Graylog2 / Graylog2/graylog2-server

OIDC should use eppn instead of login name for OIDC

Open
#19,633 0 comments 0 reactions 0 assignees View on GitHub
feature triaged
Dominant language
Java
Stars
8.1k
Forks
1.1k
Avg merge
1d 20h
Merged PRs (30d)
217

Description

### What?
Customer would like to use EPPN (eduPersonPrincipalName) instead of login name for OIDC.

From Support issue: https://github.com/Graylog2/support/issues/58

### Why?
They use multi-organisational schema so primary identifier should be user@realm.
Now when they log in as user@cesnet.cz, account name is 'user'.
This is a problem because there could be more logins 'user' for different organisations.
They need to have the username non-stripped so they can fully utilise multi-tenant setup.
- Strip Realm from UserID: Strips all data starting with the delimiter character from the user ID. This allows a submitted user ID, such as an email address (UserID@abc.com), to be authenticated as the UserID which is happening now.
They have used trusted header authentication with apache and shibboleth before.

### Customer Environment
Graylog Version: 6.0.3

(created from Zendesk ticket #600)
gz#600

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.