robchahin / sso-wall-of-shame

A list of vendors that treat single sign-on as a luxury feature, not a core security requirement.
https://sso.tax
Apache License 2.0
654 stars 297 forks source link

HashiCorp (Vault) #211

Open kplimack opened 3 years ago

kplimack commented 3 years ago

What is the vendor's name? Hashicorp

What is the vendor's pricing site? https://www.vaultproject.io/docs/enterprise/mfa

pricing is variable, but starts around $30k per server per year

the-maldridge commented 3 years ago

SSO is not gated behind enterprise support though? MFA feels distinct, and since Vault's MFA is only in use in certain circumstances, this seems like this needs some qualifiers, especially when compared with the rest of the wall where its either all or nothing for SSO.

bulebuk commented 2 years ago

https://www.hashicorp.com/products/terraform/pricing

SSO is only available for Terraform Cloud at the Enterprise tier.

the-maldridge commented 2 years ago

This ticket is now defunct since MFA is available in the free version, which was the original call to place it on the wall.

@bulebuk Sounds like you should open a new ticket for Terraform Cloud, which is a distinct product from both Vault and Terraform.

msusta commented 2 years ago

One major note here - Vault by Hashicorp is produced as Open Source and can be licensed to handle more functionality. Also considering the use-case of Vault I'd not expect the users to actually run it in a way that's reachable from public Internet.

There's a completely different offering called Hashicorp Cloud Platform, which does support SSO no matter the products/tiers you use.