<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Authentication Configuration on</title><link>https://docs.opennebula.io/7.4/product/cloud_system_administration/authentication_configuration/</link><description>Recent content in Authentication Configuration on</description><generator>Hugo</generator><language>en</language><lastBuildDate>Wed, 09 Jul 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://docs.opennebula.io/7.4/product/cloud_system_administration/authentication_configuration/index.xml" rel="self" type="application/rss+xml"/><item><title>Overview</title><link>https://docs.opennebula.io/7.4/product/cloud_system_administration/authentication_configuration/overview/</link><pubDate>Mon, 17 Feb 2025 00:00:00 +0000</pubDate><guid>https://docs.opennebula.io/7.4/product/cloud_system_administration/authentication_configuration/overview/</guid><description>&lt;p&gt;&lt;a id="external-auth"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;!--# Overview --&gt;
&lt;p&gt;OpenNebula comes with a default internal user authentication system based on username/password, where information and secrets are stored in the OpenNebula (see the &lt;a href="https://docs.opennebula.io/7.4/product/cloud_system_administration/multitenancy/auth_overview/#auth-overview"&gt;Users &amp;amp; Groups Subsystem guide&lt;/a&gt;). Dedicated external user authentication drivers can be used to leverage additional authentication mechanisms or sources of information about the users (e.g., LDAP, SAML). This chapter describes the available user authentication and management options.&lt;/p&gt;
&lt;h2 id="authentication"&gt;
 Authentication
 &lt;a class="anchor-link" href="#authentication" aria-label="Link to this section"&gt;
 &lt;i class="fas fa-link fa-xs"&gt;&lt;/i&gt;
 &lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;&lt;img src="https://docs.opennebula.io/7.4/images/auth_options_350.png" alt="image0"&gt;&lt;/p&gt;</description></item><item><title>SSH Authentication</title><link>https://docs.opennebula.io/7.4/product/cloud_system_administration/authentication_configuration/ssh/</link><pubDate>Mon, 17 Feb 2025 00:00:00 +0000</pubDate><guid>https://docs.opennebula.io/7.4/product/cloud_system_administration/authentication_configuration/ssh/</guid><description>&lt;p&gt;&lt;a id="ssh-auth"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;!--# SSH Authentication --&gt;
&lt;p&gt;This guide will show you how to enable and use the SSH authentication with the OpenNebula CLI with authentication driver &lt;code&gt;ssh&lt;/code&gt;. Using this method, users log in to the OpenNebula with a token encrypted with their private SSH keys.&lt;/p&gt;
&lt;h2 id="requirements"&gt;
 Requirements
 &lt;a class="anchor-link" href="#requirements" aria-label="Link to this section"&gt;
 &lt;i class="fas fa-link fa-xs"&gt;&lt;/i&gt;
 &lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;No additional installation required.&lt;/p&gt;
&lt;h2 id="considerations--limitations"&gt;
 Considerations &amp;amp; Limitations
 &lt;a class="anchor-link" href="#considerations--limitations" aria-label="Link to this section"&gt;
 &lt;i class="fas fa-link fa-xs"&gt;&lt;/i&gt;
 &lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;This authentication method works only for interaction with OpenNebula &lt;strong&gt;over CLI&lt;/strong&gt;.&lt;/p&gt;</description></item><item><title>X.509 Authentication</title><link>https://docs.opennebula.io/7.4/product/cloud_system_administration/authentication_configuration/x509/</link><pubDate>Mon, 17 Feb 2025 00:00:00 +0000</pubDate><guid>https://docs.opennebula.io/7.4/product/cloud_system_administration/authentication_configuration/x509/</guid><description>&lt;p&gt;&lt;a id="x509-auth"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;!--# X.509 Authentication --&gt;
&lt;p&gt;This guide will show you how to enable and use authentication using X.509 certificates with OpenNebula with authentication driver &lt;code&gt;x509&lt;/code&gt;. The X.509 certificates can be used in two different ways in OpenNebula.&lt;/p&gt;
&lt;p&gt;The first option that is explained in this guide enables us to use certificates with the CLI. In this case the user will generate a login token with their private key. OpenNebula will validate the certificate and decrypt the token to authenticate the user.&lt;/p&gt;</description></item><item><title>LDAP Authentication</title><link>https://docs.opennebula.io/7.4/product/cloud_system_administration/authentication_configuration/ldap/</link><pubDate>Mon, 17 Feb 2025 00:00:00 +0000</pubDate><guid>https://docs.opennebula.io/7.4/product/cloud_system_administration/authentication_configuration/ldap/</guid><description>&lt;p&gt;&lt;a id="ldap"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;!--# LDAP Authentication --&gt;
&lt;p&gt;The LDAP Authentication allows users to have the same credentials as in LDAP, effectively centralizing authentication. Enabling it will let any correctly authenticated LDAP user use OpenNebula.&lt;/p&gt;
&lt;h2 id="requirements"&gt;
 Requirements
 &lt;a class="anchor-link" href="#requirements" aria-label="Link to this section"&gt;
 &lt;i class="fas fa-link fa-xs"&gt;&lt;/i&gt;
 &lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;You need to have your own LDAP server in the infrastructure. OpenNebula doesn’t contain or configure any LDAP server, it only connects to an existing one. Also, it doesn’t create, delete, or modify any entry in the LDAP server it connects to. The only requirement is the ability to connect to an already running LDAP server, perform a successful &lt;strong&gt;ldapbind&lt;/strong&gt; operation, and have a user able to perform searches of other users. Therefore no special attributes or values are required in the LDIF entry of the authenticating user.&lt;/p&gt;</description></item><item><title>SAML Authentication</title><link>https://docs.opennebula.io/7.4/product/cloud_system_administration/authentication_configuration/saml/</link><pubDate>Wed, 09 Jul 2025 00:00:00 +0000</pubDate><guid>https://docs.opennebula.io/7.4/product/cloud_system_administration/authentication_configuration/saml/</guid><description>&lt;p&gt;&lt;a id="saml"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;!--# SAML Authentication --&gt;
&lt;p&gt;The SAML Authentication driver allows users to access OpenNebula by logging in into a trusted SAML Identity Provider, effectively centralizing authentication and allowing Single Sign-On. Enabling it allows OpenNebula to be used as a SAML Service Provider.&lt;/p&gt;
&lt;h2 id="requirements"&gt;
 Requirements
 &lt;a class="anchor-link" href="#requirements" aria-label="Link to this section"&gt;
 &lt;i class="fas fa-link fa-xs"&gt;&lt;/i&gt;
 &lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;You need to manage your own SAML Identity Provider. OpenNebula doesn’t contain or configure any SAML Identity Provider, it only receives SAML responses and validates those.&lt;/p&gt;</description></item><item><title>Sunstone Authentication</title><link>https://docs.opennebula.io/7.4/product/cloud_system_administration/authentication_configuration/sunstone_auth/</link><pubDate>Mon, 17 Feb 2025 00:00:00 +0000</pubDate><guid>https://docs.opennebula.io/7.4/product/cloud_system_administration/authentication_configuration/sunstone_auth/</guid><description>&lt;p&gt;&lt;a id="sunstone-auth"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;!--# Sunstone Authentication --&gt;
&lt;p&gt;By default, Sunstone works with the default &lt;code&gt;core&lt;/code&gt; authentication method (user and password) although you can configure any authentication mechanism supported by OpenNebula. In this section, you will learn how to enable other authentication.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Authentication is based on the credentials stored in the OpenNebula database for the user. Depending on the type of these credentials the authentication method can be: &lt;code&gt;remote&lt;/code&gt; or &lt;code&gt;opennebula&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The following sections explain Sunstone server authentication methods to the user.&lt;/p&gt;</description></item></channel></rss>