Yep which is why I use oauth2-proxy between these services and casdoor.
Comment on Why isn't using a key file the most common way to log into self-hosted servers?
HelloRoot@lemy.lol 3 days agoI think OP is talking about auth in services that you selfhost.
For example elster.de forces you to sign in by entering a username and uploading a cert file.
But mostbselfhosted services only have username/password logins.
northernlights@lemmy.today 2 days ago
Flipper@feddit.org 3 days ago
If a service doesnt offer Oidc, just dont self host it. The SSO service can then be properly secured and even if its only a password, at least its not reused.
melmi@lemmy.blahaj.zone 3 days ago
Just put everything that doesn’t have OIDC behind forward auth. OIDC is overrated for selfhosting.
Appoxo@lemmy.dbzer0.com 2 days ago
That is certificate based
jeena@piefed.jeena.net 3 days ago
That sounds like aPasskey
HelloRoot@lemy.lol 3 days ago
It does sound like one, but it isn’t.
Passkey
Certificate login
GreenCrunch@piefed.blahaj.zone 2 days ago
Thanks for the explanation!
Appoxo@lemmy.dbzer0.com 2 days ago
Nope it’s a P12 certificate