7
LDAP (again) or SSO
Source: dani-garcia/vaultwarden#2396 · opened by @keval6b
Hi all, I'm another advocate for full LDAP support. As a preface before you immediately dismiss this, I have read all the previous PRs and discussions on the matter. While my understanding is still minimal, I've often found that a new set of eyes can spark a yet unseen path of action. Hopefully my ideas can do so but I understand that there is still a low chance of this. So from my understanding, the main issue here is that the _Master Password_ is used for encryption and decryption of the vault. Therefore, using an LDAP password for vault encryption is impossible since they can change at which point the user is no longer able to decrypt the vault. --- <details> <summary>My brain fart process</summary> There were some solutions posted in the previous discussions, one of which caught my eye: Store a generated master password as an ldap attribute on each user Now the issue with doing that is that anyone with access to the ldap server, t…
No pledges yet. Be the first to back this.
Comments
Similar requests
LDAP
1 vote · 0 comments
Change email via SSO without user interaction
2 votes · 0 comments
Default organization flow for `SSO_ONLY`
5 votes · 0 comments
Force accounts to sign in using SSO only while retaining non-SSO logins.
1 vote · 0 comments
Feature: Auto-provision new users on first SSO login (no manual admin invite required)
1 vote · 0 comments
No comments yet.