Professor of Computer Science at the University of Stuttgart, Germany · #humanist · all-weather #cyclist · #runner (#marathon) · #DIY #photovoltaik & #heatpump · energy cooperative · #homeassistant · #woodworking · #3Dprinting · #linux · #teamwissenschaft here privately, opinions are my own
Andreas Bulling
@abulling@fedifreu.de
fedifreu.de
Hey fellow #homelab and #selfhosted users!
I am looking for a replacement for our #freeipa setup. We need a simple user management (users, groups, password self-reset), authentication via SSH, and SSO (using OpenID Connect).
I found recommendations for #keycloak #kanidm #authentik and #pocketid (the latter in combination with #lldap) but it seems these not only differ substantially in functionality but are also for different purposes?! Some can even be combined as not all of them provide identity and access management?!
Could one of you bring some light into the darkness for what (and, in case, in which combination) these are to be used for?
I'd also highly appreciate recommendations and/or to learn from your own experience running any of these services.
We'll be dealing with around 50 user accounts.
Thanks a lot in advance!
#boost welcome
Andreas Bulling
@abulling@fedifreu.de
Professor of Computer Science at the University of Stuttgart, Germany · #humanist · all-weather #cyclist · #runner (#marathon) · #DIY #photovoltaik & #heatpump · energy cooperative · #homeassistant · #woodworking · #3Dprinting · #linux · #teamwissenschaft here privately, opinions are my own
fedifreu.de
Replying to
@abulling@fedifreu.de
It's been a while since my last post and a lot has happened. Hence, a quick update.
I've fully migrated from #freeipa to #kanidm by now and while this path was definitely not without (also major) problems and a lot of back and forth also with the developers, I overall don't regret the decision at all.
While kanidm arguably falls behind in popularity/visibility compared to #authentik, #keycloak, etc and seemingly also has (much?) less developers, and development therefore feels slower, it scores with simplicity and by offering exactly what I need.
See here for a quick comparison:
https://kanidm.com/comparisons/
I have around 10 services connected to it and all is working fine (finally now).
What is a bit annoying about OIDC is that not all services offer OIDC out of the box, i.e. sometimes additional plugins are needed. The other annoying thing is that OIDC implementations differ, e.g. in how group mapping are used (if at all).
If you are looking for a one-stop solution that offers OIDC, SSH key provisioning and replication - don't look any further.
Marcelo Elizeche Landó
@melizeche@terere.social
Carbon-based life form trying to figure it out Mastodon Software Engineer @ Authentik Security
#PSF Fellow
#DSF Member #Python #Paraguay Organizer #InfoSec Consultant #RemoteWork Bull Terrier Dad También se habla #español :) Boosts==Marriage proposal
terere.social
Hace poco cumplí un año trabajando en #authentik y escribí sobre eso en mi blog
Sobre el proceso, lo que aprendí, qué rompí y algunas cosas más que sentí que quería compartir
https://blog.melizeche.com/mi-experiencia-contribuyendo-a-authentik-un-ano-construyendo-identidad-open-source/
You've seen all posts