sinha4ravi
(Sinha4ravi)
December 10, 2021, 12:38am
1
I want to Integrate Graylog web interface to use Azure AD for SSO.
I see there is option in System > Authentication > Active Directory
But not sure how i can use as a SSO
and where i can configure oAuth setting like appid / authority/ clientid setting
Any help would really appreciated.
gsmith
(GSmith)
December 10, 2021, 1:25am
2
Hello.
I might be able to help.
This documentation would be able to help you with the connection to AD.
https://docs.graylog.org/docs/permission-management
As for SSO this Documentation should help.
https://docs.graylog.org/docs/openid-connect
The SSO you will need the Enterprise version. This would require you to get a license for your Graylog server BUT if you ingest less then 5 GB a day its free.
A LOG MANAGEMENT PLATFORM Graylog Operations is built on the Graylog platform for IT, Network, and DevOps professionals. Available in a self-managed or cloud experience, Graylog Operations offers a powerful, flexible, and seamless centralized log...
Est. reading time: 23 minutes
Hope that helps.
sinha4ravi
(Sinha4ravi)
December 10, 2021, 3:32am
3
Thanks for info.
Do we have any plugin for OAuth2.0
or
any other way to authenticate through NGINX proxy
gsmith
(GSmith)
December 10, 2021, 3:58am
4
Hello
You can look here.
Find, explore, and try out Graylog add-ons created by Graylog community members and enthusiasts. Plugins, extractors, content packs and GELF libraries are available as well as guides and documentation.
There is a Trusted Header for authentication, this is also shown in the documentation.
Here is a screen shot from the link I posted above.
sinha4ravi
(Sinha4ravi)
December 10, 2021, 4:44am
5
I went through OIDC document . Where it says to create Application in oAuth provider.
Do graylog Authentication page has also such option to configure it (steps are not quite clear in document ) or only enterprise version has such option for OIDC .
because i can only see only two option Active Directory and Ldap .
gsmith
(GSmith)
December 10, 2021, 4:54am
6
Active Directory and LDAP you don’t need enterprise version to connect only if you are trying to use Group Synchronization and/or Synchronized Teams
You can us the Trusted Header Authentication for free.
System --> Authentication --> Authenticators
If you ingest less then 5 GB a day the enterprise license is free.
You can see more here.
https://docs.graylog.org/docs/permission-management
It probably would help knowing what version you have.
sinha4ravi
(Sinha4ravi)
December 14, 2021, 2:55am
7
Thanks for response .
Is there any way I can use below library
A reverse proxy that provides authentication with Google, Azure, OpenID Connect and many more identity providers. - GitHub - oauth2-proxy/oauth2-proxy: A reverse proxy that provides authentication ...
With nginx to pass user as header
gsmith
(GSmith)
December 14, 2021, 3:03am
8
Sorry, I’m unfamiliar with application. Maybe someone else has.
system
(system)
Closed
December 28, 2021, 3:04am
9
This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.