Restructured Documentation
Automatic Documentation Deployment / Sync Docs to https://kb.bunny-lab.io (push) Successful in 8s
Automatic Documentation Deployment / Sync Docs to https://kb.bunny-lab.io (push) Successful in 8s
This commit is contained in:
@@ -0,0 +1,23 @@
|
||||
---
|
||||
tags:
|
||||
- Active Directory
|
||||
- LDAP
|
||||
- Authentication
|
||||
---
|
||||
|
||||
## Purpose
|
||||
LDAP settings are used in various services from privacyIDEA to Nextcloud. This will outline the basic parameters in my homelab that are necessary to make it function.
|
||||
|
||||
| **Field** | **Value** | **Description** |
|
||||
| :--- | :--- | :--- |
|
||||
| Server Address(s) | `ldap://bunny-dc-01.bunny-lab.io` / `192.168.3.8`, `ldap://bunny-db-02.bunny.lab.io` / `192.168.3.9` | Domain Controllers |
|
||||
| Port | `389` | Unencrypted LDAP |
|
||||
| STARTTLS | `Disabled` | |
|
||||
| Base DN | `CN=Users,DC=bunny-lab,DC=io` | This is where users are pulled from |
|
||||
| User / Bind DN | `CN=Nicole Rappe,CN=Users,DC=bunny-lab,DC=io` | This is the domain admin used to connect to LDAP |
|
||||
| User / Bind Password | `<Password for User / Bind DN>` | Domain Credentials for Domain Admin account |
|
||||
| Login Attribute | ` LDAP Filter: (&(&(|(objectclass=person))(|(|(memberof=CN=Domain Users,CN=Users,DC=bunny-lab,DC=io)(primaryGroupID=513))))(samaccountname=%uid)) ` | Used by Nextcloud |
|
||||
| Login Attribute | `(sAMAccountName=*)(objectCategory=person)` | Used by PrivacyIDEA |
|
||||
|
||||
## Related Documentation
|
||||
- [Related Identity and Certificates Documentation](<../index.md>) — Find the connected deployments, procedures, and references for this subject.
|
||||
@@ -0,0 +1,20 @@
|
||||
---
|
||||
tags:
|
||||
- Keycloak
|
||||
- OAuth2
|
||||
- Authentication
|
||||
---
|
||||
|
||||
## Purpose
|
||||
Choose the documented Keycloak integration for an application or reverse proxy after Keycloak is deployed. Application OAuth settings and reverse-proxy authentication serve different integration points.
|
||||
|
||||
## Prepare Keycloak
|
||||
[Deploy Keycloak](<../../deployments/Identity and Certificates/Keycloak/Deploy Keycloak.md>) includes the service and proxy-middleware configuration.
|
||||
|
||||
## Configure an Application
|
||||
- [Gitea OAuth2](<../../workflows/Identity and Certificates/Keycloak/Connect Gitea to Keycloak.md>) — Configure the documented application client.
|
||||
- [Portainer OAuth2](<../../workflows/Identity and Certificates/Keycloak/Connect Portainer to Keycloak.md>) — Configure the documented Portainer integration.
|
||||
- [Firefox Proxy Authentication](<../../deployments/Networking and Access/Remote Access/Firefox.md>) — Review the deployment that explains the proxy authentication flow.
|
||||
|
||||
## Related Documentation
|
||||
- [Related Identity and Certificates Documentation](<index.md>) — Find the connected deployments, procedures, and references for this subject.
|
||||
@@ -0,0 +1,23 @@
|
||||
---
|
||||
tags:
|
||||
- Identity and Certificates
|
||||
- Reference
|
||||
- Documentation
|
||||
---
|
||||
|
||||
# Identity and Certificates
|
||||
## Purpose
|
||||
Connect directory services, certificate trust, single sign-on, and application authentication. Start with the identity system involved, then follow the integration or maintenance procedure.
|
||||
|
||||
## Includes
|
||||
- Build the documented offline root, online subordinate CA, and publication point.
|
||||
- Publish and monitor CRLs after the PKI exists.
|
||||
- Provide the trust material needed by directory clients.
|
||||
|
||||
## Find the Right Document
|
||||
- [Deploy Certificate Services](<../../deployments/Identity and Certificates/Active Directory/Certificate Services.md>) — Build the documented offline root, online subordinate CA, and publication point.
|
||||
- [Maintain Revocation Lists](<../../workflows/Identity and Certificates/Certificates/Publish and Maintain Certificate Revocation Lists.md>) — Publish and monitor CRLs after the PKI exists.
|
||||
- [Export LDAPS Certificates](<../../workflows/Identity and Certificates/Certificates/Export Certificates for LDAPS Clients.md>) — Provide the trust material needed by directory clients.
|
||||
- [LDAP Connection Settings](<Active Directory/LDAP Connection Settings.md>) — Locate the recorded directory connection parameters.
|
||||
- [Keycloak Application Integrations](<Keycloak Integrations.md>) — Choose reverse-proxy authentication or an application-specific OAuth integration.
|
||||
- [Windows Remote Management](<../../workflows/Identity and Certificates/Windows/Enable WinRM over HTTPS.md>) — Prepare Windows targets for the AWX or Puppet Bolt workflows that reference WinRM.
|
||||
Reference in New Issue
Block a user