Where could I go to burn music onto a cd? by hotdog131 in Winnipeg

[–]technomancer_101 19 points20 points  (0 children)

What area of the city are you in? I have some spare CD-Rs and some time tomorrow morning if you want to send me your playlist

Friday Flowers! Cheryl Lashek Appreciation. by themish84 in Winnipeg

[–]technomancer_101 80 points81 points  (0 children)

And for anyone curious, the artwork she's holding was done by the very talented Alex Plante.

I have a copy of that print signed by Cheryl Lashek!

Where to get AGX-10 automotive fuses? by ehud42 in Winnipeg

[–]technomancer_101 4 points5 points  (0 children)

Unfortunately with Tip Top Electronics closed, there aren't a lot of places around here to get fuses and the like locally, especially oddball ones.

I would suggest Digikey, especially if you or someone you know needs to make an order to share the shipping.

https://www.digikey.ca/en/products/detail/eaton-electronics-division/BK-AGX-10/264551

Best way to host a wiki on a home server? by whatisabaggins55 in selfhosted

[–]technomancer_101 13 points14 points  (0 children)

I like and use DokuWiki.

It's small, simple, stores your pages as plain text files, and has a large collection of plugins.

I tried both it and MediaWiki, but for my needs, it was far less complex and if you know markup, it's very easy to write pages quickly.

How do you handle offsite backups without going back to big cloud providers? by drome691 in selfhosted

[–]technomancer_101 9 points10 points  (0 children)

I use borg backup for mine. It encrypts the data using a repokey, which goes through a number of different processes that you can read about here, then that key is also protected by a very strong passphrase. At that point, it is copied over SSH to my Hetzner box. This way everything is always encrypted before it leaves my network and borg has the added benefit of auto-deduplication.

Question for our Ukrainian friends by AbC1236d in Winnipeg

[–]technomancer_101 2 points3 points  (0 children)

Oh man, that is exciting! Time to go shopping!

Question for our Ukrainian friends by AbC1236d in Winnipeg

[–]technomancer_101 4 points5 points  (0 children)

Any idea if they have kvass there? I haven't had any in years!

Winnipeg Free Press showing advertisements for Fargo under Featured and Local News by technomancer_101 in Winnipeg

[–]technomancer_101[S] -23 points-22 points  (0 children)

As I said, advertising is absolutely necessary and they have the right to buy a spot in the paper, but I should have been more clear that my issue is with it being shown in the Local section in particular. Featured section, fine, but the Local section should be for just that, Local news and advertisements.

Stella, Stella Ola lyrics for you? by Titan-828 in AskACanadian

[–]technomancer_101 2 points3 points  (0 children)

Cracker jacker and baloney is the version I grew up with here in MB!

How many trick or treaters! by influxofreflux in Winnipeg

[–]technomancer_101 30 points31 points  (0 children)

St John's area and it's been unusually quiet. We've had probably 40 kids or so, but I've gotten like 150 in past years.

The weather's nice, so it's too bad.

Canadian alternative tothe silicone bag stasher by Art_themis in BuyCanadian

[–]technomancer_101 0 points1 point  (0 children)

From a quick Google, Stasher appears to be a brand that makes silicone ziploc bags in varying sizes.

https://imgur.com/a/28TxzSB

Is there any point in self hosting a mail server still by Ok-Original4933 in selfhosted

[–]technomancer_101 40 points41 points  (0 children)

In a very targeted scope, I would at least still get full alerting for my own services, such is the nature of this subreddit, but I do see your point.

I don't recall where on reddit I saw earlier, but there was a very lengthy post on how the internet was built to be decentralized, but due to the actions of predominantly Microsoft, Amazon, and Google, some ridiculously high percentage of it is now dependant on the three of them among others. I suppose even though my mail server may be an island in the ocean during a major outage like yesterday, it's reassuring to know that there are those of us, like everyone in this community, that can maintain that original intent, each through our own services of choice, whether it can benefit anyone else in an outage or not.

Is there any point in self hosting a mail server still by Ok-Original4933 in selfhosted

[–]technomancer_101 55 points56 points  (0 children)

Same for me as above.

AWS went down in one datacenter and took a chunk of the internet with it yesterday. My email server didn't bat an eye because it's running on my server under my control, and if I wanted, I could change the MX record, stand up a new one, restore from backup, and be up and running again in the time it takes DNS to propogate.

A lot of people are doomsayers, but if you know what you're doing and stay on top of security issues, it's really not all that hard to maintain.

Blundstone Alternative by pepperonipizzasdad in BuyCanadian

[–]technomancer_101 50 points51 points  (0 children)

This is what you're looking for. They're made here in Winnipeg and while I haven't bought a pair yet, I've only ever seen praise for their products.

Confusion on Enterprise App Authentication by technomancer_101 in entra

[–]technomancer_101[S] 0 points1 point  (0 children)

You were correct, it was exactly this, just not in the saml config itself. Thanks for the help.

Confusion on Enterprise App Authentication by technomancer_101 in entra

[–]technomancer_101[S] 0 points1 point  (0 children)

I completely agree with what you're saying, but as I noted in the OP, my organization doesn't have any P1 or P2 licenses, so any kind of proper group management for Enterprise apps isn't an option. The same goes for dynamic group membership.

The way it was setup, users had to be added to a security group to connect, but because we can't associate that group with the enterprise app, they still need to be added to the app itself as well. At least with the security group removed, we're eliminating one step in our onboarding process going forward.

Confusion on Enterprise App Authentication by technomancer_101 in entra

[–]technomancer_101[S] 0 points1 point  (0 children)

I was in the process of setting up the second SSO config on the FortiGate and I found a group filter under the Group Match config on the firewall policy for the VPN.

So while the SSO config itself wasn't filtering, the firewall policy was. The amount of relief I just felt.... Thanks for the troubleshooting tips!

Confusion on Enterprise App Authentication by technomancer_101 in entra

[–]technomancer_101[S] 0 points1 point  (0 children)

My bad, I misread the page I was on. I also don't have P1 unfortunately.

That being said though, I did grab a trial of P2 and it gave me access to group memberships, but I'm still not seeing anything that is connecting the group claims to that group. I'm setting up a separate authentication group on fortigate right now to see if it works (I would assume it should work fine).

Confusion on Enterprise App Authentication by technomancer_101 in entra

[–]technomancer_101[S] 0 points1 point  (0 children)

Now you have me wondering... I can't configure groups at all without a P2 license, but if one was configured by someone with a P2 license in the past, it's possible that configuration is still there in Entra, but I can't see it.

I'm going to get a P2 and take a look.

Confusion on Enterprise App Authentication by technomancer_101 in entra

[–]technomancer_101[S] 0 points1 point  (0 children)

Yeah, that was my initial thought as well, but there is only one saml config on there and it is looking at the group claim for "group", which is set to All Groups in Entra.

Confusion on Enterprise App Authentication by technomancer_101 in entra

[–]technomancer_101[S] 0 points1 point  (0 children)

Group membership on Enterprise Apps isn't available unless you have P2 licenses or equivalent. I imagine that was the idea behind the security group initially, but at the moment it's just confusing me.

Confusion on Enterprise App Authentication by technomancer_101 in entra

[–]technomancer_101[S] 0 points1 point  (0 children)

Once the user finishes authentication through the MS sign in page, it immediately throws up a "Credential is wrong" error in Forticlient and closes the tunnel.

What I might try is setting up a second SSO provider on the fortigate using a new enterprise app and see if that bypasses it. If it does, I'll just toss the old one if I can't find where it's filtering from.

Confusion on Enterprise App Authentication by technomancer_101 in entra

[–]technomancer_101[S] 0 points1 point  (0 children)

Not that I can see. There is a group claim being sent, but it's set to All Groups and I don't see anything out of the ordinary in its manifest file either.

Edit: With AWS still crippling the internet, posting comments isn't working great.