Uploaded image for project: 'Apache Knox'
  1. Apache Knox
  2. KNOX-2534

Allow alias to be used in pac4j topology block

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Minor
    • Resolution: Fixed
    • None
    • None
    • KnoxSSO
    • None

    Description

      We currently use Knox to authenticate users with Microsoft via pac4j federation config. 

      We have an OIDC client secret (oidc.secret) stored in plaintext in the topology file but we'd like to obfuscate and not have the plaintext value in the topology XML.

       

      This is because OAuth strongly recommends to have the "client secret" protected.

       

      The alias service currently only seems to work for LDAP, it would be good if we could use it inside our pac4j block too.

      Attachments

        1. knoxsso-oidc.xml
          2 kB
          Michael Boulter

        Activity

          People

            amagyar Attila Magyar
            bollerboller Michael Boulter
            Votes:
            1 Vote for this issue
            Watchers:
            6 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0h
                0h
                Logged:
                Time Spent - 2h
                2h