single Sign-On (SSO). I wonder if I can use something like Red Hat SSO with two separate domains. I have one domain for Windows AD and one for Linux IDM. My idea is to use Red Hat SSO so that both domains will be able to access the same services. For example, I have one Nextcloud instance, and I would like users from both domains to use it with SSO.
Highly recommend Authentik for SSO.
I run it on it’s own sub domain and all my other apps on their own sub domains.
It has pretty much every login protocol you could want (oauth, saml, ldap) etc.
Currently using it for jellyfin, immich, linkwarden, freshrss, and seafile.
This is the way. I just hope they don’t start gatekeeping essential features behind the “enterprise” license. Already they have announced push-based 2fa (like Duo) will be enterprise which is a bit of a bummer but it’s honestly awesome software otherwise and beggars can’t be choosers!
Does it work for multiple domains (not Subdomains)? I’m currently using authelia, which can’t do that, which sucks.
I can’t imagine why it wouldn’t. The configuration just needs a URL, what domain they are actually on should be irrelevant.
For authelia, iirc it’s a problem with the way cookies work, but also with how they set their system up structurally. I don’t know the details anymore.
It it useful to use authentik with vaultwarden? Or is it redundant?
They don’t really do the same thing. I use both. Authentik provides 1 password/account for all my self hosted apps. Along with other people that use my services. I create one account on authentik and suddenly they can access everything.
I then save that password in vaultwarden.
For what it’s worth I don’t use SSO for my vault warden master password, that is a separate password not saved anywhere
Does it mean each time you host a new app you have to tie it to authentik? I will read aboot it later
Yes, when you look into a new self hosted app, you have to check if they offer some kind of SSO option. Authentik can pretty much do every protocol there is. Each all will have different instructions on how to set it up.
I see thank you :)