Skip to content

OIDC and email address #1095

Answered by tashian
foleyjohnm asked this question in General
Discussion options

You must be logged in to vote

Hi! You may just need to allow your domain name in your CA provisioner configuration. See the domains option in the OIDC provisioner documentation for more. If you want, you can access other custom claims from the token and use them in certificates, using CA templates.

Also, for a more complete IdP integration (with SCIM syncing), you might benefit from Smallstep SSH. Feel free to reach out via our chat box on the bottom right of that page, if you want to learn more or get a demo of it.

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by maraino
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants