Comment on Anybody here running AD on-prem in your homelab?

<- View Parent
MigratingtoLemmy@lemmy.world ⁨9⁩ ⁨months⁩ ago

Thanks for the great answer.

Using AD for SSO in git-frontends and other applications is a fantastic idea. I will probably also run FreeIPA/389DS (that’s a name I hadn’t heard in a while till this thread, from another commenter) and have a trust relationship.

You’re right, this is probably better for learning rather than actually using at home, since most of my computers are linux/BSD, so if I needed a central auth server, I’d probably be better off using something made for *nix.

With that said, I had a curious idea - can I spin up temporary credentials, using something akin to service/machine accounts, rotate credentials and invalidate credentials freely etc? In essence, I’m wondering if this can be a way to implement a sort of homegrown “AWS STS” alternative, for app secrets, workers and the like. I was initially looking at secret management suites like Vault and Conjur but what if this can do it?

Also, can AD encrypt the DB? Can FreeIPA/389DS do it? I’d like such an option for security.

Thanks!

source
Sort:hotnewtop