Support certificate and federated client credentials for OIDC providers - #167
Conversation
An OIDC provider can now authenticate AuthProxy to its token endpoint with a private_key_jwt client assertion signed by a certificate (file, certificate store or Azure Key Vault), or with a federated token (workload identity token file or Azure managed identity), instead of a client secret. The credential loaders come from Microsoft.Identity.Web; ClientSecret stays the default and configuring both fails at startup.
|
Notes for reviewers (not part of the release note): Design decisions
Local gate (mirrors CI): Not exercised against a live identity provider: Key Vault download and the managed identity token (IMDS) need Azure. The certificate-file and federated-token-file paths run through the real Microsoft.Identity.Web loader in specs. This is security-sensitive and needs a cross-provider review before merge. |
|
Merged current Conflicted files and resolutions:
The fail-closed identity verification from #164, key stores from #168 and host/path routing from #169 were kept unchanged from main; the remaining branch diff contains only #167's OIDC credentials and their documentation/specs. The confirmed whitespace-only PFX-password finding was already fixed in Local checks (targeted only, as requested):
No whole-solution local gate was run. The PR's CI is the full gate; it will not be watched or waited on in this task. The release-note body was checked against the post-merge diff and updated without including changes already on main. No labels were changed and the PR was not merged. |
Added
ClientCredential.Source;ClientSecretremains the default, and conflicting or incomplete credentials prevent startup. Certificate files preserve configured PFX passwords, including whitespace-only passwords. See Client credentials for configuration, rotation and Key Vault requirements. (Support certificate and federated (managed identity) client credentials for OIDC providers #149)client_assertion. Expired certificate reloads retry at most once per minute, including unavailable replacements and loading failures. Managed identity defaults to the token-exchange audience for the authority's national cloud unless overridden. (Support certificate and federated (managed identity) client credentials for OIDC providers #149)