Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

SAML config for zabbix > 6.2 #1358

Open
Daniigrof opened this issue Aug 4, 2024 · 2 comments
Open

SAML config for zabbix > 6.2 #1358

Daniigrof opened this issue Aug 4, 2024 · 2 comments

Comments

@Daniigrof
Copy link

SUMMARY

Enable configuration of LDAP and SAML for Zabbix versions greater than 6.2. Currently, there appears to be no support for these features in versions beyond 6.2.

ISSUE TYPE
Feature Request

LDAP and SAML Configuration for Zabbix > 6.2

ADDITIONAL INFORMATION

The ability to configure LDAP and SAML is crucial for automating deployments and is a significant aspect of many IT and system administration tasks. Enhanced support for these features in newer versions of Zabbix will greatly benefit users by simplifying the setup process and improving overall security and integration capabilities.

@Daniigrof Daniigrof changed the title SAML config for zabbix 6.2+ SAML config for zabbix > 6.2 Aug 4, 2024
@masa-orca
Copy link
Collaborator

masa-orca commented Aug 4, 2024

You can configure LDAP setting and SAML setting using zabbix_user_directory module.

The Zabbix API's behavior has changed since version 6.2.

@tjommie
Copy link

tjommie commented Aug 20, 2024

I've tried both modules community.zabbix.zabbix_authentication and community.zabbix.zabbix_user_directory and thought community.zabbix.zabbix_user_directory worked out for me..

community.zabbix.zabbix_authentication
Documentation for this module looks to be out of date, especially the example for "Update all authentication setting (Zabbix >= 6.4)". The playbook completes OK, but doesn't apply all configuration settings (on it's own)

community.zabbix.zabbix_user_directory
Worked out, following the "Create new user directory with SAML IDP or update existing info (Zabbix >= 6.4)" example in the documention linked above. On it's own it didn't "Enable SAML authentication".

Setup:
zabbix: 7.0.3
community.zabbix: 3.1.1

zabbix_authentication and zabbix_user_directory seem to be configuring the same, yet different options?

Update: turns out the zabbix_authentication configures which authentication method that Zabbix uses while zabbix_user_directory configures the settings within the selected authentication method ~ ie. use both for SAML.

I'm guessing SAML fields (saml_sso_url, saml_idp_entityid, etc.) in zabbix_authentication was moved to zabbix_user_directory in Zabbix > 6.4.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants