RADIUS authentication integration with an admin portal, multi-factor authentication, and enterprise identity provider support.
RoXX does not listen for RADIUS packets on UDP 1812 by itself. Deploy FreeRADIUS with the documented rlm_python3 integration for RADIUS clients; roxx server runs the administration web service.
Website: https://tsautier.github.io/RoXX/ - overview, downloads, and operator guide.
- RADIUS Integration: FreeRADIUS module and configurable upstream authentication backends
- NPS Migration Assistant: Import tools for effortless transition from Microsoft NPS
- Multi-Backend Support: LDAP, Active Directory, SAML 2.0 SSO, Entra ID
- Admin Portal: Modern web interface with real-time analytics
- RESTful API: Complete API for automation and integration
- β
Multi-Factor Authentication (MFA)
- TOTP/Authenticator Apps
- WebAuthn (Security Keys, Biometrics)
- TrustBuilder/inWebo Push Integration
- SMS (via gateway integration)
- β SAML 2.0 Single Sign-On
- β LDAP/Active Directory / Entra ID Integration
- Visual Dashboard: Real-time authentication charts and health monitoring
- Advanced Visibility: Live log viewer with color-coded event tracking
- User Management: Create, edit, delete admin users
- Audit Logs: Complete system activity tracking
- RBAC:
superadmin,admin, andauditorroles for portal access control
- Python: 3.12 or higher
- Operating System: Linux, Windows 10/11, or Windows Server 2022/2025
- Database: SQLite (included)
- Optional:
- LDAP/AD server for directory integration
- SAML IdP for SSO
- SMS gateway for SMS MFA
git clone https://github.com/tsautier/RoXX.git
cd RoXX
# Create virtual environment
python3 -m venv venv
source venv/bin/activate # On Windows: venv\Scripts\activate
# Install dependencies
pip install .sudo ROXX_CONFIG_DIR=/etc/roxx ROXX_DATA_DIR=/var/lib/roxx ROXX_LOG_DIR=/var/log/roxx \
roxx setup --non-interactive --hostname roxx.example.com
roxx serverThe server uses HTTPS by default and listens on port 8000. Setup creates the initial
superadmin with a unique generated password in
/etc/roxx/initial-admin-credentials.txt (or the configured ROXX_CONFIG_DIR). The file is
restricted to the service account where the platform supports POSIX permissions and is deleted
after the password is changed.
For unattended secret injection, set ROXX_BOOTSTRAP_ADMIN_PASSWORD only while running setup.
The supplied password must satisfy the local password policy and is never written to the
credential file.
Configuration files are located in:
- Linux:
/etc/roxx/ - Development:
~/.roxx/
Key files:
roxx.db- Main SQLite databasewebauthn.db- WebAuthn credentialsmfa.db- MFA configuration
- Read the generated initial credential file as the service account.
- Navigate to
https://localhost:8000. - Sign in and complete the mandatory password change.
RoXX uses three admin roles:
superadminadminauditor
See docs/RBAC.md for the complete permission matrix and role-management rules.
- Go to Settings β MFA Settings
- Choose your method:
- TOTP: Scan QR code with authenticator app
- WebAuthn: Register security key or biometric device
- Complete setup and test login
- Go to Config β Authentication Providers
- Click + Add Provider
- Select SAML 2.0
- Fill in:
- Name: e.g., "Corporate SSO"
- IdP Entity ID: Your IdP's entity ID
- IdP SSO URL: Your IdP's SSO endpoint
- IdP Certificate: x509 certificate from IdP metadata
- Configure your IdP with:
- Metadata URL:
https://your-domain.com/auth/saml/metadata/{provider_id} - ACS URL:
https://your-domain.com/auth/saml/acs/{provider_id}
- Metadata URL:
- Go to Config β Authentication Providers
- Click + Add Provider
- Select LDAP / Active Directory
- Configure:
- Server URL:
ldap://dc.example.com:389 - Base DN:
dc=example,dc=com - Bind DN: Service account DN
- Bind Password: Service account password
- Server URL:
All API requests require authentication via session cookie or API token.
GET /api/admins - List all admin users
POST /api/admins - Create new admin user
GET /api/admins/{username} - Get user details
PUT /api/admins/{username}/role - Change user role
DELETE /api/admins/{username} - Delete user
GET /api/admins/{username}/mfa/status - Get MFA status
GET /api/admins/{username}/mfa/credentials - List WebAuthn credentials
DELETE /api/admins/{username}/mfa/webauthn/{id} - Delete security key
POST /api/admins/{username}/mfa/totp/reset - Reset TOTP
GET /api/auth-providers - List providers
POST /api/auth-providers - Create provider
DELETE /api/auth-providers/{id} - Delete provider
curl --insecure -X POST https://localhost:8000/api/admins \
-H "Content-Type: application/json" \
-d '{
"username": "john",
"password": "SecurePass123!",
"email": "john@example.com"
}'- Protect Bootstrap Credentials: Read the generated credential file only from a trusted console and complete the mandatory password rotation
- Enable MFA: Require MFA for all admin users
- Use HTTPS: Deploy with proper SSL/TLS certificates
- Regular Updates: Keep dependencies up to date
- Audit Logs: Regularly review system audit logs
- API Tokens: Use API tokens instead of passwords for automation
- Network Security: Restrict admin portal access to trusted networks
# Application
ROXX_HOST=0.0.0.0
ROXX_PORT=8000
ROXX_DEBUG=false
# Database
ROXX_DB_PATH=/etc/roxx/roxx.db
# Security
ROXX_SECRET_KEY=your-secret-key-here
ROXX_SESSION_TIMEOUT=3600
ROXX_SECURITY_PROFILE=production
ROXX_SECURE_COOKIES=true
ROXX_HSTS=true
ROXX_ALLOWED_ORIGINS=https://your-domain.com
ROXX_METRICS_TOKEN=your-monitoring-token
# SAML
ROXX_SAML_SP_ENTITY_ID=https://your-domain.comPlace certificates in /etc/roxx/ssl/:
cert.pem- SSL certificatekey.pem- Private key
The application will automatically use HTTPS if certificates are present.
Access the dashboard at /dashboard for:
- CPU utilization
- Memory usage
- Disk space
- Active sessions
- Recent authentication events
Service endpoints:
GET /livezfor liveness.GET /readyzfor local storage, database, and optional dependency readiness.GET /metricsfor Prometheus metrics; setROXX_METRICS_TOKENto protect it.roxx audit export --output audit.jsonlfor SIEM-compatible JSON Lines export.
View comprehensive logs at /logs:
- User logins
- MFA events
- Configuration changes
- API requests
- SAML/LDAP authentication attempts
WebAuthn Not Working
- Ensure using HTTPS or
localhost - Check browser compatibility (Chrome/Edge/Firefox/Safari recommended)
- Verify WebAuthn credentials in browser dev tools
SAML Login Fails
- Verify IdP certificate is correct
- Check SP Entity ID matches IdP configuration
- Review logs at
/config/auth-providers/logs - Ensure SP metadata uploaded to IdP
LDAP Connection Issues
- Verify network connectivity to LDAP server
- Check bind DN and password
- Test with
ldapsearchcommand - Review firewall rules
Enable debug logging:
export ROXX_DEBUG=true
roxx server- Production operations, HA, upgrade and rollback: See
docs/OPERATIONS.md - Deployment: See
docs/DEPLOYMENT_GUIDE.md - SAML Setup: See
docs/saml-setup.md - RBAC: See
docs/RBAC.md
Contributions are welcome! Please:
- Fork the repository
- Create a feature branch (
git checkout -b feature/amazing-feature) - Commit your changes (
git commit -m 'Add amazing feature') - Push to the branch (
git push origin feature/amazing-feature) - Open a Pull Request
This project is licensed under the GNU Affero General Public License (AGPLv3) - see the LICENSE file for details.
This license requires that users who interact with the software over a network must have access to the source code of the exact version they are using, including any modifications.
- FastAPI - Modern web framework
- python3-saml - SAML implementation
- python-ldap - LDAP integration
- webauthn - WebAuthn/FIDO2 support
For issues and questions:
- GitHub Issues: https://github.com/tsautier/RoXX/issues
Built with β€οΈ for secure, scalable authentication