Lesson 4 : How to secure AWS ALB using Auth0 & OIDC?

  Рет қаралды 3,905

Security in Action 101

Security in Action 101

Күн бұрын

This is the second video in the series to secure AWS ALB using a OIDC provider :
Step 1 : Configure a AWS ALB with HTTPS listener • Lesson 1 : How to secu...
Step 2 : Configure Auth0 as the OIDC provider
#aws #amazonwebservices #openid #auth0 #authentication #iam #identity #amazonwebservices #awsalb #security

Пікірлер: 11
@securityinaction1018
@securityinaction1018 2 жыл бұрын
Please subscribe to this channel for regular updates kzbin.info/door/EEayyyCrJO94FYlzF0NLTg Thank You for the support.
@NimitSharma1988
@NimitSharma1988 2 жыл бұрын
I really liked the way you explained this workflow. Is it possible if you can create a video to configure Keycloak as AWS ALB OIDC Idp ?
@securityinaction1018
@securityinaction1018 2 жыл бұрын
Thank You. I have not used Keycloak before. I will let you know if I post a video using keycloak. I hope it should work the same way as any other Identity Provider.
@NimitSharma1988
@NimitSharma1988 2 жыл бұрын
@@securityinaction1018 The workflow is indeed same but I am getting 561 Authentication Error for some reason.
@securityinaction1018
@securityinaction1018 2 жыл бұрын
I think it should be some configuration issue in KeyCloak or ALB. You can check if this solution works. stackoverflow.com/questions/62820277/aws-application-load-balancer-with-onelogin-giving-561-authentication-error#:~:text=HTTP%20561%3A%20Unauthorized%20You%20configured,code%20when%20authenticating%20the%20user
@dtefft
@dtefft 2 жыл бұрын
Can you use a similar configuration for machine to machine APIs or does this ALB set up only work for user applications?
@securityinaction1018
@securityinaction1018 2 жыл бұрын
This ALB setup uses OIDC Authorization code grant flow which involves user interaction. For M2M or Machine-To-Machine APIs, you can use AWS API gateway. Front-end app can be behind ALB which will perform a user authentication and generate ID, Access & Refresh tokens. Backend APIs can be behind API Gateway which will validate the access token to allow / deny access.
@saikatghosh8437
@saikatghosh8437 2 жыл бұрын
Could you please share the app thats running, i am trying the same but not sure how to read the headers. Thanks in advance.
@securityinaction1018
@securityinaction1018 2 жыл бұрын
Are you referring to the lambda function that returns the headers? If so, please share the code here and I can check it.
@saikatghosh8437
@saikatghosh8437 2 жыл бұрын
Yes, I am not sure how to write it, if you could help with some example method. Thanks
@securityinaction1018
@securityinaction1018 2 жыл бұрын
Please watch this video kzbin.info/www/bejne/aWKngoyiqap_nZo to create that lambda function. This link is also available in the details section.
How to integrate Java Spring Boot application with Auth0 using OIDC?
38:19
Security in Action 101
Рет қаралды 2,8 М.
How to integrate two AWS Cognito user pools using OIDC?
23:14
Security in Action 101
Рет қаралды 2 М.
GIANT Gummy Worm Pt.6 #shorts
00:46
Mr DegrEE
Рет қаралды 110 МЛН
Миллионер | 1 - серия
34:31
Million Show
Рет қаралды 2,2 МЛН
РОДИТЕЛИ НА ШКОЛЬНОМ ПРАЗДНИКЕ
01:00
SIDELNIKOVVV
Рет қаралды 3 МЛН
An Illustrated Guide to OAuth and OpenID Connect
16:36
OktaDev
Рет қаралды 594 М.
Lesson 2 : How to secure AWS ALB using Cognito & OIDC?
23:20
Security in Action 101
Рет қаралды 4,9 М.
Postman Tutorials | 10 | Bearer Token Authorization | தமிழ்
15:57
Learn Automation Online
Рет қаралды 21 М.
How to add Keycloak as a OIDC Identity Provider in AWS Cognito?
23:00
Security in Action 101
Рет қаралды 3,2 М.
Application Load Balancer (ALB) Vs API Gateway // Pros Cons Comparison
14:04
How to secure SpringBoot REST APIs using Auth0 OAuth2 scopes?
30:23
Security in Action 101
Рет қаралды 5 М.
iPhone 16
0:20
Adhemz
Рет қаралды 13 МЛН
The damaged battery head isrepaired. #Battery #Repair
0:21
Hak Hang
Рет қаралды 18 МЛН
Обзор на 16 айфон
1:01
Тыковка из Германии
Рет қаралды 764 М.
Куда пропал Kodak?
1:01
MOTIVESSION
Рет қаралды 9 МЛН