mirror of
https://github.com/dani-garcia/bitwarden_rs
synced 2024-11-21 17:36:41 +01:00
Page:
Testing SSO
Pages
Audits
Backing up your vault
Building binary
Building your own docker image
Caddy 2.x with Cloudflare DNS
Changing persistent data location
Changing the API request size limit
Changing the number of workers
Configuration overview
Customize Vaultwarden CSS
Deployment examples
Differences from the upstream API implementation
Disable admin token
Disable invitations
Disable registration of new users
Disabling or overriding the Vault interface hosting
Docker Traefik ModSecurity Setup
Enable admin page
Enabling HTTPS
Enabling Mobile Client push notification
Enabling U2F (and FIDO2 WebAuthn) authentication
Enabling U2F authentication
Enabling WebSocket notifications
Enabling Yubikey OTP authentication
Enabling admin page secure the admin_token
Enabling admin page
FAQs
Fail2Ban Setup
General (not docker)
Hardening Guide
Home
Importing data from Keepass or KeepassX
Kubernetes deployment
Logging
Logrotate example
Migrating from MariaDB (MySQL) to SQLite
Other configuration
Password hint display
Pre built binaries
Private CA and self signed certs that work with Chrome
Proxy examples
Running a private vaultwarden instance with Let's Encrypt certs
Running docker container with non root user
Running without WAL enabled
SMTP Configuration
Setup as a systemd service
Starting a Container
Supporting upstream
Syncing users from LDAP
Testing SSO
Third party packages
Translating the email templates
Updating the vaultwarden image
Using Docker Compose
Using Podman
Using an alternate base dir
Using the MariaDB (MySQL) Backend
Using the MySQL Backend
Using the PostgreSQL Backend
Which container image to use
4
Testing SSO
docgalaxyblock edited this page 2024-03-10 21:09:32 +01:00
Table of Contents
Development setup to test SSO
SSO support for Vaultwarden is currently in development. The following describes a docker-compose based setup for locally testing these changes.
Warning
ONLY USE FOR TESTING SSO, SETUP IS INSECURE
Setup
- Checkout the SSO branch
- Create
docker-compose.yml
with the following contents:
services:
vaultwarden:
build: .
environment:
DOMAIN: "http://localhost:8000"
I_REALLY_WANT_VOLATILE_STORAGE: "true"
SSO_ENABLED: "true"
SSO_CLIENT_ID: "client"
SSO_CLIENT_SECRET: "clientsecret"
SSO_AUTHORITY: "http://auth.test:8080/mock"
ports:
- 127.0.0.1:8000:80
mock-oauth2:
image: ghcr.io/navikt/mock-oauth2-server:0.5.10
hostname: "auth.test"
ports:
- 127.0.0.1:8080:8080
- Add
auth.test
to your systems host file:echo "127.0.0.1 auth.test" | sudo tee -a /etc/hosts
- Build vaultwarden:
docker compose build
Testing
- Start the services:
docker compose up
- Go to http://localhost:8000/#/sso, enter any string as identifier, click "Log in".
- On the Mock Auth2 Server Sign-in-Page, enter any string for user/subject and add the email you want to test in the claims field like so:
{"email": "user@example.com"}
- If everything went according to plan, you will be asked for a master password.
FAQs
Container Image Usage
- Which container image to use
- Starting a container
- Updating the vaultwarden image
- Using Docker Compose
- Using Podman
Deployment
- Building your own docker image
- Building binary
- Pre-built binaries
- Third-party packages
- Deployment examples
- Proxy examples
- Logrotate example
HTTPS
Configuration
- Overview
- Disable registration of new users
- Disable invitations
- Enabling admin page
- Disable the admin token
- Enabling WebSocket notifications
- Enabling Mobile Client push notification
- Enabling U2F and FIDO2 WebAuthn authentication
- Enabling YubiKey OTP authentication
- Changing persistent data location
- Changing the API request size limit
- Changing the number of workers
- SMTP configuration
- Translating the email templates
- Password hint display
- Disabling or overriding the Vault interface hosting
- Logging
- Creating a systemd service
- Syncing users from LDAP
- Using an alternate base dir (subdir/subpath)
- Other configuration
Database
- Using the MariaDB (MySQL) Backend
- Using the PostgreSQL Backend
- Running without WAL enabled
- Migrating from MariaDB (MySQL) to SQLite