Files
oauth2-proxy/docs/versioned_docs/version-7.15.x/configuration/providers/cisco_duo.md
T
github-actions[bot]andJan Larwig 96c9ec6986 release v7.15.0 (#3378)
* add new docs version 7.15.x

* update to release version v7.15.0

* doc: changelog for v7.15.0 and extended docs for additional claims

* ci: fix trivy failure for release PR

---------

Signed-off-by: Jan Larwig <jan@larwig.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Jan Larwig <jan@larwig.com>
2026-03-19 01:10:21 +08:00

1.3 KiB

id, title
id title
cisco_duo Cisco Duo

Cisco Duo SSO can be configured with OAuth2 Proxy using the OIDC provider.

  1. Create a new Generic OIDC Relying Party - Single Sign-On application in the Duo Admin Portal
  2. Configure OAuth2 Proxy with the following options:
provider = "oidc"
provider_display_name = "Duo SSO"
scope = "openid email profile"
pass_access_token = true
code_challenge_method = "S256"
  1. Configure Provider endpoints. Copy the following values from the corresponding fields in the Duo Admin Portal:
# Copy from "Client ID" field
client_id = "XXXXXXXX"

# Copy from "Client Secret" field
client_secret = "XXXXXXXX"

# Copy from "Issuer" field
oidc_issuer_url = "https://sso-xxxxxxxx.sso.duosecurity.com/oidc/xxxxxxxx"

# Copy from "JWKS URL" field
oidc_jwks_url = "https://sso-xxxxxxxx.sso.duosecurity.com/oidc/xxxxxxxx/jwks"

# Copy from "Token Introspection URL" field
validate_url = "https://sso-xxxxxxxx.sso.duosecurity.com/oidc/xxxxxxxx/token_introspection"

# Copy from "UserInfo" field
profile_url = "https://sso-xxxxxxxx.sso.duosecurity.com/oidc/xxxxxxxx/userinfo"

# Copy from "Token URL" field
redeem_url = "https://sso-xxxxxxxx.sso.duosecurity.com/oidc/xxxxxxxx/token"
  1. Complete Configuration by filling in any remaining required fields and save your configuration.