mirror of
https://github.com/netbox-community/netbox.git
synced 2026-01-11 21:10:29 +01:00
No Branch/Tag Specified
main
update-changelog-comments-docs
feature-removal-issue-type
20911-dropdown
20239-plugin-menu-classes-mutable-state
21097-graphql-id-lookups
feature
fix_module_substitution
20923-dcim-templates
20044-elevation-stuck-lightmode
feature-ip-prefix-link
v4.5-beta1-release
20068-import-moduletype-attrs
20766-fix-german-translation-code-literals
20378-del-script
7604-filter-modifiers-v3
circuit-swap
12318-case-insensitive-uniqueness
20637-improve-device-q-filter
20660-script-load
19724-graphql
20614-update-ruff
14884-script
02496-max-page
19720-macaddress-interface-generic-relation
19408-circuit-terminations-export-templates
20203-openapi-check
fix-19669-api-image-download
7604-filter-modifiers
19275-fixes-interface-bulk-edit
fix-17794-get_field_value_return_list
11507-show-aggregate-and-rir-on-api
9583-add_column_specific_search_field_to_tables
v4.5.0
v4.4.10
v4.4.9
v4.5.0-beta1
v4.4.8
v4.4.7
v4.4.6
v4.4.5
v4.4.4
v4.4.3
v4.4.2
v4.4.1
v4.4.0
v4.3.7
v4.4.0-beta1
v4.3.6
v4.3.5
v4.3.4
v4.3.3
v4.3.2
v4.3.1
v4.3.0
v4.2.9
v4.3.0-beta2
v4.2.8
v4.3.0-beta1
v4.2.7
v4.2.6
v4.2.5
v4.2.4
v4.2.3
v4.2.2
v4.2.1
v4.2.0
v4.1.11
v4.1.10
v4.1.9
v4.1.8
v4.2-beta1
v4.1.7
v4.1.6
v4.1.5
v4.1.4
v4.1.3
v4.1.2
v4.1.1
v4.1.0
v4.0.11
v4.0.10
v4.0.9
v4.1-beta1
v4.0.8
v4.0.7
v4.0.6
v4.0.5
v4.0.3
v4.0.2
v4.0.1
v4.0.0
v3.7.8
v3.7.7
v4.0-beta2
v3.7.6
v3.7.5
v4.0-beta1
v3.7.4
v3.7.3
v3.7.2
v3.7.1
v3.7.0
v3.6.9
v3.6.8
v3.6.7
v3.7-beta1
v3.6.6
v3.6.5
v3.6.4
v3.6.3
v3.6.2
v3.6.1
v3.6.0
v3.5.9
v3.6-beta2
v3.5.8
v3.6-beta1
v3.5.7
v3.5.6
v3.5.5
v3.5.4
v3.5.3
v3.5.2
v3.5.1
v3.5.0
v3.4.10
v3.4.9
v3.5-beta2
v3.4.8
v3.5-beta1
v3.4.7
v3.4.6
v3.4.5
v3.4.4
v3.4.3
v3.4.2
v3.4.1
v3.4.0
v3.3.10
v3.3.9
v3.4-beta1
v3.3.8
v3.3.7
v3.3.6
v3.3.5
v3.3.4
v3.3.3
v3.3.2
v3.3.1
v3.3.0
v3.2.9
v3.2.8
v3.3-beta2
v3.2.7
v3.3-beta1
v3.2.6
v3.2.5
v3.2.4
v3.2.3
v3.2.2
v3.2.1
v3.2.0
v3.1.11
v3.1.10
v3.2-beta2
v3.1.9
v3.2-beta1
v3.1.8
v3.1.7
v3.1.6
v3.1.5
v3.1.4
v3.1.3
v3.1.2
v3.1.1
v3.1.0
v3.0.12
v3.0.11
v3.0.10
v3.1-beta1
v3.0.9
v3.0.8
v3.0.7
v3.0.6
v3.0.5
v3.0.4
v3.0.3
v3.0.2
v3.0.1
v3.0.0
v2.11.12
v3.0-beta2
v2.11.11
v2.11.10
v3.0-beta1
v2.11.9
v2.11.8
v2.11.7
v2.11.6
v2.11.5
v2.11.4
v2.11.3
v2.11.2
v2.11.1
v2.11.0
v2.10.10
v2.10.9
v2.11-beta1
v2.10.8
v2.10.7
v2.10.6
v2.10.5
v2.10.4
v2.10.3
v2.10.2
v2.10.1
v2.10.0
v2.9.11
v2.10-beta2
v2.9.10
v2.10-beta1
v2.9.9
v2.9.8
v2.9.7
v2.9.6
v2.9.5
v2.9.4
v2.9.3
v2.9.2
v2.9.1
v2.9.0
v2.9-beta2
v2.8.9
v2.9-beta1
v2.8.8
v2.8.7
v2.8.6
v2.8.5
v2.8.4
v2.8.3
v2.8.2
v2.8.1
v2.8.0
v2.7.12
v2.7.11
v2.7.10
v2.7.9
v2.7.8
v2.7.7
v2.7.6
v2.7.5
v2.7.4
v2.7.3
v2.7.2
v2.7.1
v2.7.0
v2.6.12
v2.6.11
v2.6.10
v2.6.9
v2.7-beta1
Solcon-2020-01-06
v2.6.8
v2.6.7
v2.6.6
v2.6.5
v2.6.4
v2.6.3
v2.6.2
v2.6.1
v2.6.0
v2.5.13
v2.5.12
v2.6-beta1
v2.5.11
v2.5.10
v2.5.9
v2.5.8
v2.5.7
v2.5.6
v2.5.5
v2.5.4
v2.5.3
v2.5.2
v2.5.1
v2.5.0
v2.4.9
v2.5-beta2
v2.4.8
v2.5-beta1
v2.4.7
v2.4.6
v2.4.5
v2.4.4
v2.4.3
v2.4.2
v2.4.1
v2.4.0
v2.3.7
v2.4-beta1
v2.3.6
v2.3.5
v2.3.4
v2.3.3
v2.3.2
v2.3.1
v2.3.0
v2.2.10
v2.3-beta2
v2.2.9
v2.3-beta1
v2.2.8
v2.2.7
v2.2.6
v2.2.5
v2.2.4
v2.2.3
v2.2.2
v2.2.1
v2.2.0
v2.1.6
v2.2-beta2
v2.1.5
v2.2-beta1
v2.1.4
v2.1.3
v2.1.2
v2.1.1
v2.1.0
v2.0.10
v2.1-beta1
v2.0.9
v2.0.8
v2.0.7
v2.0.6
v2.0.5
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v2.0.0
v2.0-beta3
v1.9.6
v1.9.5
v2.0-beta2
v1.9.4-r1
v1.9.3
v2.0-beta1
v1.9.2
v1.9.1
v1.9.0-r1
v1.8.4
v1.8.3
v1.8.2
v1.8.1
v1.8.0
v1.7.3
v1.7.2-r1
v1.7.1
v1.7.0
v1.6.3
v1.6.2-r1
v1.6.1-r1
1.6.1
v1.6.0
v1.5.2
v1.5.1
v1.5.0
v1.4.2
v1.4.1
v1.4.0
v1.3.2
v1.3.1
v1.3.0
v1.2.2
v1.2.1
v1.2.0
v1.1.0
v1.0.7-r1
v1.0.7
v1.0.6
v1.0.5
v1.0.4
v1.0.3-r1
v1.0.3
1.0.0
Labels
Clear labels
beta
breaking change
complexity: high
complexity: low
complexity: medium
needs milestone
netbox
pending closure
plugin candidate
pull-request
severity: high
severity: low
severity: medium
status: accepted
status: backlog
status: blocked
status: duplicate
status: needs owner
status: needs triage
status: revisions needed
status: under review
topic: GraphQL
topic: Internationalization
topic: OpenAPI
topic: UI/UX
topic: cabling
topic: event rules
topic: htmx navigation
topic: industrialization
topic: migrations
topic: plugins
topic: scripts
topic: templating
topic: testing
type: bug
type: deprecation
type: documentation
type: feature
type: housekeeping
type: translation
Mirrored from GitHub Pull Request
No Label
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/netbox#1373
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @lampwins on GitHub (Nov 1, 2017).
Issue type
[ x ] Feature request
[ ] Bug report
[ ] Documentation
Description
My employer is currently going through a large push to use SAML for application authentication. As such, I would like to implement SAML for netbox. I have several django projects similar to (and sometimes based on the core of) netbox which I am currently working on SAML integration, so it would be rather trivial to contribute it back.
This was first brought up in #118 but I also agree with the decision to close that issue for being too broad and under defined. This request covers only the addition of SAML support for authentication and no other use case.
Let me be clear in saying this is something I am 100% willing to do the work on myself.
I see it looking very similar to the LDAP support, in that it is a bolt on that a user must enable themselves. This would most likely be using djangosaml2
@Eric2XU commented on GitHub (Nov 1, 2017):
I too need this feature to use with Azure SAML. I also am willing to pitch in (although most of this is above my head). I am willing to help be a tester and perhaps contribute where I can. Please keep me in the loop.
SAML is preferred but like I said a little over my head. My other thought was to get Kerberos SSO working on Apache then figure out a way to get Netbox to use the authenticated user object created by Apache although that is where I would have a hard time figuring out where in the code base to change (while I know other languages py isn't one I know so I would be winging it). https://active-directory-wp.com/docs/Networking/Single_Sign_On/Kerberos_SSO_with_Apache_on_Linux.html Since I use Azure, I can route traffic through the Azure proxy which will automatically pass the kerberos creds to Apache
@explody commented on GitHub (Nov 4, 2017):
Check this out. https://github.com/explody/netbox/blob/basic_saml_support/README_SAML.md
It may need some additional tweaking before submitting a PR but it's working for us currently.
@lampwins commented on GitHub (Dec 14, 2017):
@explody are you okay with me working on that a bit?
@explody commented on GitHub (Dec 14, 2017):
Certainly. It's entirely functional for us, but we also sort of threw the structure of it together - naming and location of vars and configs, etc. I was thinking it could use some tidying up before a PR, just haven't gotten back to it yet.
Commits are here in case it wasn't immediately obvious: https://github.com/explody/netbox/commits/basic_saml_support
@rhysjtevans commented on GitHub (Jan 10, 2018):
Hi @explody, great work! Quick question how do you differentiate users to different groups?
I'd be interested in mapping an Active Directory group membership to a netbox group via SAML
@girlpunk commented on GitHub (Feb 6, 2018):
@explody Just tried that on my install, I think the documentation needs a little tweaking, but overall it works well. I'd agree with @rhysjtevans as well, would be nice if AD groups could set edit permissions.
@explody commented on GitHub (Feb 28, 2018):
We need group support as well, and are intending to get to it as soon as possible (can't say when though).
re:Docs, let me know what needs tweaking, I'm happy to include improvements.
@pcabido commented on GitHub (Mar 6, 2018):
@explody great work on this. I've done something similar with django_saml2_auth and Okta, wasn't too hard but I like what you did here, it's a lot more complete then my hack. I encourage you to make the PR and commit upstream. SAML support is only more common now a days and I believe a lot of users would benefit from your work.
I'd also suggest using or documenting how to use the metadata auto config url, Okta for example supports that and it makes things easier.
@01000101 commented on GitHub (Mar 13, 2018):
+1 for adding group support. Our organization just set this up with SAML but can't find a way to pass in group information.
@LukeDRussell commented on GitHub (May 22, 2018):
@jeremystretch You've labelled this as accepted. Does that mean @lampwins has the OK to submit a PR (assuming he is still keen)?
@DouglasHeriot commented on GitHub (Feb 21, 2019):
This is a feature we need to, to use with Okta. We’re about to start working on this as it’s been marked as accepting pull requests – does that sound good, or should we go for the #2328 option instead and put our work there?
@anthonyeden commented on GitHub (Mar 15, 2019):
Hi all,
Just letting you know I've begun work on SAML2 Authentication for NetBox. You can see my draft pull request here: https://github.com/digitalocean/netbox/pull/3010
There's still more work to be done, but I'd appreciate any feedback on my approach thus far.
@jeremystretch commented on GitHub (Oct 15, 2019):
Given the prevalence of issues following the introduction of LDAP authentication support and the overall burden of maintaining multiple remote authentication mechanisms, the maintainers have decided to pursue instead support for generic remote authentication handled by the HTTP frontend (see #2328). This will greatly simplify the logic needed by NetBox, as well as offer the most flexibility to the end user around what mechanisms are supported and how they can be configured.