github jpawlowski/opnsense-openid-connect v1.0.0-beta2

latest releases: v1.0.0-beta5, v1.0.0-beta4, v1.0.0-beta3...
pre-releaseone month ago

Breaking

Read these before upgrading: each one can turn a login that worked into one that does not.

  • auth: align provider setup and policy presets (#72) (aa0322072d4f)
  • oidc: complete the asymmetric JWA verification profile (#71) (9c39ad91c5a9)

    Ensure provider JWKS publishes public-only 2048–8192-bit RSA, matching NIST EC, or Ed25519 keys with compatible alg, use, and key_ops metadata.
  • oidc: verify the OAuth web-client profile (#66) (480f6cdc336d)

    Configure the identity provider to return an RFC 6750 Bearer access token and a numeric expires_in when present.
  • oidc: expand authentication method evidence (#61) (141ec4214cb4)

    Re-run Test sign-in for each required authentication policy; if it fails, set Accepted authentication methods to exact provider-documented AMR values that prove the selected tier.
  • oidc: enforce authorization server metadata capabilities (#58) (7fb341a8f9a9)

    Configure the provider to advertise PKCE S256, selected form_post, and the selected client authentication method before upgrading.

New

Fixed

Documentation

Verify and install

pkg checks nothing about a file handed to it directly. Establish its
GitHub/Sigstore provenance before the package reaches the firewall.

On an administrator workstation:

curl --fail --location --output /tmp/os-openid-connect-1.0.0.beta2.pkg \
  https://github.com/jpawlowski/opnsense-openid-connect/releases/download/v1.0.0-beta2/os-openid-connect-1.0.0.beta2.pkg
gh attestation verify /tmp/os-openid-connect-1.0.0.beta2.pkg \
  -R jpawlowski/opnsense-openid-connect \
  --signer-workflow jpawlowski/opnsense-openid-connect/.github/workflows/build.yml \
  --deny-self-hosted-runners

Copy that verified package to /tmp on the firewall. Confirm that the
transfer preserved its exact bytes, then install it:

sha256 -c 047e796b5ddf2fcb57cc10765a3623ea4e4b1f0c01b6655d74ad95a13433f91a /tmp/os-openid-connect-1.0.0.beta2.pkg

pkg add /tmp/os-openid-connect-1.0.0.beta2.pkg

No restart, no service affected. Signing in locally with a username and
password is untouched; the way back is always
pkg delete os-openid-connect.

23 commit(s) since v1.0.0-beta1.
Built from 2bd25daa71c65f1d8f268449dbb601b0611b029b.

Don't miss a new opnsense-openid-connect release

NewReleases is sending notifications on new releases.