I am new to Yunohost, and find myself quite confused about single sign-on. Having now tried several different applications, I find that for each, login requires credentials being entered into a login page generated by the application, and also that the credentials accepted are those managed by the application. Separate login to the portal is also required.
An issue report that I previously created explains the details of my overall confusion.
Although the report was intended to prompt discussion over the behavior that would be desired, I am also trying to learn the actual behavior, from the current design, of single sign-on in Yunohost.
One of my observations was that the characterization as single sign-on may be referring to behavior that is more correctly described as same sign-on. However, I have still not observed even any functionality for same sign-on.
I am hoping someone could explain how to use single sign-on in Yunohost.
every user has an account on yunohost is managed by ldap, so when you login to the portal you use your credentials
some apps support only ldap, so you have to login in the app using your yunohost credentials regardless you are logged in to the portal or not, these apps have their own login mechanism but will use ldap as authentication backend
some apps support sso, these apps get the username passed via http header. So when you login to the portal, you are automatically logged in to the app
some apps do not support neither, so they will rely on their own authentication
You can check if the app supports ldap or sso or both or none if you expand the section “yunohost integration” in the webadmin (at the bottom of the app details page). You can also dive into the package of each app and check the manifest
Unfortunately, I have already tried several applications that are reported to support for SSO, but in each case, the application generates a login screen, regardless of the portal login, and also fails to accept the credentials accepted by Yunohost.
In one case, I submitted a report to the package maintainer, but I am still waiting for a response.
Adding to the confusion, the language appearing in the application details is “Single sign-on is available (SSO)”. The phrasing implies that additional action may be required in order to use SSO, even though no instructions are provided. If SSO will function without any additional configuration, then some different phrasing would be more helpful.
I have also tried SnappyMail, but it may have a more fundamental problem. Trying to open the administrative interface results in an error message being displayed in the browser.
Well… afaik, vaultwarden cannot work with yunohost sso : it’s meant to be used with an OIDC provider -dex, keycloak…- (indeed “sso = true” should ne changed to “sso = false” in the manifest).
SSO works without tweaking with snappymail if the app is installed on the main domain. If it is installed on a subdomain, adding
It is quite a shame that OIDC is not yet included in Yunohost.
Would it be inadvisable to connect the installed instance of Vaultwarden to an already existing OIDC provider?
I really wish requirements of such kind were documented, if not automated.
When the login page of Roundcube is first loaded, a message is shown, “Login failed.” At this stage, no credentials have actually been submitted. The message appears in this way simply from navigating to the base path of the application, with no additional path components or any query parameters, from a fresh browser window. A login session for the portal has already been established. Otherwise, it will be prompted.
Upon submission of the credentials that are the same as those accepted by Yunohost, the login page simply reloads, and again flashes the same message, “Login failed.”
I was considering using an existing, external provider.
Am I understanding correctly, that Dex would function as an intermediary, by providing OIDC authentication against the users and credentials managed by Yunohost?