HashiCorp Vault - Amalgamating multiple aliases under a single entity after login via multiple OIDC auth methods and user ids

Viewed 41

We're trying to implement OIDC single sign-on to our HashiCorp Vault instance, through the following multiple auth methods:

  1. Azure AD (user authentication is through the individual's corporate email address)

  2. LDAP (user authentication is through a unique corporate personal identification number)

Each user within the organisation will have an account in both Azure and LDAP and so to avoid a single user being registered under two separate Vault entities (thereby taking up 2 Vault licences), it is imperative that we device a mechanism where the two designated Vault aliases for Azure AD and LDAP are amalgamated under one single Vault entity.

At the moment this is proving a challenge, due to the fact both auth methods used in our OIDC single sign-on implementation, rely on two entirely different identifiers for authentication:

  • a user email, and
  • a personal id number

As such, if say Joe Bloggs logged into our Vault instance using joebloggs@my-org.com (Azure AD) and joebloggs12345 (LDAP), Vault has no way of identifying them both as the same individual, in order to create both aliases under a single entity.

Any idea how we could automate the amalgamation of the two Vault auth method aliases under one entity?


1 Answers
Related