nextcloud / nextcloud/user_saml

ADFS with automatic support of cert rollover

Open
#699 0 comments 3 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement
Dominant language
PHP
Stars
104
Forks
85
Avg merge
1d 15h
Merged PRs (30d)
16

Description

Intro

Thanks for this great app! Keep on rocking!

Steps to reproduce
  1. Our ADFS holds 2(primary+secondary) decryption/signing certs. Rollover works with a few of fed. apps, e.g. cisco webex. Looks like nextcloud does not support this or we did not figure out how to get this to work. The process of exchanging certs/token is explained on: https://itpro.outsidesys.com/2017/10/14/adfs-token-certificate-rollover/
Expected behaviour

Nextcloud can rollover certs/tokens if they getting close to expire

Actual behaviour

Certs does not get automatically rollovered

Info

If more information needed, pls let me know

Server configuration

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files, tests, or code entry points are identified in the issue. Start by reviewing the linked ADFS certificate-rollover explanation and tracing the app's existing SAML certificate and token handling. Done means Nextcloud can automatically handle the primary and secondary certificates as they approach expiry.

Written by the indexing model from the issue text.

Assessment

Tech stack
php
Domain
authentication, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.