What do you use for SSO in your #homelab?
I'm currently using #Keycloak with #FreeIPA as an auth backend, but I find keycloak to be a pain to look after, and it's quite memory hungry.
I was looking at #authentik, and it seems interesting.
#homelab #keycloak #freeipa #Authentik
My #slac2023 talk about #freeipa and external Identity Provider is now online. https://www.heinlein-support.de/slac/2023/vortrag/freeipa-und-anbindung-externe-identity-provider
Trying to get some sort of centralized management of users.. On the recommendation of some, I chose FreeIPA.. Nothing short of a pain in the ass 😜 getting it installed on my LXD cluster!! I'm sure it has something todo with me not knowing WTF i'm doing..
#homelab #selfhosting #LXD #freeipa #bullshit
Onko #FreeIPA liian järeä systeemi viisihenkisen perheen tunnuksien hallintaan useissa koneissa?
Lähipiiristä sais noin 10v vanhoja kannettavia, joilla lapset voisi pelaa simppeleitä pelejä. YouTuben videoita ne ei taida enää pyörittää.
My #introduction (since I changed instance):
I am a Norwegian IT-engineer at the University of #Oslo. Originally from #Brazil, I moved to #Norway in 2011.
I work mostly with VMware stuff, but also spend most part of my days configuring #linux images for VDI's, #Nextcloud, #Kerberos, #FreeIPA, #keycloak, etc.
I love #running, #sourdough baking and became #vegan in Feb 2022. I have #glaucoma.
I started https://mastodon.babb.no for friends and colleagues.
#introduction #oslo #brazil #norway #linux #nextcloud #kerberos #freeipa #keycloak #running #sourdough #vegan #glaucoma
Transcript of the talk "How to migrate 6300 computers to GNU/Linux using
Ansible and AWX" at Nerdearla 2022
#ActiveDirectory #Ansible #Automation #AWX #Debian #Deploy #FreeIPA #GitLab #GNU #IaC #Linux #migrate #nerdearla #Proxmox #talks #Ubuntu
#activedirectory #ansible #automation #awx #debian #deploy #freeipa #gitlab #gnu #iac #linux #migrate #nerdearla #proxmox #talks #ubuntu
Transcript of the talk "How to migrate 6300 computers to GNU/Linux using
Ansible and AWX" at Nerdearla 2022
#ActiveDirectory #Ansible #Automation #AWX #Debian #Deploy #FreeIPA #GitLab #GNU #IaC #Linux #migrate #nerdearla #Proxmox #talks #Ubuntu
#activedirectory #ansible #automation #awx #debian #deploy #freeipa #gitlab #gnu #iac #linux #migrate #nerdearla #proxmox #talks #ubuntu
Transcripción de la charla "Cómo migrar 6300 equipos a GNU/Linux usando
Ansible y AWX" en Nerdearla 2022
#ActiveDirectory #Ansible #Automation #AWX #Debian #Deploy #DevOps #FreeIPA #GitLab #GNU #IaC #Linux #migrate #nerdearla #Proxmox #talks #Ubuntu
https://osiux.com/2022-10-20-como-migrar-6300-equipos-a-gnu-linux-usando-ansible-y-awx.html
#activedirectory #ansible #automation #awx #debian #deploy #devops #freeipa #gitlab #gnu #iac #linux #migrate #nerdearla #proxmox #talks #ubuntu
Transcripción de la charla "Cómo migrar 6300 equipos a GNU/Linux usando
Ansible y AWX" en Nerdearla 2022
#ActiveDirectory #Ansible #Automation #AWX #Debian #Deploy #FreeIPA #GitLab #GNU #IaC #Linux #migrate #nerdearla #Proxmox #talks #Ubuntu
https://osiux.com/2022-10-20-como-migrar-6300-equipos-a-gnu-linux-usando-ansible-y-awx.html
#activedirectory #ansible #automation #awx #debian #deploy #freeipa #gitlab #gnu #iac #linux #migrate #nerdearla #proxmox #talks #ubuntu
This is still a work in progress, but I am almost done with this project that I have been wanting to do for many, many months:
https://github.com/oculos/freeipa-postfixadmin
This is a plugin for FreeIPA to emulate the Postfix Admin interface and functionality.
Je ne sais pas si j'ai envie de pleurer ou rire...
Debian ne permet pas d'installer #FreeIPA même en passant par le dépôt experimental parce qu'une dépendance est cassée. Du coup, mon responsable préfère que j'aille chercher les paquets sur le dépôt snapshots (de 2020) où les paquets sont disponibles plutôt que de passer par #Podman ou #AlmaLinux.
Je comprends la volonté d'avoir un parc homogène en termes d'OS, mais étant donné qu'on a déjà du pfsense (routeurs) et du Windows (VeeamBackup)...
Finally back to #berlin for #slac to talk about newly added #oauth2 support in #freeipa which allows user authorization against external identity-providers like #keycloak, #google, #azure or other #idp that support OAuth device authorization grants. https://www.heinlein-support.de/slac/programm
#berlin #slac #oauth2 #freeipa #keycloak #google #azure #idp
For anyone messing around with this, I haven't worked with #FreeIPA (nothing to do with beer), but it looks like a good solution for single sign-on things. It basically integrates #LDAP and #Kerberos, with a nice web interface. That said, while those two things are kind of a pain, I think there's some value in looking at how they work in a little more depth. Not to mention how Linux and other systems do authentication.
today: ran the #fedora qa meeting, sent out the minutes, investigated the morning's #rawhide breakages:
* an iscsi-initiator-utils update with unfulfillable deps (got noticed and fixed by folks on devel@ list around the same time)
* some kind of change which makes anaconda look more 'native' on KDE live images: https://bugzilla.redhat.com/show_bug.cgi?id=2167534 (adjusted #openqa to cope, filed a bug in case it's unintended or undesired)
* an update to resteasy which breaks #freeipa : https://bugzilla.redhat.com/show_bug.cgi?id=2167539
#fedora #rawhide #openqa #freeipa
Did two talks yesterday at #FOSDEM. Both to packed audiences in security devroom and at a main tracks in Le Fontaine room. Today is a day to meet up some people who want to talk about Kerberos, LDAP and the stuff we do. Good conference back to physical presence this year! #sssd #freeipa