[GH-ISSUE #7390] Non-functional SSO configuration #39944

Closed
opened 2026-07-17 20:59:21 -05:00 by GiteaMirror · 0 comments
Owner

Originally created by @laqures on GitHub (Jul 1, 2026).
Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/7390

Prerequisites

Vaultwarden Support String

Ваша среда (сгенерирована через страницу диагностики)

  • Версия Vaultwarden: v1.36.0
  • Версия веб-хранилища: v2026.4.1
  • ОС/Архитектура: linux/x86_64
  • Запуск внутри контейнера: true (Основа: Debian)
  • Тип базы данных: SQLite
  • Версия базы данных: 3.51.3
  • Использует config.json: true
  • Использует обратный прокси: true
  • Проверка заголовка IP: true (X-Real-IP)
  • Доступ в Интернет: true
  • Доступ в Интернет через прокси: false
  • Проверка DNS: true
  • Проверка времени браузера/сервера: true
  • Проверка времени сервера/NTP: true
  • Проверка конфигурации домена: true
  • Проверка HTTPS: true
  • Проверка WebSocket: false
  • Проверка HTTP-ответа: true

Конфигурация и подробные сведения (сгенерированы через страницу диагностики)

Показать конфигурацию и подробности

Переопределяемые параметры среды: DOMAIN, ADMIN_TOKEN

Конфигурация:

{
  "_duo_akey": null,
  "_enable_duo": true,
  "_enable_email_2fa": false,
  "_enable_smtp": true,
  "_enable_yubico": true,
  "_icon_service_csp": "",
  "_icon_service_url": "",
  "_ip_header_enabled": true,
  "_max_note_size": 10000,
  "_smtp_img_src": "***:",
  "admin_ratelimit_max_burst": 3,
  «admin_ratelimit_секунды»: 300,
  "admin_session_lifetime": 20,
  "admin_token": "***",
  "allowed_connect_src": "",
  "allowed_iframe_ancestors": "",
  "attachments_folder": "data/attachments",
  "auth_request_purge_schedule": "30 * * * * *",
  "authenticator_disable_time_drift": false,
  "data_folder": "data",
  "database_conn_init": "",
  "database_idle_timeout": 600,
  "database_max_conns": 10,
  "database_min_conns": 2,
  "database_timeout": 30,
  "database_url": "***************",
  "db_connection_retries": 15,
  "disable_2fa_remember": false,
  "disable_admin_token": false,
  "disable_icon_download": false,
  "dns_prefer_ipv6": false,
  "домен": "*****://****************************",
  "domain_origin": "*****://****************************",
  "domain_path": "",
  "domain_set": true,
  "duo_context_purge_schedule": "30 * * * * *",
  "duo_host": null,
  "duo_ikey": null,
  "duo_skey": null,
  "duo_use_iframe": false,
  "email_2fa_auto_fallback": false,
  "email_2fa_enforce_on_verified_invite": false,
  "email_attempts_limit": 3,
  "email_change_allowed": true,
  "email_expiration_time": 600,
  "email_token_size": 6,
  "emergency_access_allowed": true,
  "emergency_notification_reminder_schedule": "0 3 * * * *",
  "emergency_request_timeout_schedule": "0 7 * * * *",
  "enable_db_wal": true,
  "enable_websocket": true,
  "enforce_single_org_with_reset_pw_policy": false,
  "event_cleanup_schedule": "0 10 0 * * *",
  "events_days_retain": null,
  "experimental_client_feature_flags": "",
  "extended_logging": true,
  "helo_name": null,
  "hibp_api_key": null,
  "http_request_block_non_global_ips": true,
  "http_request_block_regex": null,
  "icon_blacklist_non_global_ips": true,
  "icon_blacklist_regex": null,
  "icon_cache_folder": "data/icon_cache",
  "icon_cache_negttl": 259200,
  "icon_cache_ttl": 2592000,
  "icon_download_timeout": 10,
  "icon_redirect_code": 302,
  "icon_service": "internal",
  "incomplete_2fa_schedule": "30 * * * * *",
  "incomplete_2fa_time_limit": 3,
  "increase_note_size_limit": false,
  "invitation_expiration_hours": 120,
  "invitation_org_name": "Vaultwarden",
  "invitations_allowed": true,
  "ip_header": "X-Real-IP",
  "job_poll_interval_ms": 30000,
  "log_file": null,
  "log_level": "info,vaultwarden::sso=debug,rustls::webpki::anchors=debug,rustls_platform_verifier::verification::others=debug",
  "log_timestamp_format": "%Y-%m-%d %H:%M:%S.%3f",
  «login_ratelimit_max_burst»: 10,
  "login_ratelimit_seconds": 60,
  "org_attachment_limit": null,
  "org_creation_users": "",
  "org_events_enabled": false,
  "org_groups_enabled": false,
  "password_hints_allowed": true,
  "password_iterations": 600000,
  "purge_incomplete_sso_auth": "0 20 0 * * *",
  "push_enabled": false,
  "push_identity_uri": "https://identity.bitwarden.com",
  "push_installation_id": "***",
  "push_installation_key": "***",
  "push_relay_uri": "https://push.bitwarden.com",
  "reload_templates": false,
  "require_device_email": false,
  "rsa_key_filename": "data/rsa_key",
  "send_purge_schedule": "0 5 * * * *",
  "sendmail_command": null,
  "sends_allowed": true,
  "sends_folder": "data/sends",
  "show_password_hint": false,
  "signups_allowed": true,
  "signups_domains_whitelist": "",
  "signups_verify": false,
  "signups_verify_resend_limit": 6,
  "signups_verify_resend_time": 3600,
  "smtp_accept_invalid_certs": false,
  "smtp_accept_invalid_hostnames": false,
  "smtp_auth_mechanism": "Plain,Login",
  "smtp_debug": false,
  "smtp_embed_images": true,
  "smtp_explicit_tls": null,
  "smtp_from": "********************",
  "smtp_from_name": "***************",
  "smtp_host": "************",
  "smtp_password": "***",
  "smtp_port": 587,
  "smtp_security": "starttls",
  "smtp_ssl": null,
  "smtp_timeout": 15,
  "smtp_username": "******************",
  "sso_allow_unknown_email_verification": false,
  "sso_audience_trusted": null,
  "sso_auth_only_not_session": false,
  "sso_authority": "*****://*************************",
  "sso_authorize_extra_params": "",
  "sso_callback_path": "*****://*********************************************************",
  "sso_client_cache_expiration": 0,
  "sso_client_id": "****************************************",
  "sso_client_secret": "***",
  "sso_debug_tokens": false,
  "sso_enabled": true,
  "sso_master_password_policy": null,
  "sso_only": false,
  "sso_pkce": true,
  "sso_scopes": "email profile",
  "sso_signups_match_email": true,
  "templates_folder": "data/templates",
  "tmp_folder": "data/tmp",
  "trash_auto_delete_days": null,
  "trash_purge_schedule": "0 5 0 * * *",
  "use_sendmail": false,
  "use_syslog": false,
  "user_attachment_limit": null,
  "user_send_limit": null,
  "web_vault_enabled": true,
  "web_vault_folder": "web-vault/",
  "yubico_client_id": null,
  "yubico_secret_key": null,
  "yubico_server": null
}

Vaultwarden Build Version

1.36.0

Deployment method

Official Container Image

Custom deployment method

No response

Reverse Proxy

NPM v2.14.0

Host/Server Operating System

Linux

Operating System Version

Ubuntu 26.04

Clients

Web Vault

Client Version

2026.4.1

Steps To Reproduce

  1. Go to the "url" link
  2. Enter the username
  3. Click the SSO button
  4. It returns an error

Expected Result

  1. Go to 'url'
  2. FIll in username
  3. Click on SSO
  4. Login ADFS
  5. Login Succesfull

Actual Result

  1. Go to the "url" link
  2. Enter the username
  3. Click the SSO button
  4. The following error occurs:
    {"message":"Failed to discover OpenID provider: Request failed","validationErrors":{"":["Failed to discover OpenID provider: Request failed"]},"errorModel":{"message":"Failed to discover OpenID provider: Request failed","object":"error"},"error":"","error_description":"","exceptionMessage":null,"exceptionStackTrace":null,"innerExceptionMessage":null,"object":"error"}

Logs

vaultwarden          | [2026-07-01 12:00:10.518][request][INFO] POST /api/organizations/domain/sso/verified
vaultwarden          | [2026-07-01 12:00:10.519][response][INFO] (get_org_domain_sso_verified) POST /api/organizations/domain/sso/verified => 200 OK
vaultwarden          | [2026-07-01 12:00:10.535][request][INFO] GET /identity/sso/prevalidate?domainHint=00000000-01DC-01DC-
vaultwarden          | [2026-07-01 12:00:10.540][response][INFO] (prevalidate) GET /identity/sso/prevalidate => 200 OK
vaultwarden          | [2026-07-01 12:00:10.596][request][INFO] GET /identity/connect/authorize?client_id=web&redirect_uri=htt
vaultwarden          | [2026-07-01 12:00:10.644][vaultwarden::sso_client][ERROR] Failed to discover OpenID provider: Request failed
vaultwarden          | [2026-07-01 12:00:10.644][response][INFO] (authorize) GET /identity/connect/authorize?<data..> => 400 Bad Request

Screenshots or Videos

Image

Additional Context

I am fairly certain the issue lies in my configuration, but I am asking for your help nonetheless.
I am using a local ADFS server for SSO; I set it up following the official Bitwarden documentation (https://bitwarden.com/help/adfs-oidc-implementation/#create-an-application-group)
and configured the Vaultwarden SSO settings using your documentation (https://github.com/dani-garcia/vaultwarden/wiki/Enabling-SSO-support-using-OpenId-Connect).
I also found a few issues that might be related to my problem, specifically:

  1. (https://github.com/dani-garcia/vaultwarden/discussions/7192) – this discusses a potential cause, although I did add the Active Directory Certificate Authority certificate using these commands:
    docker cp /root/ca.crt vaultwarden-ldap-sync:/usr/local/share/ca-certificates/ca.crt
    and inside the Vaultwarden-ldap-sync container:
    docker exec -it vaultwarden-ldap-sync sh
    update-ca-certificates
  2. (https://github.com/dani-garcia/vaultwarden/discussions/7152)
    No one replied to this issue, but in my case, email addresses don't always use my domain; they might also be, for example, gmail.com.
Originally created by @laqures on GitHub (Jul 1, 2026). Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/7390 ### Prerequisites - [x] I have searched the existing **Closed _AND_ Open** [Issues](https://github.com/dani-garcia/vaultwarden/issues?q=is%3Aissue%20) **_AND_** [Discussions](https://github.com/dani-garcia/vaultwarden/discussions?discussions_q=) - [x] I have searched and read the [documentation](https://github.com/dani-garcia/vaultwarden/wiki/) ### Vaultwarden Support String ### Ваша среда (сгенерирована через страницу диагностики) * Версия Vaultwarden: v1.36.0 * Версия веб-хранилища: v2026.4.1 * ОС/Архитектура: linux/x86_64 * Запуск внутри контейнера: true (Основа: Debian) * Тип базы данных: SQLite * Версия базы данных: 3.51.3 * Использует config.json: true * Использует обратный прокси: true * Проверка заголовка IP: true (X-Real-IP) * Доступ в Интернет: true * Доступ в Интернет через прокси: false * Проверка DNS: true * Проверка времени браузера/сервера: true * Проверка времени сервера/NTP: true * Проверка конфигурации домена: true * Проверка HTTPS: true * Проверка WebSocket: false * Проверка HTTP-ответа: true ### Конфигурация и подробные сведения (сгенерированы через страницу диагностики) <details><summary>Показать конфигурацию и подробности</summary> **Переопределяемые параметры среды:** DOMAIN, ADMIN_TOKEN **Конфигурация:** ```json { "_duo_akey": null, "_enable_duo": true, "_enable_email_2fa": false, "_enable_smtp": true, "_enable_yubico": true, "_icon_service_csp": "", "_icon_service_url": "", "_ip_header_enabled": true, "_max_note_size": 10000, "_smtp_img_src": "***:", "admin_ratelimit_max_burst": 3, «admin_ratelimit_секунды»: 300, "admin_session_lifetime": 20, "admin_token": "***", "allowed_connect_src": "", "allowed_iframe_ancestors": "", "attachments_folder": "data/attachments", "auth_request_purge_schedule": "30 * * * * *", "authenticator_disable_time_drift": false, "data_folder": "data", "database_conn_init": "", "database_idle_timeout": 600, "database_max_conns": 10, "database_min_conns": 2, "database_timeout": 30, "database_url": "***************", "db_connection_retries": 15, "disable_2fa_remember": false, "disable_admin_token": false, "disable_icon_download": false, "dns_prefer_ipv6": false, "домен": "*****://****************************", "domain_origin": "*****://****************************", "domain_path": "", "domain_set": true, "duo_context_purge_schedule": "30 * * * * *", "duo_host": null, "duo_ikey": null, "duo_skey": null, "duo_use_iframe": false, "email_2fa_auto_fallback": false, "email_2fa_enforce_on_verified_invite": false, "email_attempts_limit": 3, "email_change_allowed": true, "email_expiration_time": 600, "email_token_size": 6, "emergency_access_allowed": true, "emergency_notification_reminder_schedule": "0 3 * * * *", "emergency_request_timeout_schedule": "0 7 * * * *", "enable_db_wal": true, "enable_websocket": true, "enforce_single_org_with_reset_pw_policy": false, "event_cleanup_schedule": "0 10 0 * * *", "events_days_retain": null, "experimental_client_feature_flags": "", "extended_logging": true, "helo_name": null, "hibp_api_key": null, "http_request_block_non_global_ips": true, "http_request_block_regex": null, "icon_blacklist_non_global_ips": true, "icon_blacklist_regex": null, "icon_cache_folder": "data/icon_cache", "icon_cache_negttl": 259200, "icon_cache_ttl": 2592000, "icon_download_timeout": 10, "icon_redirect_code": 302, "icon_service": "internal", "incomplete_2fa_schedule": "30 * * * * *", "incomplete_2fa_time_limit": 3, "increase_note_size_limit": false, "invitation_expiration_hours": 120, "invitation_org_name": "Vaultwarden", "invitations_allowed": true, "ip_header": "X-Real-IP", "job_poll_interval_ms": 30000, "log_file": null, "log_level": "info,vaultwarden::sso=debug,rustls::webpki::anchors=debug,rustls_platform_verifier::verification::others=debug", "log_timestamp_format": "%Y-%m-%d %H:%M:%S.%3f", «login_ratelimit_max_burst»: 10, "login_ratelimit_seconds": 60, "org_attachment_limit": null, "org_creation_users": "", "org_events_enabled": false, "org_groups_enabled": false, "password_hints_allowed": true, "password_iterations": 600000, "purge_incomplete_sso_auth": "0 20 0 * * *", "push_enabled": false, "push_identity_uri": "https://identity.bitwarden.com", "push_installation_id": "***", "push_installation_key": "***", "push_relay_uri": "https://push.bitwarden.com", "reload_templates": false, "require_device_email": false, "rsa_key_filename": "data/rsa_key", "send_purge_schedule": "0 5 * * * *", "sendmail_command": null, "sends_allowed": true, "sends_folder": "data/sends", "show_password_hint": false, "signups_allowed": true, "signups_domains_whitelist": "", "signups_verify": false, "signups_verify_resend_limit": 6, "signups_verify_resend_time": 3600, "smtp_accept_invalid_certs": false, "smtp_accept_invalid_hostnames": false, "smtp_auth_mechanism": "Plain,Login", "smtp_debug": false, "smtp_embed_images": true, "smtp_explicit_tls": null, "smtp_from": "********************", "smtp_from_name": "***************", "smtp_host": "************", "smtp_password": "***", "smtp_port": 587, "smtp_security": "starttls", "smtp_ssl": null, "smtp_timeout": 15, "smtp_username": "******************", "sso_allow_unknown_email_verification": false, "sso_audience_trusted": null, "sso_auth_only_not_session": false, "sso_authority": "*****://*************************", "sso_authorize_extra_params": "", "sso_callback_path": "*****://*********************************************************", "sso_client_cache_expiration": 0, "sso_client_id": "****************************************", "sso_client_secret": "***", "sso_debug_tokens": false, "sso_enabled": true, "sso_master_password_policy": null, "sso_only": false, "sso_pkce": true, "sso_scopes": "email profile", "sso_signups_match_email": true, "templates_folder": "data/templates", "tmp_folder": "data/tmp", "trash_auto_delete_days": null, "trash_purge_schedule": "0 5 0 * * *", "use_sendmail": false, "use_syslog": false, "user_attachment_limit": null, "user_send_limit": null, "web_vault_enabled": true, "web_vault_folder": "web-vault/", "yubico_client_id": null, "yubico_secret_key": null, "yubico_server": null } ``` </details> ### Vaultwarden Build Version 1.36.0 ### Deployment method Official Container Image ### Custom deployment method _No response_ ### Reverse Proxy NPM v2.14.0 ### Host/Server Operating System Linux ### Operating System Version Ubuntu 26.04 ### Clients Web Vault ### Client Version 2026.4.1 ### Steps To Reproduce 1. Go to the "url" link 2. Enter the username 3. Click the SSO button 4. It returns an error ### Expected Result 1. Go to 'url' 2. FIll in username 3. Click on SSO 4. Login ADFS 5. Login Succesfull ### Actual Result 1. Go to the "url" link 2. Enter the username 3. Click the SSO button 4. The following error occurs: {"message":"Failed to discover OpenID provider: Request failed","validationErrors":{"":["Failed to discover OpenID provider: Request failed"]},"errorModel":{"message":"Failed to discover OpenID provider: Request failed","object":"error"},"error":"","error_description":"","exceptionMessage":null,"exceptionStackTrace":null,"innerExceptionMessage":null,"object":"error"} ### Logs ```text vaultwarden | [2026-07-01 12:00:10.518][request][INFO] POST /api/organizations/domain/sso/verified vaultwarden | [2026-07-01 12:00:10.519][response][INFO] (get_org_domain_sso_verified) POST /api/organizations/domain/sso/verified => 200 OK vaultwarden | [2026-07-01 12:00:10.535][request][INFO] GET /identity/sso/prevalidate?domainHint=00000000-01DC-01DC- vaultwarden | [2026-07-01 12:00:10.540][response][INFO] (prevalidate) GET /identity/sso/prevalidate => 200 OK vaultwarden | [2026-07-01 12:00:10.596][request][INFO] GET /identity/connect/authorize?client_id=web&redirect_uri=htt vaultwarden | [2026-07-01 12:00:10.644][vaultwarden::sso_client][ERROR] Failed to discover OpenID provider: Request failed vaultwarden | [2026-07-01 12:00:10.644][response][INFO] (authorize) GET /identity/connect/authorize?<data..> => 400 Bad Request ``` ### Screenshots or Videos <img width="1146" height="809" alt="Image" src="https://github.com/user-attachments/assets/dd3f742b-42d7-412b-a72f-39ca268c13e2" /> ### Additional Context I am fairly certain the issue lies in my configuration, but I am asking for your help nonetheless. I am using a local ADFS server for SSO; I set it up following the official Bitwarden documentation (https://bitwarden.com/help/adfs-oidc-implementation/#create-an-application-group) and configured the Vaultwarden SSO settings using your documentation (https://github.com/dani-garcia/vaultwarden/wiki/Enabling-SSO-support-using-OpenId-Connect). I also found a few issues that might be related to my problem, specifically: 1. (https://github.com/dani-garcia/vaultwarden/discussions/7192) – this discusses a potential cause, although I did add the Active Directory Certificate Authority certificate using these commands: docker cp /root/ca.crt vaultwarden-ldap-sync:/usr/local/share/ca-certificates/ca.crt and inside the Vaultwarden-ldap-sync container: docker exec -it vaultwarden-ldap-sync sh update-ca-certificates 2. (https://github.com/dani-garcia/vaultwarden/discussions/7152) No one replied to this issue, but in my case, email addresses don't always use my domain; they might also be, for example, gmail.com.
GiteaMirror added the bug label 2026-07-17 20:59:21 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/vaultwarden#39944