Elektrine lite

← Feed

@jana@social.jsteuernagel.de

Post #1313402

2026-03-30 13:14 UTC

Gonna use a self-signed cert directly for kanidm. Gonna give the crt to Caddy for verification and then it'll generate the LE for outside exposure. Now what's left to figure out is the exact domain structure, with regards to multiple replicas. The wiki has an example, which lists origin, domain name and hostnames, but I'm a bit confused about the hostnames part and what exactly I would now create DNS records for :neobot_woozy:

Replies (3)

  • @jana@social.jsteuernagel.de 2026-04-03 07:56

    Progress on kanidm :3 I finally managed to generate a self-signed cert. It shouldn't have been this hard, but I was trying to be fancy and ran into all kinds of weird issues. Now it's a plain RSA 2048 cert, which Caddy trusts explicitly, and it works. Currently installing the kanidm client tools and starting with user setup. I think I figure out hostnames and stuff, but I am also not 100% sure, so I'll see if it works as expected.

    Open ##1313403

  • @evilham@fedi.unchat.cat 2026-03-30 14:20

    @jana hah, I want to see how this pans out. This has been on my TODO for a while, and after studying the docs of a lot of IDPs, I too had landed on kanidm. I find it cool that we seem to be reaching very similar conclussions when it comes to infra :-) thanks for sharing your rides!

    Open ##1313434

  • @arichtman@eigenmagic.net 2026-04-03 12:38

    @jana you will want to allowlist the header like x-kanidm-opid or the logging uuids aren't useful (iirc, it's on a github issue somewhere)

    Open ##1313435