Post 2415438 by offication@pleroma.site
(DIR) More posts by offication@pleroma.site
(DIR) Post #2412056 by sean@social.deadsuperhero.com
2018-12-29T21:34:11.192289Z
0 likes, 0 repeats
Not really sure how to phrase this...If I wanted to provide someone with an email address, NextCloud account, and WordPress account all at the same time, would I be able to accomplish that with LDAP?Or is this JIT provisioning of user accounts between applications more of a SAML thing?
(DIR) Post #2412103 by kaniini@pleroma.site
2018-12-29T21:35:13.084978Z
1 likes, 0 repeats
@sean LDAP will work for this.
(DIR) Post #2412169 by jalcine@playvicious.social
2018-12-29T21:37:13Z
1 likes, 0 repeats
@sean To be honest, I had a longer response but it might be contigent on how each of these things support LDAP
(DIR) Post #2412300 by sean@social.deadsuperhero.com
2018-12-29T21:42:13.165906Z
0 likes, 0 repeats
@jalcine The Internet's favorite answer: "It depends!" 😛I'm mostly just considering a way to roll my own "Google Apps", but self-hosted and Free Software. Ideally, it'd be nice if onboarding for collaborators could be as painless and seamless as possible, where the creation of an email account creates a corresponding account in NextCloud and WordPress.I'll have to play around with it.
(DIR) Post #2412771 by jalcine@playvicious.social
2018-12-29T21:44:48Z
0 likes, 0 repeats
@sean you peeped yunohost? https://yunohost.org/#/
(DIR) Post #2412772 by msh@coales.co
2018-12-29T21:56:56Z
1 likes, 0 repeats
@jalcine @sean Hmm I'll have to look at that myself :blobthinking: I have been using the classic LDAP/Kerberos solution to provide a unified authentication for email/groupware, file server and various other apps (Kallithea git/mercurial front end, Tryton ERP/accounting, and so on). Lots of stuff integrates with it and you could set up gateways of sorts for things that don't support it directly. The initial setup was non trivial though.There are reasons MSFT embraced and extended it I guess.
(DIR) Post #2415438 by offication@pleroma.site
2018-12-29T23:09:31.394038Z
1 likes, 0 repeats
@msh @sean @jalcine Yunohost follows the same basic idea: a central LDAP server with multiple applications with LDAP integration, plus an automated setup procedure and admin tools
(DIR) Post #2416952 by M0YNG@mastodon.radio
2018-12-29T23:28:16Z
1 likes, 0 repeats
@sean I think I would like this too... Please let us know if you have any success! Or failure, that's also good to know about.
(DIR) Post #2427116 by max@smeap.com
2018-12-30T07:15:19Z
1 likes, 0 repeats
@sean They are orthogonal concerns: LDAP is one possible backing store for Authentication data (identity provider) with multiple token formats to interact (pass verifications / credentials) with the apps (relying parties), including SAML as one token option (along with older junk like Kerberos tickets and newer junk like JWT).tl;dr: It's stupid complicated but the answers include "both" and "none of the above" and "Rube Goldberg all the things".
(DIR) Post #2427127 by sean@social.deadsuperhero.com
2018-12-30T07:52:46.966288Z
0 likes, 0 repeats
@max fml 😂