mod_auth_openidc is a free, open source identity & access management (iam) project written in C and released under Apache-2.0. It has 1,096 GitHub stars, 332 forks and 0 open issues, and was last pushed yesterday. On this registry it ranks #44 of 58 tracked projects in Identity & Access Management (IAM), with 5 head-to-head comparisons available.

What is mod_auth_openidc?

mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server, aimed at administrators and developers who want to protect web applications with OpenID Connect and FAPI 2 Relying Party support.

What it is

mod_auth_openidc is a C module for the Apache 2.x HTTP server that turns that server into an OpenID Connect Relying Party (RP) towards an OpenID Connect Provider (OP). It relays end user authentication to the Provider, receives user identity information in the form of claims from the resulting id_token and, where configured, the UserInfo endpoint, and then establishes an authentication session for the identified user with the applications protected by Apache. The module is an OpenID Certified™ implementation of OpenID Connect 1.x and FAPI 2.x Relying Party functionality, and its complete set of configuration options is documented in the file auth_openidc.conf, which can also be included directly from httpd.conf.

The concrete problem it solves is adding standards-based authentication to applications that have none, or replacing legacy authentication with OpenID Connect Single Sign On (SSO). Because Apache can be configured as a reverse proxy in front of origin servers, the module can front existing applications, services and SPAs without modifying those applications at all, while the protected content may equally be hosted by the Apache server itself. Rather than operating as an identity provider of its own, it replaces the hand-rolled or proprietary login logic inside each application with a single delegation point that talks to an external OP.

Key capabilities

  • Sets the REMOTE_USER variable by default to the id_token [sub] claim concatenated with the OP's Issuer identifier as [sub]@[iss].
  • Passes further id_token claims to protected applications through HTTP headers and/or environment variables, together with claims optionally obtained from the UserInfo endpoint.
  • Supports custom fine-grained authorization rules built on Apache's Require primitives, matched against the claims provided in the id_token and userinfo.
  • Configures clustering for resilience and performance through a choice of supported cache backends.
  • Configures the Provider by pointing OIDCProviderMetadataURL at the Discovery metadata served on the .well-known/openid-configuration endpoint.
  • Registers a vanity OIDCRedirectURI inside a protected location together with OIDCClientID and OIDCClientSecret obtained from the Provider.
  • Provides a full configuration reference in auth_openidc.conf, usable as an include file for httpd.conf.

Who uses it and how

  • Operators placing Apache as a reverse proxy in front of existing origin servers, services or SPAs to add OpenID Connect authentication without changing the applications behind it.
  • Teams migrating users away from legacy authentication mechanisms to standards-based OpenID Connect Single Sign On across applications served by the same Apache server.
  • Administrators protecting content hosted directly by Apache itself, using Require rules against id_token and userinfo claims for authorization.
  • Deployments that need clustering for resilience and performance, selecting one of the supported cache backends.
  • Environments obtaining pre-built binaries from distribution packages or from release binaries attached to GitHub Releases, rather than building from source.

Getting started

On Debian/Ubuntu install the pre-built package with apt install libapache2-mod-auth-openidc, then load mod_auth_openidc.so, set OIDCRedirectURI, configure OIDCProviderMetadataURL and supply OIDCClientID and OIDCClientSecret. To build from source, run ./configure --with-apxs=/usr/bin/apxs2, then make and sudo make install, with the full dependency list in INSTALL.

How it compares

No paid products this project replaces are named in the available facts, and no similar tools are named either; mod_auth_openidc therefore stands alone in this registry.

When to use it — and when not to

You must be running the Apache 2.x HTTP server, since the module has no other host, and you need an external OpenID Connect Provider plus a registered client identifier, secret and redirect URI before anything authenticates; cache backend choice also has to be made if you want clustered state. It is a poor fit for applications served by other web servers or for teams that would have to stand up a Provider themselves, and note that REMOTE_USER is set from the [sub] and [iss] claims by default, so applications relying on a different identifier format will need header or environment claim configuration.

project readme (upstream, from github) — read inline

Build Status Quality Gate Status Coverage License OpenID Certification

mod_auth_openidc

mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect 1.x and FAPI 2.x Relying Party functionality.

Overview

This module enables an Apache 2.x web server to operate as an OpenID Connect Relying Party (RP) towards an OpenID Connect Provider (OP). It relays end user authentication to a Provider and receives user identity information from that Provider. It then passes on that identity information (a.k.a. claims) to applications protected by the Apache web server and establishes an authentication session for the identified user.

The protected content, applications and services can be hosted by the Apache server itself or served from origin server(s) residing behind it by configuring Apache as a Reverse Proxy in front of those servers. The latter allows for adding OpenID Connect based authentication to existing applications/services/SPAs without modifying those applications, possibly migrating them away from legacy authentication mechanisms to standards-based OpenID Connect Single Sign On (SSO).

By default the module sets the REMOTE_USER variable to the id_token [sub] claim, concatenated with the OP's Issuer identifier ([sub]@[iss]). Other id_token claims are passed in HTTP headers and/or environment variables together with those (optionally) obtained from the UserInfo endpoint. The provided HTTP headers and environment variables can be consumed by applications protected by the Apache server.

Custom fine-grained authorization rules - based on Apache's Require primitives - can be specified to match against the set of claims provided in the id_token/ userinfo claims, see here. Clustering for resilience and performance can be configured using one of the supported cache backends options as listed here.

For a complete overview of all configuration options, see the file auth_openidc.conf. This file can also serve as an include file for httpd.conf.

Installation

Preferably install one of the pre-built binary packages. On Debian/Ubuntu:

apt install libapache2-mod-auth-openidc

Packages for other platforms are listed in the Wiki, and release binaries are attached to the GitHub Releases.

To build from source (see INSTALL for the full dependency list):

./configure --with-apxs=/usr/bin/apxs2   # apxs2 may be named apxs on your platform
make
sudo make install

How to Use It

  1. install and load mod_auth_openidc.so in your Apache server
  2. set OIDCRedirectURI to a "vanity" URL within a location that is protected by mod_auth_openidc
  3. configure OIDCProviderMetadataURL so it points to the Discovery metadata of your OpenID Connect Provider served on the .well-known/openid-configuration endpoint
  4. register/generate a Client identifier and a secret with the OpenID Connect Provider and configure those in OIDCClientID and OIDCClientSecret respectively
  5. register the OIDCRedirectURI configured above as the Redirect or Callback URI for your client at the Provider
  6. configure your protected content/locations with AuthType openid-connect

A minimal working configuration would look like:

LoadModule auth_openidc_module modules/mod_auth_openidc.so

# OIDCRedirectURI is a vanity URL that must point to a path protected by this module but must NOT point to any content
OIDCRedirectURI https://<hostname>/secure/redirect_uri

# required to persist sessions across restarts and share them across a cluster;
# when omitted a random passphrase is generated at each restart, invalidating existing sessions
OIDCCryptoPassphrase <passphrase-or-"exec:/path/to/generator">

OIDCProviderMetadataURL <issuer>/.well-known/openid-configuration
OIDCClientID <client_id>
OIDCClientSecret <client_secret>

<Location /secure>
   AuthType openid-connect
   Require valid-user
</Location>

For claims-based authorization with Require claim: directives see the Wiki page on Authorization. For details on configuring multiple providers see the Wiki.

Quickstart for specific Providers

See the Wiki for configuration docs for other OpenID Connect Providers.

Interoperability and Supported Specifications

mod_auth_openidc is OpenID Certified™ and supports the following specifications:

Support

Community

Documentation can be found at the Wiki (including Frequently Asked Questions) at:
https://github.com/OpenIDC/mod_auth_openidc/wiki
For questions, issues and suggestions use the Github Discussions forum at:
https://github.com/OpenIDC/mod_auth_openidc/discussions

Security

To report a security vulnerability, please follow the process in SECURITY.md (e-mail support@openidc.com); do not file public issues for vulnerabilities.

Commercial

Licensed builds with support for Redis/Valkey over TLS, Redis Sentinel/Cluster as well as binary packages for Microsoft Windows, EOL Red Hat, Ubuntu and Debian releases, Oracle HTTP Server and IBM HTTP Server are available under a commercial agreement.

For inquiries about commercial - subscription based - support and licensing please contact:
sales@openidc.com

License

Apache License 2.0 - see LICENSE.txt.

Disclaimer

This software is open sourced by OpenIDC, a subsidiary of ZmartZone Holding B.V. For commercial services you can contact OpenIDC as described above in the Support section.

Frequently asked questions

Is mod_auth_openidc free to use?

mod_auth_openidc is open source under the Apache-2.0 licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does mod_auth_openidc do?

OpenID Certified™ OpenID Connect and FAPI 2 Relying Party module for Apache HTTPd

What is mod_auth_openidc written in?

mod_auth_openidc is primarily written in C. Its source is publicly available at https://github.com/OpenIDC/mod_auth_openidc, and it has 1,096 GitHub stars.