#freeipa

4 posts · Last used 18d

Back to Timeline
Andreas Bulling @abulling@fedifreu.de · Jun 17, 2026
Hey fellow #homelab and #selfhosted users! I am looking for a replacement for our #freeipa setup. We need a simple user management (users, groups, password self-reset), authentication via SSH, and SSO (using OpenID Connect). I found recommendations for #keycloak #kanidm #authentik and #pocketid (the latter in combination with #lldap) but it seems these not only differ substantially in functionality but are also for different purposes?! Some can even be combined as not all of them provide identity and access management?! Could one of you bring some light into the darkness for what (and, in case, in which combination) these are to be used for? I'd also highly appreciate recommendations and/or to learn from your own experience running any of these services. We'll be dealing with around 50 user accounts. Thanks a lot in advance! #boost welcome
5
1
3
Andreas Bulling @abulling@fedifreu.de · Jun 26, 2026
Replying to @abulling@fedifreu.de
Quick update - after evaluating the different options I settled on #kanidm It offers everything that we need, is light-weight, and is mainly managed through the CLI (yes, that's an advantage from my point of view). It comes closest to #FreeIPA in terms of functionality and all that without requiring any additional services or extras. I've already installed a test server and managed to set up #OIDC for all services. Basic authentication is working fine but I still have to test group membership handling, particularly also for new users. Same for SSH login and POSIX user/group features. OIDC for #nextcloud was a bit of a hassle as its internal UIDs were non-standard. I had to manually change them for all users in the database and filesystem. To be continued...
4
1
0
Andreas Bulling @abulling@fedifreu.de · Jul 27, 2026
Replying to @abulling@fedifreu.de
It's been a while since my last post and a lot has happened. Hence, a quick update. I've fully migrated from #freeipa to #kanidm by now and while this path was definitely not without (also major) problems and a lot of back and forth also with the developers, I overall don't regret the decision at all. While kanidm arguably falls behind in popularity/visibility compared to #authentik, #keycloak, etc and seemingly also has (much?) less developers, and development therefore feels slower, it scores with simplicity and by offering exactly what I need. See here for a quick comparison: https://kanidm.com/comparisons/ I have around 10 services connected to it and all is working fine (finally now). What is a bit annoying about OIDC is that not all services offer OIDC out of the box, i.e. sometimes additional plugins are needed. The other annoying thing is that OIDC implementations differ, e.g. in how group mapping are used (if at all). If you are looking for a one-stop solution that offers OIDC, SSH key provisioning and replication - don't look any further.
0
0
0
tod @tod@mastodon.tod.net · Jul 03, 2026
Part 5 of my homelab downsizing series: a week building the wrong cert automation (acme-proxy — turns out it doesn't support Cloudflare DNS-01), then six days and three attempts standing up FreeIPA as a subordinate CA before shelving it for Samba AD. Two burned signing ceremonies, one silently-discarded private key. #homelab #pki #freeipa #selfhosted https://homelab.tod.net/posts/downsizing-the-homelab/pki-decision-journal/
0
0
0

You've seen all posts