Greg greg
  • Joined on 2018-11-05
greg pushed to feature/123-ejabberd_5apps at kosmos/chef 2020-02-12 16:42:13 +00:00
49d01991fd Enable LDAP on the XMPP 5apps.com vhost
greg created pull request kosmos/chef#131 2020-02-12 15:19:29 +00:00
Set the ACIs on the base DN
greg pushed to bugfix/128-set_acis_on_users at kosmos/chef 2020-02-12 15:17:40 +00:00
e56faab5b1 Set the ACIs on the base DN
greg commented on issue kosmos/chef#128 2020-02-07 15:42:19 +00:00
LDAP users should only be able to change their own password

Makes sense, I'm fixing the title

greg commented on issue kosmos/chef#129 2020-02-07 10:31:22 +00:00
Encrypt user data at rest

Good idea. We might want to compare it with eCryptfs and other solutions

greg commented on issue kosmos/chef#128 2020-02-07 10:28:42 +00:00
LDAP users should only be able to change their own password

I agree that everything should be locked down (and the LDAP server should only be accessible by servers that need access) once we have added these features to akkounts. However I think the changes for akkounts should go in another issue. For now we need users to be able to change their passwords.

greg commented on issue kosmos/chef#127 2020-02-06 12:27:22 +00:00
Change LDAP directory structure to accommodate multiple domains

I agree, here's a filtered role example (for the 5apps XMPP config): kosmos/chef#123 (comment)

greg commented on issue kosmos/chef#123 2020-02-06 12:24:18 +00:00
Enable LDAP support on ejabberd

I have prepared the 5apps XMPP migration to LDAP.

greg commented on issue kosmos/meta#12 2020-02-06 09:37:19 +00:00
Kosmos Hack Days 2020/1

Cool! I'm in for both XMPP and Kosmos

greg commented on issue kosmos/chef#127 2020-02-05 17:42:25 +00:00
Change LDAP directory structure to accommodate multiple domains

Thanks for clarifying it, this is all clearer to me now

greg commented on issue kosmos/chef#128 2020-02-05 15:06:20 +00:00
LDAP users should only be able to change their own password

Yes, there are ACIs for everything. We can create an account for akkounts-api that can create users and nothing else

greg commented on issue kosmos/chef#128 2020-02-05 13:31:11 +00:00
LDAP users should only be able to change their own password

Setting ACIs is what we need.

greg commented on issue kosmos/chef#127 2020-02-05 12:16:18 +00:00
Change LDAP directory structure to accommodate multiple domains

OK, now I understand. In Gitea there is a global setting for "Allow Creation of Organizations by Default", that is off by default and off in our deployment. Admins can always create organizations, and there's also a flag on regular users for their ability to create organizations if needed

greg commented on issue kosmos/chef#127 2020-02-04 21:03:55 +00:00
Change LDAP directory structure to accommodate multiple domains

So far I think for the use case of enabling different services, that roles, in particular filtered roles would be a good fit.

greg commented on issue kosmos/meta#11 2020-02-04 20:20:36 +00:00
Cap amount of users/accounts

This is a good idea, I think we should keep this around and revisit it before we go public!

greg opened issue kosmos/chef#128 2020-02-04 15:33:55 +00:00
LDAP users should not be able to list other users' email address
greg pushed to master at kosmos/chef 2020-02-04 15:26:37 +00:00
396cc344fb Switch the ipfs cookbook from GitHub to Gitlab
greg pushed tag v0.1.3 to kosmos/ipfs-cookbook 2020-02-04 15:23:57 +00:00
greg pushed tag v0.4.0 to kosmos/ipfs-cookbook 2020-02-04 15:23:57 +00:00
greg pushed tag v0.1.2 to kosmos/ipfs-cookbook 2020-02-04 15:23:57 +00:00