Cookie Consent by Free Privacy Policy Generator ๐Ÿ“Œ rant: Linux authentication is a freaking dog's breakfast

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š rant: Linux authentication is a freaking dog's breakfast


๐Ÿ’ก Newskategorie: Linux Tipps
๐Ÿ”— Quelle: reddit.com

This rant is a result of frustrations built from circling around the barn looking for something to replace NIS for relatively small (3 to 30 machine) networks. I haven't found an answer I like so I've kept looking trying to figure out if I've missed something. Feel free to ignore this screed.

I'm coming to the conclusion that the best replacement is AD and in my recent experience with AD says it's a dogs breakfast twice recycled. There's a fundamental mismatch between AD and Linux authentication. I think the reason people try to use it is because it happens to have an LDAP interface that you can kind of twist into working with an LDAP schema on Linux.

If that isn't enough there is the additional insult of paying rent to Microsoft. From what I can tell, even canonical has given up on having a Linux based authentication system because her latest desktops have built-in active directory integration. What the hell canonical?!?

Personally, I would stick with NIS except that I need to work with couple of application dedicated Red Hat systems and RH is planning on removing NIS from 8.X. FreePA looks like a reasonable, if overly complicated alternative but it only runs on Red Hat systems and I don't want to pay rent to Red Hat any more than I want to pay rent to Microsoft. I would consider using Centos except Red Hat took Centos out back behind the barn and shot it then didn't even have the decency to bury the body. They just left rotting in the sun.

I'm probably okay with using LDAP. In researching it, I found that I have to wrap all LDAP traffic in SSL because it uses forking clear text passwords just like NIS. Now I need to build a forking CA and maintain certificates not to mention some some ancible hack to set up and replicate data that isn't handled by LDAP. I am not looking forward to editing LDIF files for account management. The web interfaces have seen are either built for 10,000 person enterprises or are a web representation of an LDIF file. GaCk!

I would use the scripted shove-fractional-password-files-around-by-SSH model except I have to integrate with a TrueNAS Core for storage.

90% plus of my work fits nicely with NIS level functionality. It's easy to set up, easy to maintain. Only causes a little hair loss and is easily distributed.

I looked at alternatives like jumpcloud, okta and keycloak but again, I'm struck by the complexity and the fact that I'm signing up for a lifetime of monthly charges just to give someone a method for logging in.

I know I'm Bitching a lot about complexity and paying rent. If there's a reason for complexity, I haven't seen any good justifications. Tony Hoare said "There are two methods in software design. One is to make the program so simple, there are obviously no errors. The other is to make it so complicated, there are no obvious errors."

Linux distributed authentication has no obvious errors...

On the point of paying rent, distributed authentication is so core to everyday systems that should be built-in. It doesn't have to be enterprise scale but should let you bridge to enterprise scale. I have no problem paying for things like support contracts for OpnSense or Xen orchestra but paying for essential services like basic distributed authentication just doesn't sit right.

Unless I can find a better solution shortly, I'm probably going to go for a minimalist LDAP solution. I'll try to define it using cloud-init so other people can reproduce it in different environments and maybe not get as frustrated as I have been.

Rant rant rant rant rant. Thank you. I'm done

submitted by /u/closerocks
[link] [comments] ...



๐Ÿ“Œ rant: Linux authentication is a freaking dog's breakfast


๐Ÿ“ˆ 88.55 Punkte

๐Ÿ“Œ rant rant rant Sound quality in Debian Linux is just trash and here we are in 2018 and I just want my old Sound Blaster Live card to work!


๐Ÿ“ˆ 58.78 Punkte

๐Ÿ“Œ Clever Dog Smart Camera DOG-2W / DOG-2W-V4 File Disclosure / Backdoor


๐Ÿ“ˆ 43.32 Punkte

๐Ÿ“Œ Clever Dog Smart Camera DOG-2W / DOG-2W-V4 File Disclosure / Backdoor


๐Ÿ“ˆ 43.32 Punkte

๐Ÿ“Œ Windows update is making me switch to ubuntu (rant / over-dramatic rant)


๐Ÿ“ˆ 37.52 Punkte

๐Ÿ“Œ Shenzhen Cylan Clever Dog Smart Camera DOG-2W-V4 Telnet Service Password Default Admin Password weak authentication


๐Ÿ“ˆ 34.64 Punkte

๐Ÿ“Œ #0daytoday #CleverDog Smart Camera DOG-2W / DOG-2W-V4 - Multiple Vulnerabilities [#0day #Exploit]


๐Ÿ“ˆ 28.88 Punkte

๐Ÿ“Œ [webapps] CleverDog Smart Camera DOG-2W / DOG-2W-V4 - Multiple Vulnerabilities


๐Ÿ“ˆ 28.88 Punkte

๐Ÿ“Œ Shenzhen Cylan Clever Dog Smart Camera DOG-2W-V4 HTTP Web Server privilege escalation


๐Ÿ“ˆ 28.88 Punkte

๐Ÿ“Œ Bill Barr: No Lap Dog, Just Defending His Idea of the Top Dog


๐Ÿ“ˆ 28.88 Punkte

๐Ÿ“Œ Discover your dog's history and screen its health with these dog DNA tests


๐Ÿ“ˆ 28.88 Punkte

๐Ÿ“Œ Rant: Treasurydirect.gov authentication


๐Ÿ“ˆ 24.52 Punkte

๐Ÿ“Œ This Smart Doorbell Was Accidentally Sending Data To China, Until People Started Freaking Out


๐Ÿ“ˆ 23.55 Punkte

๐Ÿ“Œ Sicherheitsexperten treffen sich branchenรผbergreifend zum Security Breakfast


๐Ÿ“ˆ 23.55 Punkte

๐Ÿ“Œ Sicherheitsexperten treffen sich zum Security Breakfast


๐Ÿ“ˆ 23.55 Punkte

๐Ÿ“Œ Infoguard lรคdt zum Security Breakfast


๐Ÿ“ˆ 23.55 Punkte

๐Ÿ“Œ Britain's Scientists Are 'Freaking Out' Over Brexit


๐Ÿ“ˆ 23.55 Punkte

๐Ÿ“Œ Uber's Terrifying 'Ghost Drivers' Are Freaking Out Passengers in China


๐Ÿ“ˆ 23.55 Punkte

๐Ÿ“Œ Infoguard lรคdt zum Security Breakfast


๐Ÿ“ˆ 23.55 Punkte

๐Ÿ“Œ The Facebook Android App Is Asking for Superuser Privileges and Users Are Freaking Out


๐Ÿ“ˆ 23.55 Punkte

๐Ÿ“Œ Kenne Deinen Gegner wie Dich selbstโ€“ IT Security Breakfast, Wien 02.10.2018


๐Ÿ“ˆ 23.55 Punkte

๐Ÿ“Œ Breakfast Session โ€“ Data Visibility: Performance und Sicherheit in der Public Cloud


๐Ÿ“ˆ 23.55 Punkte

๐Ÿ“Œ Britain's Scientists Are 'Freaking Out' Over Brexit


๐Ÿ“ˆ 23.55 Punkte

๐Ÿ“Œ Uber's Terrifying 'Ghost Drivers' Are Freaking Out Passengers in China


๐Ÿ“ˆ 23.55 Punkte

๐Ÿ“Œ Breakfast Session โ€“ Data Visibility: 20.09.18, InterContinental Hotel, Dรผsseldorf


๐Ÿ“ˆ 23.55 Punkte

๐Ÿ“Œ Pionier der IT-Security-Branche lรคdt IT-Fรผhrungskrรคfte zum exklusiven Security Breakfast in der ...


๐Ÿ“ˆ 23.55 Punkte

๐Ÿ“Œ cellent & Wipro IT Security Breakfast


๐Ÿ“ˆ 23.55 Punkte

๐Ÿ“Œ Skipping Breakfast May Be Linked To Poor Heart Health, Study Says


๐Ÿ“ˆ 23.55 Punkte

๐Ÿ“Œ Chrome Is Scanning Files on Your Computer, and People Are Freaking Out


๐Ÿ“ˆ 23.55 Punkte

๐Ÿ“Œ At Last, GNOME Shell! At Long Freaking Laโ€ฆ


๐Ÿ“ˆ 23.55 Punkte

๐Ÿ“Œ Freaking out about fiendish IoT exploits? Maybe stop disable telnet and change that default password first?


๐Ÿ“ˆ 23.55 Punkte

๐Ÿ“Œ Freaking out about fiendish IoT exploits? Maybe disable telnet, FTP and change that default password first?


๐Ÿ“ˆ 23.55 Punkte

๐Ÿ“Œ Hackaday: Mike Szczys, DEF CON 27: Hardware From Breakfast At DEF CON


๐Ÿ“ˆ 23.55 Punkte

๐Ÿ“Œ People Who Can't Remember Their Bitcoin Passwords Are Really Freaking Out Now


๐Ÿ“ˆ 23.55 Punkte

๐Ÿ“Œ Freaking out over IP address!


๐Ÿ“ˆ 23.55 Punkte











matomo