Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)GP
Posts
1
Comments
26
Joined
2 yr. ago

  • The only alternative I know of that goes close to what FreeIPA does (minus the cert part) is kanidm. It does:

    • oauth2
    • ssh key distribution
    • RADIUS
    • PAM/SSSD
    • LDAP

    I just noticed they have a beta for multimaster replication, which is nice.

    I use it at home. Note, though, that it does not do any hand-holding, and all configuration is done through CLI. Also note, there are docs for the stable or dev branch and there sometimes are big differences between the two.

  • I use kanidm with oauth2-proxy. No issues so far, it was pretty easy to set up.

    Note that the connection to kanidm needs to be TLS even if you have a reverse proxy!

    EDIT: currently using 80MB RAM for two users and three Service Providers.

  • I also moved away my domains and the ones of the hackerspace I manage, mainly to:

    • infomaniak (Switzerland): a bit too pushy with extra services, but not bad
    • openprovider (NL): more geared towards bulk users, have to prepay (min 20€), but okay so far
    • aruba: meh, but free mailboxes are nice

    I also use Migadu, they have been great so far!

    desec.io for DNS, also great and supported by Traefik for DNS-01 ACME challenge.

  • It’s a bit chaotic, and they try to force you to pay for other stuff in the process, but the prices were not that far off from other registrars. Note that I use DeSEC for the actual nameservers though.

  • Selfhosted @lemmy.world

    Gandi announced a price increase and discontinuation of free mailboxes