# Choice of Authentication

**URL:** <https://discourse.openondemand.org/t/choice-of-authentication/4971>\
**Category:** Get Help\
**Tags:** question\
**Created:** [September 4, 2026, 9:49am UTC](https://discourse.openondemand.org/t/choice-of-authentication/4971 "2026-09-04T09:49:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![James-Allsopp](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/james-allsopp/32/3519_2.png) [@James-Allsopp](https://discourse.openondemand.org/u/James-Allsopp)\
**Post date:** [September 4, 2026, 9:49am UTC](https://discourse.openondemand.org/t/choice-of-authentication/4971/1 "2026-09-04T09:49:56Z")

</div>

Hi,

We’re installing OpenOnDemand on a Alma9 system with Apache 2.4. The our university can authenticate with either CAS. Shibboleth, or ADFS (mod\_auth\_mellon). Shibboleth seems quite out of date and doesn’t seem to be supported in the Alma repositories, but has the best documentation on the OOD site. Given this, what would people recommend for a new OOD system in 2026.

One complication is that we may need to map email addresses to unix user account names.

Thanks

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [September 4, 2026, 12:52pm UTC](https://discourse.openondemand.org/t/choice-of-authentication/4971/2 "2026-09-04T12:52:16Z")

</div>

Hi and welcome!

> [@James-Allsopp](#):
>
> One complication is that we may need to map email addresses to unix user account names.

I think this is a big factor. Another factor may be what your customers are already used to, given you have 3 options I’d wonder which one most users already use.

With regard to the email mapping - do any of them already return a preffered username? I.e., the IDP itself can return the unix username as the apache `REMOTE_USER` without having to run a mapping script or similar.

---

<div class="post-metadata">

**Author:** ![mrobbert](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/mrobbert/32/440_2.png) [@mrobbert](https://discourse.openondemand.org/u/mrobbert)\
**Post date:** [September 9, 2026, 5:20pm UTC](https://discourse.openondemand.org/t/choice-of-authentication/4971/3 "2026-09-09T17:20:23Z")

</div>

I don’t have any experience with mapping email address to account names, at least nothing more complicated than chopping off @domain.edu, but I did want to point out that ADFS can support OIDC (mod\_auth\_openidc) and that package is provided by Rocky 9 so I assume it should be in Alma 9. That is what we’re using and it works great for us.

I believe that I was using mod\_auth\_mellon with a local ActiveDirectory cluster at my last job and I found OIDC much simpler to setup. Maybe it is a different story if your AD admins don’t have experience with that though.

---

<div class="post-metadata">

**Author:** ![Micket](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/micket/32/829_2.png) [@Micket](https://discourse.openondemand.org/u/Micket)\
**Post date:** [September 10, 2026, 2:14pm UTC](https://discourse.openondemand.org/t/choice-of-authentication/4971/4 "2026-09-10T14:14:24Z")

</div>

We decided to setup a keycloak server as the middleman between, which we have connected to our university SAML auth.

We are very happy with that solution (and it should be able to do whatever mapping you need)

---

<div class="post-metadata">

**Author:** ![PhoenixEmik](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/phoenixemik/32/3512_2.png) [@PhoenixEmik](https://discourse.openondemand.org/u/PhoenixEmik)\
**Post date:** [September 17, 2026, 7:21am UTC](https://discourse.openondemand.org/t/choice-of-authentication/4971/5 "2026-09-17T07:21:28Z")

</div>

We have a similar setup, but using FreeIPA as our identity backend.

We deployed Authelia in front of Open OnDemand and configured it as an OIDC provider, with Authelia authenticating users against FreeIPA via LDAP. So the flow is roughly:

**Open OnDemand → OIDC → Authelia → LDAP → FreeIPA**

This has been working well for us so far and lets us keep FreeIPA as the central user/account management system without requiring Open OnDemand to authenticate directly against it.
