Generate a client secret:
authelia crypto hash generate pbkdf2 --variant sha512 --random --random.length 72 --random.charset rfc3986
Random Password goes to Trilium, Digest (the
$pbkdf2-sha512$…string) goes to Authelia.
Add a client under identity_providers.oidc.clients in
Authelia's configuration.yml, replacing
<server>with the URL of your Trilium instance:
identity_providers:
oidc:
clients:
- client_id: 'trilium'
client_name: 'Trilium'
client_secret: '<Digest>'
public: false
authorization_policy: 'two_factor'
redirect_uris:
- 'https://<server>/callback'
scopes:
- 'openid'
- 'profile'
- 'email'
Unlike GitLab, client_id is a name you choose
rather than one the provider generates.
Restart Authelia.
Adjust config.ini, using the Random Password from
step 1:
[MultiFactorAuthentication]
oauthBaseUrl=https://<server>
oauthClientId=<ClientId>
oauthClientSecret=<RandomPassword>
oauthIssuerBaseUrl=https://<server>
oauthIssuerName=Authelia
https://<server>/callback
Adjust config.ini as follows, replacing
<ApplicationId>and <Secret> with
the values from the last step as well as the <server> with
a URL to your Trilium instance.
[MultiFactorAuthentication]
oauthBaseUrl=https://<server>
oauthClientId=<ApplicationId>
oauthClientSecret=<Secret>
oauthIssuerBaseUrl=https://gitlab.com
oauthIssuerName=GitLab
oauthClientAuthMethod=client_secret_post
Create the client, add the redirect URL and grant the scopes, replacing
<server>with the URL of your Trilium instance and <group> with
an existing Kanidm group whose members may sign in:
kanidm system oauth2 create trilium "Trilium" "https://<server>"
kanidm system oauth2 add-redirect-url trilium "https://<server>/callback"
kanidm system oauth2 update-scope-map trilium <group> openid profile email
The openid scope is mandatory; without it
Kanidm treats the client as plain OAuth 2.0.
Read the client secret:
kanidm system oauth2 show-basic-secret trilium
Adjust config.ini as follows, replacing
<idm>with the URL of your Kanidm instance and <BasicSecret> with
the value from step 2:
[MultiFactorAuthentication]
oauthBaseUrl=https://<server>
oauthClientId=trilium
oauthClientSecret=<BasicSecret>
oauthIssuerBaseUrl=https://<idm>/oauth2/openid/trilium
oauthIssuerName=Kanidm
The client name you chose in step 1 is both the client ID and the last path segment of the issuer URL, so the two must match.
https://<server>/callback,
replacing <server> with the URL of
your Trilium instance.Adjust config.ini as follows, using the
values from step 4:
[MultiFactorAuthentication]
oauthBaseUrl=https://<server>
oauthClientId=<ClientID>
oauthClientSecret=<ClientSecret>
oauthIssuerBaseUrl=<OIDCDiscoveryURL>
oauthIssuerName=Pocket ID
GitHub cannot be used as an identity provider because it is plain OAuth
2.0 and not OpenID Connect, so it will fail with OAUTH_RESPONSE_IS_NOT_CONFORM.
https://<server>/callback.Adjust config.ini as follows, replacing
<ClientID>and <ClientSecret> with
the values from the last step as well as the <server> with
a URL to your Trilium instance.
[MultiFactorAuthentication]
oauthBaseUrl=https://<server>
oauthClientId=<ClientID>
oauthClientSecret=<ClientSecret>