nextcloud / nextcloud/user_saml
ADFS with automatic support of cert rollover
Open
Nobody has claimed this yet.
enhancement
- Dominant language
- PHP
- Stars
- 104
- Forks
- 85
- Avg merge
- 1d 15h
- Merged PRs (30d)
- 16
Description
Intro
Thanks for this great app! Keep on rocking!
Steps to reproduce
- Our ADFS holds 2(primary+secondary) decryption/signing certs. Rollover works with a few of fed. apps, e.g. cisco webex. Looks like nextcloud does not support this or we did not figure out how to get this to work. The process of exchanging certs/token is explained on: https://itpro.outsidesys.com/2017/10/14/adfs-token-certificate-rollover/
Expected behaviour
Nextcloud can rollover certs/tokens if they getting close to expire
Actual behaviour
Certs does not get automatically rollovered
Info
If more information needed, pls let me know
Server configuration
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No files, tests, or code entry points are identified in the issue. Start by reviewing the linked ADFS certificate-rollover explanation and tracing the app's existing SAML certificate and token handling. Done means Nextcloud can automatically handle the primary and secondary certificates as they approach expiry.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- php
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100