Tag Archives: Single Sign-On

CAcert OpenID Connect resolve the security issues of logon credentials

More and more people have access to the internet. These people spend an increasing amount of time on the web. On the web are many websites on which the user has to authenticate itself; in many cases with a username and password combination. Using the same combination on every site is unwise. This is where Single Sign On (SSO) gets into the picture.

OpenID is an open standard, it is open source. OpenID is decentralized which means that authentication does not need to take place on the site that offers the service. Within OpenID there are three parties, the User, Identity Provider (IdP) and Relaying Party (RP). The IdP provides the user with an identity and an identifier. The user can provide his identifier to the RP. The RP will then redirect the user to the IdP. The user will authenticate himself to the IdP. The IdP redirects the user back to the RP. The RP then accepts that the user has identified himself. The only thing, OpenID could have, are trust problems. On this point comes CAcert into the game.

CAcert is not unlike a common CA. It does, however, use a Web of Trust to verify the identy of their users. CAcert has assurers which are users with 100 or more assurance points who have successfully taken an assurer test. The assurer can then grant the user points. Once a user has 50 or more points he is deemed assured which will unlock various options in generating certificates.

P.S. If your CMS is missing, please get in touch with our project team. It would be happy to create together with you an other CAcert OpenID Connect access that fits your needs.

CAcert OpenID Connect for Nextcloud now available

Nextcloud is free software for storing data (e.g. files, calendars, contacts, etc.) on a server. The user can access the data both via the web and with client applications. This enables a centralised and consistent database from many end devices and optional sharing with other users.

In addition to data storage, Nextcloud offers functionalities for video conferencing and various office applications via the web interface.

Using passwords is just annoying and not very secure. Now it’s much easier and even more secure: with CAcert OpenID Connect for Nextcloud, you simply log in with your certificate. Welcome to the future!

You can find out exactly how this works and how easy it is to activate in the illustrated guide for CAcert OpenID Connect for Nextcloud right here in the wiki: https://wiki.cacert.org/CAcertOpenIDConnect (no credit card, no e-mail-address, just download)

CAcert OpenID Connect for Drupal now available

OpenID Connect (OIDC) was developed by the OpenID Foundation as an authentication protocol that verifies a user’s identity when they attempt to access a protected site. CAcert now offers a way to both authenticate and authorise Drupal with OIDC. This allows users of one of the best known and most widely used open source content management systems (CMS), used by some of the largest websites such as The Economist or the White House, to be used for single sign-on (SSO) and offers the benefits of a single login for multiple sites.

This Guide will help you configure your Drupal sites and other applications as an OpenID Connect Client with CAcert. Following these steps will allow you to configure OIDC SSO which will allow your users to log in to your Drupal site using their CAcert credentials.

Get the illustrated guide for CAcert OpenID Connect for Drupal here: https://wiki.cacert.org/CAcertOpenIDConnect

If you are happy with the new functions of CAcert OpenID Connect for Drupal, done by our volunteers, please consider to donate: Donations IBAN CH02 0077 4010 3947 4420 0