How to use single-sign on

I am new to Yunohost, and find myself quite confused about single sign-on. Having now tried several different applications, I find that for each, login requires credentials being entered into a login page generated by the application, and also that the credentials accepted are those managed by the application. Separate login to the portal is also required.

An issue report that I previously created explains the details of my overall confusion.

Although the report was intended to prompt discussion over the behavior that would be desired, I am also trying to learn the actual behavior, from the current design, of single sign-on in Yunohost.

One of my observations was that the characterization as single sign-on may be referring to behavior that is more correctly described as same sign-on. However, I have still not observed even any functionality for same sign-on.

I am hoping someone could explain how to use single sign-on in Yunohost.

To explain it simply :

  • every user has an account on yunohost is managed by ldap, so when you login to the portal you use your credentials
  • some apps support only ldap, so you have to login in the app using your yunohost credentials regardless you are logged in to the portal or not, these apps have their own login mechanism but will use ldap as authentication backend
  • some apps support sso, these apps get the username passed via http header. So when you login to the portal, you are automatically logged in to the app
  • some apps do not support neither, so they will rely on their own authentication

You can check if the app supports ldap or sso or both or none if you expand the section “yunohost integration” in the webadmin (at the bottom of the app details page). You can also dive into the package of each app and check the manifest

Would be good if the app-catalog could filter for SSO/LDAP.

Thank you for the clear explanation.

Unfortunately, I have already tried several applications that are reported to support for SSO, but in each case, the application generates a login screen, regardless of the portal login, and also fails to accept the credentials accepted by Yunohost.

In one case, I submitted a report to the package maintainer, but I am still waiting for a response.

Adding to the confusion, the language appearing in the application details is “Single sign-on is available (SSO)”. The phrasing implies that additional action may be required in order to use SSO, even though no instructions are provided. If SSO will function without any additional configuration, then some different phrasing would be more helpful.

Do you remember which application(s) it was?

I have tried Vaultwarden and Roundcube.

I have also tried SnappyMail, but it may have a more fundamental problem. Trying to open the administrative interface results in an error message being displayed in the browser.

I submitted a report for Vaultwarden.

Well… afaik, vaultwarden cannot work with yunohost sso : it’s meant to be used with an OIDC provider -dex, keycloak…- (indeed “sso = true” should ne changed to “sso = false” in the manifest).

SSO works without tweaking with snappymail if the app is installed on the main domain. If it is installed on a subdomain, adding

secfetch_allow = "dest=document,mode=navigate,site=same-site"

to the

/var/www/snappymail/app/data/_data_/_default_/configs/application.ini

should fix the issue with SSO. See here.

With roundcube, do you remember what was the issue ?

It is quite a shame that OIDC is not yet included in Yunohost.

Would it be inadvisable to connect the installed instance of Vaultwarden to an already existing OIDC provider?

I really wish requirements of such kind were documented, if not automated.

When the login page of Roundcube is first loaded, a message is shown, “Login failed.” At this stage, no credentials have actually been submitted. The message appears in this way simply from navigating to the base path of the application, with no additional path components or any query parameters, from a fresh browser window. A login session for the portal has already been established. Otherwise, it will be prompted.

Upon submission of the credentials that are the same as those accepted by Yunohost, the login page simply reloads, and again flashes the same message, “Login failed.”

You can use dex.

Yes, that is indeed strange because SSO does work with this app. Is it a fresh install ?

See here :

Hope this helps.

I was considering using an existing, external provider.

Am I understanding correctly, that Dex would function as an intermediary, by providing OIDC authentication against the users and credentials managed by Yunohost?

Yes.

Yes, that’s also possible.

Yes, dex will use yunohost ldap.

I guess you already have tried to force the upgrade or uninstall-reinstall ?

Yes. I have tried both, but the same problem still persists.

I have created a new thread to discuss the login failures in Roundcube.