diff options
| author | Joe Mou <dev@mou.fo> | 2024-07-02 18:07:28 -0400 |
|---|---|---|
| committer | Joe Mou <dev@mou.fo> | 2024-10-09 13:48:41 -0400 |
| commit | 26479ad1b9e441bd45642cf70a47e92f11cd6b32 (patch) | |
| tree | 4caaa7e020334b9a5f4ee900c60fb22a094c73aa /hostnix/weebnix | |
| parent | 19805b91322878264cc235c880c04fdabafa0949 (diff) | |
Replace Keycloak with Kanidm
Keycloak has always been heavyweight and cumbersome. Kanidm is meant to
be an all-in-one Rust identity provider instead.
$ sudo kanidmd recover-account idm_admin
$ kanidm login --name idm_admin
$ kanidm group account-policy credential-type-minimum idm_all_persons any
$ kanidm person create joe Joe
$ kanidm person credential update joe
$ kanidm system oauth2 create oauth2-proxy 'OAuth2 Proxy' https://op.mou.fo
$ kanidm system oauth2 update-scope-map oauth2-proxy idm_all_persons openid profile email
$ kanidm system oauth2 show-basic-secret oauth2-proxy
Passkeys don't work with KeePassXC on Firefox. They might work with
Chrome or BitWarden. We disable TOTP for password authentication.
Kanidm itself has considered and rejected forward auth support per
https://github.com/kanidm/kanidm/issues/2774
With this arrangement session cookies are about 2k. While large these
should fit within the default nginx buffers.
Dex can be used as a simple identity provider, although it is more
designed to facilitate app authentication. It can be configured to have
a workable configuration with no persistent state and only staticClients
and staticPasswords for resource servers and users.
Vouch Proxy is comparable with oauth2-proxy. Both assume the user has an
e-mail which we don't use. However oauth2-proxy seems to have better
workarounds and is somewhat more actively maintained. Vouch Proxy also
lacks a NixOS module.
https://discourse.nixos.org/t/configuring-vouch-proxy-or-oauth2-proxy-nginx-nix/19337/2
https://github.com/vouch/vouch-proxy/issues/309
Diffstat (limited to 'hostnix/weebnix')
0 files changed, 0 insertions, 0 deletions
