SSO for non-cloud version of wazuh

755 views
Skip to first unread message

Robert Sitro

unread,
Jun 28, 2022, 4:47:47 PM6/28/22
to Wazuh mailing list
Hi is there  a way to integration with github or google for auth using a self-hosted version of wazuh?

Franco Giovanolli

unread,
Jun 28, 2022, 5:24:48 PM6/28/22
to Wazuh mailing list
Hello, Robert!

Thank you for using Wazuh. Wazuh Dashboards is based on the OpenSearch Dashboards project. 

This means that both environments support the configuration of different forms of authentication and authorization.

In the following documentation you can find the necessary guidelines that apply to your case.

https://github.com/wazuh/wazuh-documentation/issues/2981

https://opensearch.org/docs/latest/security-plugin/configuration/saml/
https://opensearch.org/docs/latest/security-plugin/configuration/openid-connect/

Please, let me know if this helps.


Regards,
Franco.

Valerio Vinci

unread,
Aug 27, 2022, 7:17:24 AM8/27/22
to Wazuh mailing list
Hello,

I'm trying to configure the SSO as well but in the documentation it's specified to configure the IdP in "config.yml" under "config/opensearch-security/" path.
I'm not finding these folder in my dashboard server.. 

So, where I should put the IdP configuration? Should I use the "opensearch_dashboards.yml" config file? 

I'm using a clustered environment v 4.3.1

Sandra Ocando

unread,
Sep 8, 2022, 9:25:25 AM9/8/22
to Valerio Vinci, Wazuh mailing list
Hi Valerio,

The config.yml file where you need to configure the authentication domain is located at /usr/share/wazuh-indexer/plugins/opensearch-security/securityconfig/ for the Wazuh indexer.If you are using Wazuh with Open Distro for Elasticsearch, the file is located at /usr/share/elasticsearch/plugins/opendistro_security/securityconfig/.

Let us know if you have any questions.
Best regard,
Sandra.

--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/1e753df8-a2bb-46fd-98b8-ecd14bc0e0dfn%40googlegroups.com.

Jim Nitterauer

unread,
Jan 26, 2023, 1:52:57 PM1/26/23
to Wazuh mailing list
I have modified my configuration files and restarted the services. The LDPA authentication still shows as disabled. Are there other steps that must be completed? I am sure this is buried deep in the OpenSearch docs but their documentation is pretty convoluted and not very intuitive.

Thanks for any help here.

Jim

Reply all
Reply to author
Forward
0 new messages