Feature Request – Certificate-Based Authentication for External IdP (Microsoft Entra ID)
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 18/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- azure, rust
- Domain
- authentication
Research direction
The issue names no files or tests. Start by finding where the External OIDC provider's Client ID and Client Secret are configured and used, then check whether the OIDC client already supports private_key_jwt. Done means a maintainer-agreed design for certificate storage, Entra ID configuration and rotation, not a patch, since the issue is open with no comments yet.
Written by the indexing model from the issue text.
Description
Hello Defguard Support Team,
We would like to request a feature enhancement to support certificate-based authentication for External Identity Providers (IdP), specifically Microsoft Entra ID.
Currently, Defguard's External OpenID Connect (OIDC) integration requires a Client ID and Client Secret for authentication. We would like to have the option to use an X.509 certificate instead of a Client Secret to improve security and credential management.
Requested Feature:
- Support certificate-based client authentication using the OIDC private_key_jwt authentication method.
- Allow administrators to configure an X.509 certificate and associated private key securely in Defguard.
- Support Microsoft Entra ID App Registration authentication using certificate credentials.
- Support certificate renewal and rotation without interrupting existing SSO authentication.
- Maintain backward compatibility with the existing Client Secret authentication method.
Business and Security Benefits:
- Reduce reliance on shared Client Secrets.
- Improve credential security and lifecycle management.
- Support organizational security policies that prefer certificate-based application authentication.
- Reduce operational risks associated with Client Secret expiration and rotation.
Questions:
- Does Defguard currently support certificate-based authentication for External OIDC providers through any existing configuration?
- If not, could this capability be considered for a future release?
- Is there an existing feature request or roadmap item for this functionality?
- We would appreciate your feedback on the feasibility of implementing this feature.
Thank you for your support.
- Dominant language
- Rust
- Stars
- 2.9k
- Forks
- 119
- Avg merge
- 1d 2h
- Merged PRs (30d)
- 61
Getting set up
- Ships a Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from DefGuard/defguard
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
Maintainers usually reply within 1 day
-
bug
Difficulty 1/5 Under an hour Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day
All issues in DefGuard/defguard
Similar issues
-
C-bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
rust-lang/rust-analyzer#23501 ·
Maintainers usually reply within 1 day
-
Streamable HTTP client: a 401 or 403 with a JSON-RPC error body and no WWW-Authenticate loses its HTTP statusPossibly taken A pull request linked to this issue is open or already merged. Openbug P2 ready for work T-security T-transport
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
modelcontextprotocol/rust-sdk#1339 ·
Maintainers usually reply within 3 days
-
scripts/gen-gallery.py:118: a ready session now reports in_progress, so SESSION_READY_OLD can goOpennightly-audit
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
antithesishq/snouty#396 ·
Maintainers usually reply within 1 day
-
French BIP39 wordlist starts with a UTF-8 BOM, so generated French mnemonics carry U+FEFF and derive a non-canonical seedPossibly taken @Kshot3000 claimed this today. Open
Difficulty 1/5 Under an hour Newbie friendliness 91/100
ergoplatform/sigma-rust#976 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
Maintainers usually reply within 1 day