

Its just storing a date you tell it is your birthday. Nothing more than an age gate that can easily be lied to.
Honestly just have your distro zero accounts out to 00:00:00-1970-01-01 by default.


Its just storing a date you tell it is your birthday. Nothing more than an age gate that can easily be lied to.
Honestly just have your distro zero accounts out to 00:00:00-1970-01-01 by default.
This was tweeted damn near to the day that my egg fully cracked that’s fuckin insane
You scared the shit outta me because I thought this was official femtanyl merchant for a second.
The solution to that is open source tooling to download backup and re-upload your private key material to a set of keys.
Doesn’t solve the issue of the key cut though.
Maybe just use an rfid coil in the ignition and turn a key to start like immobilizers have done for like 20-30 years at this point.
Better yet use physical contacts in the key and use an on key cryptographic controller to do public key authentication.
That way key material never leaves the key itself after being manufactured making it basically impossible to steal the car without the key.
Lol right maybe a gram dab.


What happens when a kid talks about their trans parent? What about trans kids?
You don’t think everyone’s just born cis then DECIDES to become trans later on do you?


For webapp stuff for sure, but when you want to login as the same user with the same perms across all your VMS and baremetal servers at the os, it’s nice.
I use virtualization over containerization because i have the hardware resource so I might as well take advantage of improved isolation and security VMS provide. Plus I use Linux on my desktop/laptop, and have a separate dedicated storage host.
Its nice to have everything managed by one service with global accounts and permissions.
Looking at authentik it seems to provide some but not all of that. Def something to keep an eye on if freeipa decides to stop being so free.
If you’re running a docker-based environment, and especially if your personal workstation/laptop doesn’t run Linux, I totally get it.
I think freeIPA could use an openid provider packed in for sure. I also kinda trust api keys more than creating the service accounts for software that needs to auth.
Outta curiosity how do you handle SSO and File Storage? I like being able to make samba shares that require SSO authentication over something like nextcloud because I can directly mount the disk. Not sure if theres a good option there.


deleted by creator


Your router is an important security device that you should own and control your self if you want any semblence of ownership over your network.
Your modem is remotely controlled by the ISP even if you own it, and is mostly there to demodulate from the medium installed by your ISP (usually cable, or fiber but those are called ont’s not modems) to a standard cat. 6 Ethernet connection you can plug into most routers.
The main benefit of owning your own modem is not having one with a router built in and not having to pay an equipment fee.


Haven’t touched HA yet but I run FreeIPA, is there an LDAP option or will I have to get an open I’d solution go sit in front of it?


Got off gubermin estrogen months ago hope that’s enough :(
For inside the lan/lab, I have my pem chain looks like:
cold storage root-ca -> offline vault qubes VM ca -> pfsense ca -> freeipa ca
I use letsencrypt for externally facing services.
Its a little bit more effort than getting things just workin’ but its worth the whole lotta security you get in return. Plus it feels nice looking at a shiny green lock.
The XMPP ecosystem is a mess and matrix has a ton of security and metadata issues.
We shouldn’t be using discord-likes anymore, it was a bad idea the first time.
Personal IM/VoIP should be separate from game party chat should be separate from communitt IRC/forums
Matrix has lots of metadata issues and signal requires a phone number which is a non-starter.
Self host what makes sense for communities, use simplex for one-to-one IM/VoIP.
Also discord acted as like six different services and we shouldn’t continue letting anything do that.
Personal IM, party chat/VoIP, meeting software, inter-office communication, wiki software, and forum software are all different things for a good fucking reason.


Already got one full of computers in my closet next to my clothes maybe I should just get another to hold em up lol


You’d have to be a real smeg head to do that.
How much microplastics am I getting when I swallow my boifriends nut?
Alternatively if you’re tired of manual DNS configuration:
FreeIPA, like AD but fer ur *Nix boxes
Configures users, sudoer group, ssh keys, and DNS in one go.
Also lotta services can be integrated using LDAP auth too.
So far I’ve got proxmox, jellyfin, zoneminder, mediawiki, and forgejo authing against freeipa in top of my samba shares.
Ansible works too just because its uses ssh, but I’ve yet to figure out how to build ansible inventories dynamically off of freeIPA host groups. Seen a coupla old scripts but that’s about it.
Current freeipa plugin for it seems more about automagic deployment of new domains.
You can take my 2012 civic from my cold dead and fabulous hands.