<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Æ-DIR -- Authorized Entities Directory</title>
        <link>https://peertube.watch/videos/watch/a38a60ad-9ddc-40ed-869a-76bca16b41be</link>
        <description>from paranoid user management to secure system management This talk will introduce Æ-DIR, a paranoid identity and access management (IAM) system based on pure OpenLDAP. The talk will detail the data model used for delegated administration and its use e.g. for a strictly authorizing SSH proxy. Furthermore it introduces OATH-LDAP, a OATH-based OTP authentication system with pure LDAP backend and the enrollment process used for secure initializing yubikey tokens. The conclusion of the talk will highlight want else will be done with the data and role model in the near future. Æ-DIR and OATH-LDAP are free software projects. This talk will present a concept and real-world implementation of a privileged identity and access management system (IAM, PAM) purely based on OpenLDAP. The main goal of Æ-DIR (besides challenging Unicode handling in various software with its name) is to follow the delegation, need-to-know and least-privilege principles as strict as possible. The visibility of user, group, sudoers, etc. is limited by OpenLDAP’s set-based ACLs. All systems and services, no exception(!), have to individually authenticate to be authorized to access Æ-DIR. The talk will give some additional information about the secured base configuration of OpenLDAP, tools developed and some experiences made when migrating/attaching 7000+ servers to this user management. Furthermore the architecture of a SSH gateway is shown which uses the very same access control data to authorize SSH connections passing through the gateway. Finally the talk will outline some additional to-dos, and rough ideas how to further develop this system. OATH-LDAP defines a schema, a functional model and a LDAP-based enrollment for OATH-based authentication tokens. It is designed to be used with any LDAP server, but especially is ready-to-use integrated with Æ-DIR. It is actually used combined with a highly secure enrollment process (no QR code displayed!) for two-factor HOTP authentication with yubikey tokens. Speaker: Michael Ströder, Track: Identity and Access Management, Room: UD2.119, When: Saturday 3 February 2018, 11:15–11:45 (Brussels time), Schedule: FOSDEM 2018 event page, Slides &amp; links Æ-DIR -- Authorized Entities Directory, OATH-LDAP -- OATH-based authc with LDAP backend, Licence: Creative Commons Attribution 2.0 Belgium (CC BY 2.0 BE) (as stated in the FOSDEM video archive). Attribution: “Æ-DIR -- Authorized Entities Directory” by Michael Ströder, FOSDEM 2018. Original recording: 2018/UD2.119/idm_aedir.webm from the FOSDEM video archive. This channel is an unofficial mirror; FOSDEM is a free and non-commercial event organised by the community for the community.</description>
        <lastBuildDate>Sat, 10 Oct 2026 00:33:33 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>PeerTube - https://peertube.watch</generator>
        <image>
            <title>Æ-DIR -- Authorized Entities Directory</title>
            <url>https://peertube.watch/lazy-static/avatars/3b284627-b75f-409e-ac2e-10f4c2946f43.png</url>
            <link>https://peertube.watch/videos/watch/a38a60ad-9ddc-40ed-869a-76bca16b41be</link>
        </image>
        <copyright>All rights reserved, unless otherwise specified in the terms specified at https://peertube.watch/about and potential licenses granted by each content's rightholder.</copyright>
        <atom:link href="https://peertube.watch/feeds/video-comments.xml?videoId=a38a60ad-9ddc-40ed-869a-76bca16b41be" rel="self" type="application/rss+xml"/>
    </channel>
</rss>