u/Heracles_31

▲ 27 r/PFSENSE

pfSense's new UI does not work for me...

After a review of the new UI, I already discarded it :

1-Despite SAML is listed as a type of Authentication Server, we can not configure one...

2-I use HAProxy for both Internet and local services but HAProxy is nowhere to be found in the new UI...

3-Despite I fixed the problem about the missing serial number in the BIOS of my Proxmox VM, the new UI keeps complaining that it is not licensed...

4-Basic tasks like package management are not accessible because the new UI says that this feature is restricted to properly licensed installations

5-Same for update management

So with all of this already identified, it is clear that I will have to use the original UI for many basic and essential tasks. As such, there is no reason to log in and out from new to old to new according to what I need to do. That new interface is far to be complete and ready, so I will stay with the good old one...

EDIT: Great! Now it broke my entire licensing, even in the old UI. I can no longer check for updates because pfSense says that my system is not properly licensed but when I go in Register in the System menu, it says that I do not need to register because the installation is already recognized as legitimate.

Really, do not even try the new UI or you may brake and lose your license like me!

reddit.com
u/Heracles_31 — 8 days ago
▲ 12 r/PFSENSE

A missed opportunity for centralized authentication

Experiencing the new user interface here and I am surprised by what I discovered. One one side, pfSense finally supports centralized authentication and SSO but on the other side, it has been implemented with SAML instead of OpenID...

My Keycloak server supports SAML as well and I do have 2 softwares that are still using SAML only. But the truth is that OpenID replaced SAML a long time ago and that the vast majority of tools are now using it.

So... good to have half-a-solution instead of nothing for now but still, the real need is for OpenID and we are still waiting for that one. I have no clue why Netgate did the work for an outdated technology instead of the new standards but well...

EDIT: It looks like I celebrated too quickly... The UI shows about SAML authentication servers but you can not create a new one...

reddit.com
u/Heracles_31 — 8 days ago