Hey, we tried to migrate from 2.58.4 in staging to 3.1.0 but the SSO Login was disabled because it is only in the PRO Model anymore, right? But how to login with the existing SSO Users? I cant set a password for them and cant even delete them to register them. What is the best way to get them to work?
Hi Kristoffer, Thank you for raising this issue. To address it, I have submitted a PR to document the recommended procedure: github.com/DefectDojo/django-DefectDojo/pull/15167
Hey, thank you very much for the documentation. This is rather a hack to modify them than a fix itself. We have 50+ users from SSO, is this the only recommended way? I think we will stay at 2.58.4 forever then 😄
Another take: If you have a lot of users getting a great deal of value from a tool, especially a security tool, why not consider paying for it? 😉
Folks Cody M. Greg A. I understand that SSO is a main feature of any paid version of software, but SSO was already on the OSS version and the decision of removing that has left plenty of SSO users in the darkness with this. Would be great to review this, as now, we won't be migrating to 3.X because of this.
I would appreciate to review this and at least leave a SSO option (Google?) for SSO and provide a proper migration path otherwise...
Hi mbelarde. I'd appreciate you not pulling Cody or Valentijn into this. They work incredibly hard for this community, and I'm the one who made the decision. The full details are in DefectDojo v3 - A New Chapter for the OWASP Edition.pdf. We held office hours discussing different avenues before settling on this route, I've done my best to be clear and transparent about the why, and the move has drastically helped the economics. I empathize with your frustration, but no one offered up a reasonable alternative, and I believe that's because one doesn't exist: if the conversion metrics aren't sustainable, there aren't other viable options. We did weigh the other paths. If we stopped supporting the Jira integration instead, that would hit small teams hardest. If we stopped supporting deduplication or auto-triage via reimport, both would impact far more of the community. Everything else we looked at had the same problem. Choosing not to support RBAC and SSO in v3 was the option that affected the fewest users while also making the platform easier to maintain: supporting integrations with identity systems we don't control or have access to is resource intensive. We offer a free tier of Pro to non-enterprise teams that qualify. It gives the community cross-tool deduplication, root cause analysis with correlation, threat intel, reachability, auto-remediation, a new UI, astronomical performance gains, the list goes on. I made these changes so that Dojo is still here years from now. A sustainable company is what funds the platform, the OSS edition included. You're welcome to stay on v2. It's still available and accessible, and everything you're running today keeps working as it always has. The reasons SSO didn't carry into v3 are laid out in the letter.
Understood sorry about that and thanks Greg A. won't pull anyone else from the team on the chats. I can't talk for everyone else on the community, but I am pretty much sure many (as Rajat R.,Kristoffer P. and Seth and maybe other surely) might be frustrated with the fact that this will only mean that v2 will not have any improvements and v3 will, whilst key features that were open source are now removed.
Question on staying on v2? What would that mean? Would v2 will have vulnerability fixes? Will it be abandoned or add key features? Or none of the that?
Will this happen with other OSS-time-dev in the future?
If you are touching on this topic on the office hours I am happy to listening to a recording or try to make it, but might be challenging with the timezone differences. I do understand your side, 100%. But also it is difficult to swallow the fact that SSO and Jira integration were features created for the OSS version too. Removing that now is hard for OSS users and contributors, feels like it is a move that forced us into take a decision that might be 50/50 good or bad for DD development. I am sure there are other features for which Pro is worth it.. why not to keep those on the bait rather than these?
Thank you mbelarde, I appreciate that. Below are answers to your questions, and I'm sorry, but this will have to be my final reply here so I can get back to building. Dojo is going through rapid growth (we just crossed 50M downloads) and there's a lot to do. Staying on v2: nothing changes for existing deployments. v2 stays available and keeps working as it does today. It won't get new development from us though; active work, security fixes included, happens in v3. On OSS improvements: the OSS edition is not frozen and not going away. It continues in v3, and it's getting real investment. Since the last v2 release, OSS v3 has added 42 new tool integrations, taking it from 215 to 257 supported tools, and every one of the 215 from v2 is still there. That's on top of the new UI and other new areas of the platform. And to clear up one thing in your message, the Jira integration was not removed. Choosing RBAC and SSO is what let us keep it. On whether more features move later: the point of doing this once, and doing it the way we did, was to make the economics stable enough that we don't have to keep revisiting what's in the OSS edition. There is no list of features waiting to move. On why SSO and RBAC rather than others: that's the tradeoff analysis in my earlier message and the letter, so I'll point you there rather than re-run it. For anything beyond this, office hours is the place, and you're welcome any time.

