Modernizing Authentication with the New NCAS Captive Portal Flow

Options
Zyxel_Lynn
Zyxel_Lynn Posts: 212
5 Answers First Comment Friend Collector First Anniversary
image  Zyxel Employee
edited September 17 in Other Topics

Modernizing the NCAS Captive Portal Flow

Nebula Cloud Authentication Server (NCAS) has been updated to follow a standardized OIDC-based flow, matching the security architecture of NID FS. This modernization introduces support for biometric passkeys and refined site privilege checks.

New NCAS Authentication Workflow

  • Authentication: The IFS platform hosts the new login page, redirecting users to the NCAS server. This page supports standard credentials and the "Continue with Passkey" option.


  • Authorization: The AP verifies the user's site privilege, which includes checking authorized sites, account expiration times, and enrollment status.



  • Access Control: Successful users reach the network, while failed users see a customizable error page.

Operational Changes

With the new flow, the NCAS Disconnect Behavior setting is no longer supported. If an AP loses its connection to the NCAS server, it will automatically block traffic for non-authenticated users to prevent unauthorized access. This is a significant change from the legacy flow where "Allow" could permit access during outages.

Customization

Unlike third-party OIDC providers, NCAS still allows administrators to customize the theme and text additions for the login page such as success page, Error Page, click-to-continue page. Error page is a new page that has been added to the customization menu, allowing for script-based modifications to the message shown when authorization fails.

Please note that since the login page is fully managed by the NID FS platform, it cannot be customized when using the new NCAS sign-in flow. Currently, customization is only available for the Click-to-Continue login page.