Live data from Hacker News

Viewing profile — firstyear

firstyear

HN member
Joined
Sat, Oct 16, 2021, 10:12 PM UTC
HN karma
16
Public activity
8 items

About firstyear

No profile information was provided.

Recent public activity

  1. comment
    Comment #28892125

    This is exactly what Kanidm does, and there is already some ideas around application password validation via the LDAP facade.

  2. comment
    Comment #28892105

    Just for you, I fixed up this line in the book to make it clearer. Issue reports about things like this is docs and clarity are always welcome!

  3. comment
    Comment #28892083

    Disclosure: I work on 389-ds at SUSE, so I have a lot to say about LDAP, and why I don't want to re-implement a new LDAP server. As mentioned, the main goal is "all in one" to avoi…

  4. comment
    Comment #28892065

    This is intended to provide oauth2 and oidc, which means you won't need keycloak.

  5. comment
    Comment #28892056

    It depends how you look at it - as a professional LDAP developer, I know the ins and outs pretty well, and the issue is that both LDAP and Kerberos "limit" our thoughts on a design…

  6. comment
    Comment #28892048

    It's Japanese - Kani == Crab. Crab-Identity-Management :)

  7. comment
    Comment #28892045

    The main reason to do Kanidm is that it's "all in one". I've had a lot of experience with FreeIPA and have learnt that the microservice design is hard to test and hard to make reli…

  8. comment
    Comment #28892036

    There actually is a plan and set of designs that worked towards these parts. There was a lot of foundational work, and currently the goal is the integrations on top.