Project

General

Profile

Actions

Feature #11920

open
KP

SAML Authentication for pfSense (VPN and webConfigurator)

Feature #11920: SAML Authentication for pfSense (VPN and webConfigurator)

Added by Kris Phillips over 5 years ago. Updated 11 days ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Authentication
Target version:
-
Start date:
05/13/2021
Due date:
% Done:

0%

Estimated time:
Release Notes:
Default

Description

A customer has requested SAML authentication support for things like Azure as an alternative to LDAP and RADIUS. Please reference internal ticket number 84890 for more details.

There are some projects that exist for making the webConfigurator work with SAML for authentication. See here:
https://github.com/jaredhendrickson13/pfsense-saml2-auth

Additionally, it seems that OpenVPN has support for this as an authentication method.

VG Updated by Viktor Gurov over 5 years ago Actions #1

see also #9970

JS Updated by jeffrey Smith about 3 years ago Actions #2

Have been told in https://forum.netgate.com/topic/182512/login-security-phishing-resistant-mfa/ that this was discussed internally and there are non-trivial issues with implementing this. Any chance of adding this list to the feature request.

WF Updated by Wagner Ferreira about 2 years ago Actions #3

That would be great, I'm changing my LOCAL AD to Microsoft Entra ID and I now need to authenticate my VPN with it.

TM Updated by Tue Madsen 3 months ago Actions #4

Yes, I have customers where this would be a major score as well. Especially for IPSEC VPN two factor auth support.

DZ Updated by Danilo Zrenjanin 11 days ago Actions #5

Another request for this feature was received during a phone call to TAC.

Actions

Also available in: Atom