Breaking
Read these before upgrading: each one can turn a login that worked into one that does not.
- auth: align provider setup and policy presets (#72) (aa0322072d4f)
- oidc: complete the asymmetric JWA verification profile (#71) (9c39ad91c5a9)
Ensure provider JWKS publishes public-only 2048–8192-bit RSA, matching NIST EC, or Ed25519 keys with compatiblealg,use, andkey_opsmetadata. - oidc: verify the OAuth web-client profile (#66) (480f6cdc336d)
Configure the identity provider to return an RFC 6750 Bearer access token and a numericexpires_inwhen present. - oidc: expand authentication method evidence (#61) (141ec4214cb4)
Re-run Test sign-in for each required authentication policy; if it fails, set Accepted authentication methods to exact provider-documented AMR values that prove the selected tier. - oidc: enforce authorization server metadata capabilities (#58) (7fb341a8f9a9)
Configure the provider to advertise PKCE S256, selectedform_post, and the selected client authentication method before upgrading.
New
- agents: preserve work and coordinate pull requests (#74) (2bd25daa71c6)
- auth: add mutual-TLS client authentication (#70) (2c00eacb3edb)
- oidc: add private-key JWT client authentication (#68) (da8010333678)
- oidc: add DPoP sender-constrained tokens (#65) (7df46de71786)
- oidc: manage shared signals stream lifecycle (#67) (4811250fdc11)
- ui: make OIDC diagnostics live and explicit (#62) (95d579d516e7)
- auth: expand actionable CAEP event coverage (#69) (9e0da694f7e6)
- oidc: add signed authorization request objects (#63) (305db0feb862)
- oidc: support signed JARM authorization responses (#64) (1b61812a897c)
- oidc: complete the OAuth security BCP profile (#60) (972ab7aac4b3)
- auth: expand actionable RISC event coverage (#59) (aadefc1d72bc)
- contribution: coordinate isolated agent work (#38) (b990588c50f3)
- oidc: add provider connectivity resilience (#34) (98a7cbab50fc)
- ui: create local accounts while binding identities (#24) (884f43419f62)
Fixed
- contribution: harden control-checkout coordination (#57) (d9e7dc63a626)
- packaging: activate bundled cron jobs (#55) (b9d32a7b9855)
- ui: normalize provider brand icons (#32) (536109815323)
Documentation
- consolidate security and provider guidance (#37) (8a2ab03a6666)
Verify and install
pkg checks nothing about a file handed to it directly. Establish its
GitHub/Sigstore provenance before the package reaches the firewall.
On an administrator workstation:
curl --fail --location --output /tmp/os-openid-connect-1.0.0.beta2.pkg \
https://github.com/jpawlowski/opnsense-openid-connect/releases/download/v1.0.0-beta2/os-openid-connect-1.0.0.beta2.pkg
gh attestation verify /tmp/os-openid-connect-1.0.0.beta2.pkg \
-R jpawlowski/opnsense-openid-connect \
--signer-workflow jpawlowski/opnsense-openid-connect/.github/workflows/build.yml \
--deny-self-hosted-runners
Copy that verified package to /tmp on the firewall. Confirm that the
transfer preserved its exact bytes, then install it:
sha256 -c 047e796b5ddf2fcb57cc10765a3623ea4e4b1f0c01b6655d74ad95a13433f91a /tmp/os-openid-connect-1.0.0.beta2.pkg
pkg add /tmp/os-openid-connect-1.0.0.beta2.pkg
No restart, no service affected. Signing in locally with a username and
password is untouched; the way back is always
pkg delete os-openid-connect.
23 commit(s) since v1.0.0-beta1.
Built from 2bd25daa71c65f1d8f268449dbb601b0611b029b.