Viewing profile — firstyear
firstyear
HN member- Joined
- Sat, Oct 16, 2021, 10:12 PM UTC
- HN karma
- 16
- Public activity
- 8 items
- HN profile
- View on Hacker News ↗
About firstyear
No profile information was provided.
Recent public activity
-
comment
Comment #28892125
This is exactly what Kanidm does, and there is already some ideas around application password validation via the LDAP facade.
-
comment
Comment #28892105
Just for you, I fixed up this line in the book to make it clearer. Issue reports about things like this is docs and clarity are always welcome!
-
comment
Comment #28892083
Disclosure: I work on 389-ds at SUSE, so I have a lot to say about LDAP, and why I don't want to re-implement a new LDAP server. As mentioned, the main goal is "all in one" to avoi…
-
comment
Comment #28892065
This is intended to provide oauth2 and oidc, which means you won't need keycloak.
-
comment
Comment #28892056
It depends how you look at it - as a professional LDAP developer, I know the ins and outs pretty well, and the issue is that both LDAP and Kerberos "limit" our thoughts on a design…
-
comment
Comment #28892048
It's Japanese - Kani == Crab. Crab-Identity-Management :)
-
comment
Comment #28892045
The main reason to do Kanidm is that it's "all in one". I've had a lot of experience with FreeIPA and have learnt that the microservice design is hard to test and hard to make reli…
-
comment
Comment #28892036
There actually is a plan and set of designs that worked towards these parts. There was a lot of foundational work, and currently the goal is the integrations on top.