LDAP is such a pain in the ass to integrate with, and it seems like most things are going OIDC these days.
LDAP is such a pain in the ass to integrate with, and it seems like most things are going OIDC these days.
Kerberos, yes, but LDAP no.
What are your pain points integrating with LDAP? It is pretty simple.
LDAP is a pain because you have to expose/support a lot of knobs for integration (bind vs anonymous, secure vs unsecure, group format, root DNs, etc.). OIDC is (in theory) a lot simpler for the most part as the bare minimum is discovery URL, client ID, and client secret.
I've been avoiding LDAP like the plague. I think MS is moving away from self-hosted AD, and LDAP really loses its luster for most folks when the self hosted options are something like OpenLDAP.
And the parent makes a good point that OIDC/OAuth does not give group membership.