element-hq / element-hq/synapse
Kerberos SSO (GSSAPI/SPNEGO) authentication to on-prem installations of synapse
- Dominant language
- Python
- Stars
- 4.6k
- Forks
- 600
- Avg merge
- 5d 22h
- Merged PRs (30d)
- 51
Description
This issue has been migrated from [#9412](https://github.com/matrix-org/synapse/issues/9412).
---
It would be a killer feature to have real single-sign-on abilities in synapse. When deployed in an "enterprise" environment where computers are enrolled in a Kerberos realm.
I think the standards to look into is SPNEGO (since it's often used for any "kerberized" HTTP-service). Take a look at mod_auth_krb or mod_auth_gssapi for Apache for ideas.
I have coded a few things like this before (at least GSSAPI on client/server), and this way of authenticating to an on-prem installation would really be user friendly but as secure as one would like.
This way any user able to login to his/her computer on the local network, would automatically be able to sign-in to their respective matrix accounts.
Contributor guide
Assessment
This issue has not been assessed yet.