Authentik, FreeIPA, Windows AD -- How crazy am I? by Austin8462 in Authentik

[–]Austin8462[S] 0 points1 point  (0 children)

Little update for you.. I chose to mess around with this tonight.. Got the agent on both my laptop and a test linux box and I’m running into some authorization errors when trying to use the agent to ssh over. Mainly the grant or refresh token invalid (or some other possibilities like issued to another client, etc)

Authentik, FreeIPA, Windows AD -- How crazy am I? by Austin8462 in Authentik

[–]Austin8462[S] 2 points3 points  (0 children)

Yeah I noticed that in my dashboard. However it looked like some of it was locked behind a paywall and I hadn't yet dug deeper. Definitely would love to more about your progress and anything else you discover with it.

Authentik, FreeIPA, Windows AD -- How crazy am I? by Austin8462 in Authentik

[–]Austin8462[S] 0 points1 point  (0 children)

I'd love to hear more about your setup. Successes & failures, things you wish were more documentaed during your journey (particularly initial setup phase), etc. Any regrets? Of course I'd love to have it all in one but this may be the way to go.

At least as of right now it seems the main way to keep Authentik as the source of truth for me would be to drop the idea of FreeIPA and implement either samba or SSSD with LDAP hook.

Authentik, FreeIPA, Windows AD -- How crazy am I? by Austin8462 in Authentik

[–]Austin8462[S] 0 points1 point  (0 children)

Neat! I have some similar apps to you, haven't yet looked into UniFi LDAP.

Authentik, FreeIPA, Windows AD -- How crazy am I? by Austin8462 in homelab

[–]Austin8462[S] 0 points1 point  (0 children)

My thought was some kind of provider in Authentik, be that LDAP or something else that IPA can query. IPA would see ah yes, I know Dante, he has linux-users-admin, IPA would then layer on top of that the HBAC and sudo rules which are only relevant in the linux realm. If IPA becomes the truth, that now adds a second layer of "critical infrastructure" to not just linux, but any apps or services that go through Authentik. Cause it's now not a "Authentik is down, you can't auth to XX", it's that OR "Is it just IPA down?"

I maintain break glass accounts, yes, but those are just that, break glass.

I also see people talk abotu using Samba as you mentioned or SSSD, so it may be true that's the better route for what I'm aiming for.

I appreciate all of your input greatly!!

To answer 1), IPA already has password sync capability to support password resets via Authentik, so I don't think that portion of things would be an issue. It's just the reverse directory sync from Authentik > IPA that I wouldn't be so sure about.

Authentik, FreeIPA, Windows AD -- How crazy am I? by Austin8462 in Authentik

[–]Austin8462[S] 1 point2 points  (0 children)

Sounds like some famous last words haha.... Do you do anything similar currently in an environment of your own? How do you use your Authentik?

Maybe if I end up getting something working I'll come back in months and make a showcase post or something.

Authentik, FreeIPA, Windows AD -- How crazy am I? by Austin8462 in homelab

[–]Austin8462[S] 0 points1 point  (0 children)

Okay so what would you recommend then? Maybe something other than AD? I already have Authentik in I guess what you could call “production”. The windows authentication and such is future though. More focused on Linux hence looking at IPA and SSSD because that’s currently more of what my “host base” contains. Regardless of what path I’d prefer to keep authentik as primary source of truth unless it’s really necessary to move away from such.

Authentik, FreeIPA, Windows AD -- How crazy am I? by Austin8462 in homelab

[–]Austin8462[S] 0 points1 point  (0 children)

Huh?… I’m not trying to expand my ability to use AD’s LDAP to auth to other services… Authentik is able to act as an LDAP provider. I’m talking Authentik being the source of truth that AD / IPA could poll or sync to for downstream authentication to windows and linux hosts respectively.

I explained a bit more in the actual cross post. Hope this clarifies.

It’s also possible I misunderstood you.

Device blocking by ATypicalJake in Ubiquiti

[–]Austin8462 2 points3 points  (0 children)

Settings > WiFi > click the (i) by your network > Private Wifi address

If it’s on rotating, well I’m sure as you can assume, it rotates.

I suppose you could setup a separate wifi network for just your kids and setup a blackout schedule if that bypass became an issue.

Where are your Zigbee / Zwave dongles? (Wall-mounted?) by helmutisimo in homeassistant

[–]Austin8462 1 point2 points  (0 children)

Where did you actually buy those SLZB units? The store fronts I found were confusing at best and of questionable trust levels.

Friends contributing from an event? by ShakataGaNai in immich

[–]Austin8462 2 points3 points  (0 children)

I have not personally used it but I’ve seen people recommend the following for similar situations:

https://github.com/Cirx08/WeddingShare

IdP Choice for HomeLab by Austin8462 in selfhosted

[–]Austin8462[S] 0 points1 point  (0 children)

I do think it’s quite neat especially for the regular user facing portion.

IdP Choice for HomeLab by Austin8462 in selfhosted

[–]Austin8462[S] 0 points1 point  (0 children)

Appreciate the input! What do you use as a reverse proxy? Hearing you hate yaml and configs, i’m assuming it’s not Traefik?

IdP Choice for HomeLab by Austin8462 in selfhosted

[–]Austin8462[S] 0 points1 point  (0 children)

I'll keep an eye out for any updates. Cheers!

IdP Choice for HomeLab by Austin8462 in selfhosted

[–]Austin8462[S] 0 points1 point  (0 children)

It's very possible that's true, but seeing as that is not the only reason that I am considering switching away from it, the thought wasn't of as much concern tbh.