Details
-
Improvement
-
Status: Resolved
-
Minor
-
Resolution: Fixed
-
None
-
None
-
None
Description
We currently use Knox to authenticate users with Microsoft via pac4j federation config.
We have an OIDC client secret (oidc.secret) stored in plaintext in the topology file but we'd like to obfuscate and not have the plaintext value in the topology XML.
This is because OAuth strongly recommends to have the "client secret" protected.
The alias service currently only seems to work for LDAP, it would be good if we could use it inside our pac4j block too.