Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Feature Request – Certificate-Based Authentication for External IdP (Microsoft Entra ID)

Open
#3,839 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
18/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Active
Tech stack
azure, rust

Research direction

The issue names no files or tests. Start by finding where the External OIDC provider's Client ID and Client Secret are configured and used, then check whether the OIDC client already supports private_key_jwt. Done means a maintainer-agreed design for certificate storage, Entra ID configuration and rotation, not a patch, since the issue is open with no comments yet.

Written by the indexing model from the issue text.

Description

Hello Defguard Support Team,

We would like to request a feature enhancement to support certificate-based authentication for External Identity Providers (IdP), specifically Microsoft Entra ID.

Currently, Defguard's External OpenID Connect (OIDC) integration requires a Client ID and Client Secret for authentication. We would like to have the option to use an X.509 certificate instead of a Client Secret to improve security and credential management.

Requested Feature:

  • Support certificate-based client authentication using the OIDC private_key_jwt authentication method.
  • Allow administrators to configure an X.509 certificate and associated private key securely in Defguard.
  • Support Microsoft Entra ID App Registration authentication using certificate credentials.
  • Support certificate renewal and rotation without interrupting existing SSO authentication.
  • Maintain backward compatibility with the existing Client Secret authentication method.

Business and Security Benefits:

  • Reduce reliance on shared Client Secrets.
  • Improve credential security and lifecycle management.
  • Support organizational security policies that prefer certificate-based application authentication.
  • Reduce operational risks associated with Client Secret expiration and rotation.

Questions:

  1. Does Defguard currently support certificate-based authentication for External OIDC providers through any existing configuration?
  2. If not, could this capability be considered for a future release?
  3. Is there an existing feature request or roadmap item for this functionality?
  4. We would appreciate your feedback on the feasibility of implementing this feature.

Thank you for your support.

Dominant language
Rust
Stars
2.9k
Forks
119
Avg merge
1d 2h
Merged PRs (30d)
61

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from DefGuard/defguard

All issues in DefGuard/defguard

Similar issues

More Rust issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.