Modernizing Authentication with the New NCAS Captive Portal Flow

Options
Zyxel_Lynn
Zyxel_Lynn image  Zyxel Employee
5 Answers First Comment Friend Collector First Anniversary
edited August 14 in Other Topics

Modernizing the NCAS Captive Portal Flow

Nebula Cloud Authentication Server (NCAS) has been updated to follow a standardized OIDC-based flow, matching the security architecture of NID FS. This modernization introduces support for biometric passkeys and refined site privilege checks.

New NCAS Authentication Workflow

  • Authentication: The IFS platform hosts the new login page, redirecting users to the NCAS server. This page supports standard credentials and the "Continue with Passkey" option.


  • Authorization: The AP verifies the user's site privilege, which includes checking authorized sites, account expiration times, and enrollment status.



  • Access Control: Successful users reach the network, while failed users see a customizable error page.

Operational Changes

With the new flow, the NCAS Disconnect Behavior setting is no longer supported. If an AP loses its connection to the NCAS server, it will automatically block traffic for non-authenticated users to prevent unauthorized access. This is a significant change from the legacy flow where "Allow" could permit access during outages.

Customization

Unlike third-party OIDC providers, NCAS still allows administrators to customize the login theme and text additions. A new Error Page has been added to the customization menu, allowing for script-based modifications to the message shown when authorization fails.