!coeAONBrWyDJnYMbMi:nixos.org

NixOS System Operations

603 Members
About system administration for running NixOS systems in production. Declaratively manage your operations. | Room recommendations: #networking:nixos.org165 Servers

Load older messages


SenderMessageTime
9 Mar 2024
@hexa:lossy.networkhexabut does that really justify the added complexity for saml?01:53:42
@hexa:lossy.networkhexalike why would you even say you prefer it?01:53:51
@hexa:lossy.networkhexayour neither a government, nor a university, nor a global conglomerate01:54:06
@raitobezarius:matrix.orgraitobezarius(well I worked for :P)01:54:23
@raitobezarius:matrix.orgraitobezariusAnd honestly every time I tried to replicate certain setups with OIDC, it made me appreciate the thoughtfulness of the SAML design01:54:43
@hexa:lossy.networkhexapretty sure people go for saml for poltiical or structural reasons only01:54:52
@raitobezarius:matrix.orgraitobezariusNow, my position is more I wish there were Kanidm for SAML01:54:54
@raitobezarius:matrix.orgraitobezariusAnd I'd probably use more SAML in my infrastructure if I could do that01:55:06
@hexa:lossy.networkhexakeycloak? 😛01:55:16
@raitobezarius:matrix.orgraitobezariusKeycloak does not know how to implement SAML01:55:22
@hexa:lossy.networkhexawho does though? 😄 01:55:36
@raitobezarius:matrix.orgraitobezariusdon't tell me 'see?' :D01:55:37
@raitobezarius:matrix.orgraitobezarius
In reply to @hexa:lossy.network
who does though? 😄
Well, Apereo folks does OK things in that area
01:55:49
@hexa:lossy.networkhexaso CAS?01:55:59
@raitobezarius:matrix.orgraitobezariusIt's honest even though I hate Java Enterprise01:56:37
@raitobezarius:matrix.orgraitobezarius(it hurts me to say it ok)01:56:49
@hexa:lossy.networkhexa
❯ rg apereo
pkgs/development/php-packages/phing/composer.lock
4672:                "apereo/phpcas": "<1.6",
01:57:03
@hexa:lossy.networkhexa🤡01:57:08
@raitobezarius:matrix.orgraitobezariuswhat is this supposed to mean :D01:57:24
@hexa:lossy.networkhexatake the best of both worlds01:57:27
@raitobezarius:matrix.orgraitobezariusBut honestly, you say 'added complexity of SAML', I wonder how much this complexity has been inflicted by the bad reputation of SAML via corporate vendors01:57:40
@raitobezarius:matrix.orgraitobezariusOIDC was/is also very complicated01:57:47
@raitobezarius:matrix.orgraitobezariusI wonder why that complexity is also accepted01:58:14
@raitobezarius:matrix.orgraitobezariusand well all software has bugs :p https://github.com/kanidm/kanidm/issues/261101:59:27
@raitobezarius:matrix.orgraitobezariuseven with a good codebase like kanidm we find some weird stuff01:59:53
@hexa:lossy.networkhexacontemplating the requirements for our sso02:02:21
@hexa:lossy.networkhexawondering if the self service that kani provides is sufficient02:02:32
@hexa:lossy.networkhexahaven't seen rc16 yet02:02:38
@raitobezarius:matrix.orgraitobezariuswe are probably going to develop a self service on the top of it for our needs02:02:59
@raitobezarius:matrix.orgraitobezariusand just use kanidm API for a bunch of things02:03:13

Show newer messages


Back to Room ListRoom Version: 10