Choice of Authentication

Hi,

We’re installing OpenOnDemand on a Alma9 system with Apache 2.4. The our university can authenticate with either CAS. Shibboleth, or ADFS (mod_auth_mellon). Shibboleth seems quite out of date and doesn’t seem to be supported in the Alma repositories, but has the best documentation on the OOD site. Given this, what would people recommend for a new OOD system in 2026.

One complication is that we may need to map email addresses to unix user account names.

Thanks

Hi and welcome!

I think this is a big factor. Another factor may be what your customers are already used to, given you have 3 options I’d wonder which one most users already use.

With regard to the email mapping - do any of them already return a preffered username? I.e., the IDP itself can return the unix username as the apache REMOTE_USER without having to run a mapping script or similar.

I don’t have any experience with mapping email address to account names, at least nothing more complicated than chopping off @domain.edu, but I did want to point out that ADFS can support OIDC (mod_auth_openidc) and that package is provided by Rocky 9 so I assume it should be in Alma 9. That is what we’re using and it works great for us.

I believe that I was using mod_auth_mellon with a local ActiveDirectory cluster at my last job and I found OIDC much simpler to setup. Maybe it is a different story if your AD admins don’t have experience with that though.

We decided to setup a keycloak server as the middleman between, which we have connected to our university SAML auth.

We are very happy with that solution (and it should be able to do whatever mapping you need)

We have a similar setup, but using FreeIPA as our identity backend.

We deployed Authelia in front of Open OnDemand and configured it as an OIDC provider, with Authelia authenticating users against FreeIPA via LDAP. So the flow is roughly:

Open OnDemand → OIDC → Authelia → LDAP → FreeIPA

This has been working well for us so far and lets us keep FreeIPA as the central user/account management system without requiring Open OnDemand to authenticate directly against it.