hey Jason, nice work it seems. I know there is some work to be
released with v23: https://github.com/apache/cloudstack/pull/13033
be sure to have a look at that as well. I am not sure how keycloak
fits in your idea, but it might either conflict or give you some
further inspiration.

On Fri, Jul 24, 2026 at 10:10 AM Jason Ball <[email protected]> wrote:
>
> Hi all,
>
> I'd like to gauge interest in adding a generic OIDC provider to the OAuth2
> user-authenticator plugin (plugins/user-authenticators/oauth2) before I
> start on a PR.
>
> Motivation
> The plugin currently only supports Google and GitHub. There is no way to
> point ACS at a standard OIDC issuer, meaning enterprise IdPs like Microsoft
> Entra ID, Keycloak, Authentik, and Okta require bespoke Java.
>
> While the saml2 plugin exists, OIDC is the modern default, simpler to
> configure, and avoids the end-of-life OpenSAML 2.x stack.
>
> Proposal
> A single generic OIDC provider using standard discovery
> (.well-known/openid-configuration). It would validate the ID token as a JWT
> against the IdP's JWKS and match existing ACS users by email.
>
> Design Input Needed
>
>   - Generic vs. Named: I favor a single generic provider.
>   - Schema: The oauth_provider table needs an issuer/discovery URL. Should
> this be a new column/API param or a details map?
>   - Dependencies: Validating ID tokens requires a JOSE/JWT library (e.g.,
> nimbus-jose-jwt). Is adding this dependency acceptable?
>
> If there's support, I'll draft an FS and open a PR with tests.
>
> Thanks,
> Jason/resetdata
>
> --
> --
> Teach your kids Science, or somebody else will :/
>
> [email protected]
> [email protected] <[email protected]>
> callsign: vk2vjb



-- 
Daan

Reply via email to