-
-
Notifications
You must be signed in to change notification settings - Fork 176
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
check-mk saml auth with entra-id as idp #1048
Comments
Hi @Hstrohi, |
Thank you for your quick response @HenriWahl ! Unfortunately we have not the coding skills to support you with code snippets, but if there is anything else we can do to support the development (like testing, provide logs, etc.) please let us know. |
@Hstrohi this is really going to be interesting. |
Hello @HenriWahl, any hope for nagstamon to support Entra ID for Icinga? |
@HenriWahl just wanted to get back to you with an actual status. After weeks of waiting for feedback from our check-mk partner, the outcome is very poor. We were told that they discussed the problem with tribe29(check-mk creator) and the feedback ist that they see this one not as an urgent topic. Not very satisfying for all of us. Seems that we have a showstopper here and I really do not have a clue what step would be next. Any ideas? |
@Hstrohi this is bad news. Right now I did not find the time yet to look further. I plan to check this in autumn before our setup also moves to single-sign-on. |
@realasmo honestly the situation is even worse than with Checkmk because I neither have access to EntraID nor Icinga, so I can't tell. Maybe someone else finds a solution? |
Maybe #953 can help here but I was not able yet to fully check this. |
The easiest solution would be that Checkmk allows several ways of login in parallel. |
We are preparing the update from check_mk 2.2 to 2.3.
https://docs.checkmk.com/latest/en/update_major.html
One of the preparation steps is to get rid of the authentication with the apache mod_auth_mellon module and switch the built-in SAML authentication from check-mk. With version 2.3.0 mod_auth_mellon` is no longer delivered with the check-mk software. So this one is a must.
https://docs.checkmk.com/latest/en/saml.html#saml_cee
After setting that up like documented with entra-id as IdP the authentication works like a charme in the web frontend, but is not working anymore with nagstamon.
When accessing the web-ui there now is an extra button above the username/password fields which allows to chose "login with entra-id".
Any ideas on this one, is this something, that we have to address to the check-mk support, because the check_mk/login.py does not support this one already for the automated nagstamon calls? Or is that something that has to be added in the nagstamon framework?
Really appreciate your reply, because nagstamon is for us so important, that we paused our update plans and check-mk version 2.2 is running out of support in October.
The text was updated successfully, but these errors were encountered: