| Age | Commit message (Collapse) | Author |
|
Kanidm development is kind of slow and conservative. Their frontend is
lacking.
The hope was Zitadel would solve some issues logging in to the Home
Assistant app behind oauth2-proxy, but it doesn't really help. In
particular, KeePassium is unable to password complete (login page
reloads to username entry?).
In any case, we probably prefer Zitadel so let's at least record it for
now. Pocket ID is an interesting minimal alternative, but the Home
Assistant app doesn't support passkeys.
$ sudo rm -r /var/lib/kanidm/
|
|
Keycloak has always been heavyweight and cumbersome. Kanidm is meant to
be an all-in-one Rust identity provider instead.
$ sudo kanidmd recover-account idm_admin
$ kanidm login --name idm_admin
$ kanidm group account-policy credential-type-minimum idm_all_persons any
$ kanidm person create joe Joe
$ kanidm person credential update joe
$ kanidm system oauth2 create oauth2-proxy 'OAuth2 Proxy' https://op.mou.fo
$ kanidm system oauth2 update-scope-map oauth2-proxy idm_all_persons openid profile email
$ kanidm system oauth2 show-basic-secret oauth2-proxy
Passkeys don't work with KeePassXC on Firefox. They might work with
Chrome or BitWarden. We disable TOTP for password authentication.
Kanidm itself has considered and rejected forward auth support per
https://github.com/kanidm/kanidm/issues/2774
With this arrangement session cookies are about 2k. While large these
should fit within the default nginx buffers.
Dex can be used as a simple identity provider, although it is more
designed to facilitate app authentication. It can be configured to have
a workable configuration with no persistent state and only staticClients
and staticPasswords for resource servers and users.
Vouch Proxy is comparable with oauth2-proxy. Both assume the user has an
e-mail which we don't use. However oauth2-proxy seems to have better
workarounds and is somewhat more actively maintained. Vouch Proxy also
lacks a NixOS module.
https://discourse.nixos.org/t/configuring-vouch-proxy-or-oauth2-proxy-nginx-nix/19337/2
https://github.com/vouch/vouch-proxy/issues/309
|
|
To resolve database collation version mismatches ("The database was
created using collation version 2.38, but the operating system provides
version 2.39."):
$ sudo -u postgres psql
> \c hass
> REINDEX DATABASE hass;
> ALTER DATABASE hass REFRESH COLLATION VERSION;
[ Repeat for all databases (except special database template0) ]
|
|
|
|
Clarifies that they are not managed by a distribution package.
|
|
|
|
|