From f10c3ba0ea43a1ae3385a91bc4ebbcb3aeb2a462 Mon Sep 17 00:00:00 2001 From: Joe Mou Date: Wed, 16 Apr 2025 13:33:47 -0400 Subject: Try setting up glauth LDAP, for some reason If we wanted an LDAP server, glauth seems like a pretty good pick. It's lightweight and can be configured entirely by a stateless text config (it also supports a sqlite backend; it doesn't appear they can be used together though). But do we really benefit from an LDAP server? It could help set up services that have LDAP authentication but not OIDC (most services that use oauth2-proxy). Perhaps we'll revisit this. glauth docs are spotty, but these are relevant for the config file: - https://glauth.github.io/docs/file.html - https://github.com/glauth/glauth/blob/master/v2/sample-simple.cfg Nix has envsubst and replace-secret to include secrets in the config. Information on setting up MFA: https://www.couchbase.com/blog/multi-factor-authentication-mfa-2fa/ If we bind to an address besides localhost we should also set up LDAPS. --- hostnix/elmo/oidc.nix | 8 ++++++++ 1 file changed, 8 insertions(+) (limited to 'hostnix/elmo/oidc.nix') diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix index 88f8e9a..4421eb9 100644 --- a/hostnix/elmo/oidc.nix +++ b/hostnix/elmo/oidc.nix @@ -1,6 +1,14 @@ { lib, pkgs, ... }: { + systemd.services.glauth = { + wantedBy = [ "multi-user.target" ]; + serviceConfig = { + DynamicUser = true; + }; + script = "${pkgs.glauth}/bin/glauth -c ${./glauth/glauth.toml}"; + }; + services.dex = { enable = true; settings = { -- cgit v1.3.1