Râu Cao raucao
  • Joined on 2018-11-24
raucao commented on issue kosmos/chef#129 2020-02-07 15:23:47 +00:00
Encrypt user data at rest

Regarding ecryptfs, that's what I meant with faster on HDDs, but didn't explain in detail:

raucao commented on issue kosmos/chef#128 2020-02-06 21:42:12 +00:00
LDAP users should only be able to change their own password

The title of this issue is still misleading. LDAP users shouldn't be able to directly change anything in the directory. They should always go through akkounts, and I think we should enforce 2FA there for everyone as well.

raucao opened issue kosmos/chef#129 2020-02-06 21:40:07 +00:00
Encrypt user data at rest
raucao commented on issue kosmos/chef#127 2020-02-06 16:57:39 +00:00
Change LDAP directory structure to accommodate multiple domains

It's not so much about if the account is enabled, but when to send a message to donate again.

raucao opened issue kosmos/meta#12 2020-02-05 21:57:21 +00:00
Kosmos Hack Days 2020/1
raucao commented on issue kosmos/chef#127 2020-02-05 18:30:16 +00:00
Change LDAP directory structure to accommodate multiple domains

By the way, filtered roles seem like a good solution for enabling/disabling services.

raucao commented on issue kosmos/chef#128 2020-02-05 15:19:47 +00:00
LDAP users should only be able to change their own password

We can create an account for akkounts-api that can create users and nothing else

raucao commented on issue kosmos/chef#127 2020-02-05 15:15:02 +00:00
Change LDAP directory structure to accommodate multiple domains

You keep mixing up lots of things, and it's very difficult to discuss these topics when the terms used are either inaccurate or outright the wrong ones.

raucao commented on issue kosmos/chef#128 2020-02-05 15:05:31 +00:00
LDAP users should only be able to change their own password

By the way, shouldn't we also restrict access to the entire LDAP server by IP address? Why does a user have to be able to connect to it directly?

raucao commented on issue kosmos/chef#128 2020-02-05 15:03:55 +00:00
LDAP users should only be able to change their own password

I don't think akkounts-api should have credentials to a master admin account. But it does need to write to the directory.

raucao commented on issue kosmos/chef#127 2020-02-04 21:23:46 +00:00
Change LDAP directory structure to accommodate multiple domains

When it comes to Gitea, the LDAP support is for authentication, including adding admin privileges to users, but it looks like we’ll have to deal with organizations ourselves

raucao commented on issue kosmos/chef#128 2020-02-04 16:57:24 +00:00
LDAP users should only be able to change their own password

They shouldn't see any data from other users really. Not just the email address.

raucao closed issue kosmos/chef#88 2020-02-01 18:07:37 +00:00
Upgrade bitcoind
raucao closed issue kosmos/meta#6 2020-02-01 18:06:29 +00:00
Create architecture diagram for Kredits
raucao opened issue kosmos/gitea.kosmos.org#43 2020-02-01 16:26:53 +00:00
Disable registrations, delete all inactive accounts
raucao opened issue kosmos/meta#11 2020-02-01 16:19:25 +00:00
Cap amount of users/accounts
raucao commented on issue kosmos/chef#127 2020-01-30 19:35:41 +00:00
Change LDAP directory structure to accommodate multiple domains

Gitea also supports an attribute for SSH public keys, and a bunch of other things:

raucao commented on issue kosmos/chef#127 2020-01-30 19:32:25 +00:00
Change LDAP directory structure to accommodate multiple domains

One more thing:

raucao commented on issue kosmos/chef#127 2020-01-30 19:29:58 +00:00
Change LDAP directory structure to accommodate multiple domains

Looks good. But shouldn't wiki and xmpp rather be user groups?

raucao opened issue kosmos/chef#127 2020-01-30 16:05:52 +00:00
Change LDAP directory structure to accommodate multiple domains