kimai / Paid-plugins

Support for paid Kimai plugins: Discussions and feature requests
https://www.kimai.org/store/
11 stars 1 forks source link

Renew Signature / x509 Certificate #99

Closed PentaPaetzold closed 1 year ago

PentaPaetzold commented 1 year ago

We use Authentik/SAML with Kimai as documented in https://www.kimai.org/documentation/saml-authentik.html , which works really fine!

Our Certificates in Authentik are let's encryted ones, so they renew quite fast and automagically. Authentik is able to refresh them when they have changed.

But after every refresh, the Signature of the Cert has changed - breaking Kimai Login while the Parameter in local.yaml for the x509cert is wrong and needs to be manually changed each time.

I have had no problem with other services using the same Certificate (but Oauth2), so technically there should be ways to make it work. Removing the x509Cert- Value from Config also breaks Login.

Wondering if there is another parameter to supress the need of x509Cert. If not, any solutions to make it work automatically? The Certs could be made public to kimai i needed.

kevinpapst commented 1 year ago

That has nothing to do with paid plugins. Please post in the core repository at https://github.com/kimai/kimai/discussions