#oidc

2025-05-22

Proxmox in Enterprises: I'm often asked, 'Can we use our Active Directory, LDAP, or OIDC with Proxmox?' Yes, you can!

Let's have quick dive into installing and configuring Authentik and configure Proxmox VE to use OIDC as an additional authentication realm.

#Proxmox #ProxmoxVE #opensource #Authentik #OpenID #OpenIDConnect #OIDC #EntraID #enterprise #homelab

gyptazy.com/proxmox-authentik-

2025-05-20

Me to the library: Please verify the signature of this document.
Library: Document is OK.
Me: What keys did you use exactly?
Library: What keys?
Me: ...
Library: Well, I did not have any keys so I did not really check.
Me: 😠

#OIDC #infosec

2025-05-19

Trabalhando ativamente na integração de login do isaCloud Messenger com oAuth2 / OpenID Connect, o que permitirá uso do mensageiro com bases corporativas de autenticação...

Vai vendo...

#xmpp #oidc #oauth2

Trabalhando ativamente na integração de login do isaCloud Messenger com oAuth2 / OpenID Connect, o que permitirá uso do mensageiro com bases corporativas de autenticação... Vai vendo... #xmpp #oidc #oauth2

2025-05-10

Зачем использовать OIDC с GitHub Actions?

OIDC GitHub Actions может запрашивать временные токены, действительные только на время выполнения workflow, что значительно повышает безопасность и упрощает управление доступом.

habr.com/ru/articles/908282/

#aws #oidc #terraform #security #iam #cicd #iac #credentials

Replay Identity Days 2024 - Déploiement des recommandations de l’ANSSI pour sécuriser OpenID Connect

peertube.nomagic.uk/videos/wat

2025-05-01

This lazy Labour Day, I changed to a bicycle in the name of multimodality

This #METRO I'm happy to report, we managed to implement single sign-on in the issue tracker. We want it to spread, but Bimba will always be available anonymously and without log-in. Bringing #OIDC to #Roundup tracker wasn't as easy as it sounds

This month, I'm taking a legally required two-week break from the $dayjob; I will either do lots more in Bimba, or spend it resting and do nothing

Claus Malter 🤘🏻+❤️+🐈cloonix@chaos.social
2025-04-26

Replaced Tiny Tiny RSS with #miniflux today. The web UI is not the best, but if you use desktop/mobile RSS readers, #miniflux is the way to go. It doesn't need much resources. Small and easy to set up. It also supports #OIDC (which ttrss does not afaik).

Felicitas Pojtinger 🌅felicitas.pojtinger.com@bsky.brid.gy
2025-04-25

Finally managed to get #OIDC post-login redirects to specific "URLs" (well, #libadwaita `NavigationView` tags, to be precise) to work. That was quite a bit more complex than I expected it to be!

Felicitas Pojtinger 🌅pojntfx
2025-04-25

Finally managed to get post-login redirects to specific "URLs" (well, `NavigationView` tags, to be precise) to work. That was quite a bit more complex than I expected it to be!

2025-04-18

Oh very neat, Forgejo 11 supports providing SSH public key via OpenID Connect authentication as well! Now just need to implement this in my OP. Is there a standardized claim name/scope for this?

#forgejo #openid #oidc #ssh

Huge 9.0 release for node-oidc-provider!

Awesome to see #DPoP enabled by default.

github.com/panva/node-oidc-pro

#OIDC #OAuth #NodeJS #AS

Anonymous 🐈️🐾☕🍵🏴🇵🇸 :af:youranonriots@kolektiva.social
2025-04-09

Poisoned pipeline execution combined with lax #OIDC federation policies can lead to privilege escalation. By not relying on broad trust relationships, organizations can strengthen their security posture. Read more: bit.ly/41Wt1D1

Jinna, Experimental Editionjinna@laalaa.land
2025-04-04

Still thinking about that time when I was attempting to help an OSS project understand why they really should implement a recommendation from a security RFC, and one of the core developers who wasn't getting the importance asked an #LLM how critical my suggestion really is to security. That time I think it answered ~"very critical", but I can't stop thinking that it was pretty much a fluke that it managed to recommend following a bit of an RFC that most humans misunderstand most of the time, and what this means longer term for "non-core" portions of software such as security. I don't think it'll be good when people stop trying to understand security and just vibe it from a slopmachine.

For the security aware, this was about public #OIDC RPs and that PKCE really isn't optional for them.

2025-03-29

### #Cloudflare open sources #OPKSSH to bring Single Sign-On #SSO to #SSH

This week, it was officially open-sourced under the umbrella of the #OpenPubkey project, itself became a #Linux Foundation open-source initiative in 2023, OPKSSH remained closed-source until now. Making it easy to #authenticate to #servers over SSH using #OpenID Connect (#OIDC), allowing developers to ditch manually configured SSH keys in favor of identity provider-based access.

helpnetsecurity.com/2025/03/28

2025-03-28

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst