6 ms·
Kanidm: A simple, secure and fast identity management platform
- hs86 5y agoIsn't the name also working in Turkish? https://translate.google.com/?sl=tr&tl=en&text=kan%C4%B1tlamak&op=translate https://translate.google.com/?sl=tr&tl=en&text=kan%C4%B1tlam... The kanıdım conjugation is basically like "I did [verb]".
- firstyear 5y agoIt's Japanese - Kani == Crab. Crab-Identity-Management :)
- unixhero 5y agoCan this be used together with Keycloak in some fashion?
- mindwok 5y agoSeems like it's intending to replace key cloak, or at least some of it.
- unixhero 5y agoStrangely there are people from Redhat on its team, as evident from their code of conduct page.
- mooreds 5y agoHere is the OAuth/OIDC issue: https://github.com/kanidm/kanidm/issues/278 https://github.com/kanidm/kanidm/issues/278 They are talking here: https://github.com/kanidm/kanidm/pull/485 https://github.com/kanidm/kanidm/pull/485 about being an IdP with support for OIDC, so once that is implemented you could probably federate to Keycloak (or any other compliant IdP). Might be worth filing an issue, I'm sure they'd love the feedback.
- firstyear 5y agoThis is intended to provide oauth2 and oidc, which means you won't need keycloak.
- JamesBenson 5y agoThank you for publishing this open source project! One question I have though - there are so many projects in this area popping up (eg. Ory‘s Kratos - https://github.com/ory/kratos https://github.com/ory/kratos) - isn’t there a way to collaborate on these larger projects instead of starting new ones? Or are there specific differences or reasons for rebuilding something like Kandim?
- firstyear 5y agoThe main reason to do Kanidm is that it's "all in one". I've had a lot of experience with FreeIPA and have learnt that the microservice design is hard to test and hard to make reliable at scale. So a key goal was to be able to create a single bundle, that we can test end to end to ensure reliability.
- KajMagnus 5y ago> "all in one" ... create a single bundle That's nice. (I too think it's simpler to get everything okay well tested, when it's all in one place, rather than different software, possibly from different vendors, that's supposed to integrate with each other to accomplish the same thing.) Also nice that it's written in Rust. And that you've chosen the MPL 2.0 license. And that Kanidm is an OIDC Identity Provider, I've been looking for that :- ) And WebAuthn (Keycloak is nice, however it's Java and thus a bit resource intensive (RAM), and some other things.)
- SahAssar 5y agoLooks to me like the main difference (besides the language) is that this is planning to offer more in the way of OS and network level auth (SSH/PAM/RADIUS) while kratos focuses on app/website level auth. I'm not sure how hard it'd be to extend kratos with those sort of features.
- deleted 5y ago[deleted]
- RedShift1 5y agoUnder features to avoid it says "Being like LDAP/GSSAPI/Kerberos", but aren't you just re-implementing these things?
- q3k 5y agoEspecially bundling these together as equally bad/legacy is weird. LDAP itself can actually be quite easy to understand and work with if you limit yourself to a useful subset of functionality, ie. a account/group directory. Any Kerberos compatibilty/design inspiration should IMO be avoided though, as it was designed to not use public key crypto, and that translates to a lot of its weirdness. What I’d like to see is one of these modern offerings actually expose an LDAP facade (bonus points for translating app-specific passwords into binds and for flattening nested group membership) so that it’s easy to bridge existing software which expects LDAP into this newfangled web-centric world. Things like an email MTA/MDA, a PHP app that wants a user directory or even nss_ldap for unified UIDs/GIDs across machines.
- haveyaseen 5y agoIt does speak LDAP as well: https://www.youtube.com/watch?v=8IaxnSAggkI&t=1507s https://www.youtube.com/watch?v=8IaxnSAggkI&t=1507s
- georgyo 5y agoKerberos' use of symmetric keys is actually one of its strengths. In a post-quantum world, kerberos is significant more resistant to attack. Kerberos suffers in other areas, suck as only doing authentication but not authorization, and realm discovery is not trivial. EDIT: Thinking further, I think you are taking about the fact that you need to get a secret key (keytab) from the KDC to do authentication, where as in other auth technologies you are giving the public key to a server and no sensitive information ever has to be transported. That is true.
- firstyear 5y agoThis is exactly what Kanidm does, and there is already some ideas around application password validation via the LDAP facade.
- mooreds 5y agoInteresting that they are choosing to provide an integrated solution including user management and OAuth IdP ( https://github.com/kanidm/kanidm/pull/485 https://github.com/kanidm/kanidm/pull/485 ) rather than plug into existing open source or even commercial offerings. Here's a design doc about their OAuth choices: https://github.com/kanidm/kanidm/blob/master/designs/oauth.rst https://github.com/kanidm/kanidm/blob/master/designs/oauth.r... It would seem simpler to go with the Ory approach of "best in breed" for, say network management tooling (most of which they already have implemented), and then integrate with Keycloak, Okta, FusionAuth, the Ory suite, etc for user management. Maybe they didn't want to do that because there are synergies with integrated user management? I dunno, seems like there are a lot of user management tools out there. I also find it interesting that they explicitly disallow a goal of building a better LDAP server. I think there's a lot of room to run in that. My employer has had users show a fair bit of interest in a modern experience with LDAP layered on top ( https://github.com/FusionAuth/fusionauth-issues/issues/954 https://github.com/FusionAuth/fusionauth-issues/issues/954 ) and I talked to someone at a conference that had built a whole business out of virtual LDAP: https://www.radiantlogic.com https://www.radiantlogic.com . They were working with companies with multiple LDAP based auth systems, and providing a way to have apps see one view of the user. Maybe kanidm isn't that project, but it seems like a modern OSS LDAP implementation would be welcomed by the software community. Disclosure: I work at FusionAuth.
- GekkePrutser 5y ago> Interesting that they are choosing to provide an integrated solution including user management and OAuth IdP ( https://github.com/kanidm/kanidm/pull/485 https://github.com/kanidm/kanidm/pull/485 ) rather than plug into existing open source or even commercial offerings. I can understand their focus of being completely open and self-contained. At work we use Azure AD and I've been looking at an IDP to use personally. I actually do have access to a personal AAD instance. But I don't want to give commercial parties access or data about my stuff. Existing open source offerings would be ok but then you have a codebase to consider that you don't manage and it could make the product heavier. The only thing I'd 'outsource' would be algorithm stuff in libraries like crypto. I'm looking for something lightweight that is stand-alone and this looks really interesting. I'll definitely try it out. Just wanted to point out that there is definitely a niche for it :)
- _Anima_ 5y agoIs it a replacement for freeipa? Key cloak?
- mooreds 5y agoLooks like it squarely competes with FreeIPA. Maybe main differentiator is that FreIPA is in python whereas this is in rust (and so less prone to bugs)?
- rzzzt 5y agoIs it a widely held concept that Rust is less prone to bugs compared to Python? I've only heard it being compared to C, and only wrt. memory safety bugs.
- tptacek 5y agoRust is statically typed and doesn't have null returns, so it's got advantages for correctness, but the big win with Rust vs. Python would be performance, not security.
- yaleman 5y agoThere's a lot more checks and balances built into rust as a language, so the foot-gun opportunities are less likely - which makes it rather suitable for reliable systems programming. And getting back to this particular case... kanidm is fast AND reliable. There's a lot of testing going on comparing it to 389 DS.
- tptacek 5y agoYes, I write a fair bit of Rust. I'm just saying: between Python and Rust, there isn't that much of a security difference (you could nitpick things like deserialization in Python, but really the significant security win of Rust is not having memory corruption flaws, which Python has never really had.)
- 5y ago
- permalac 5y agoNobody is mentioning a big open source project like Grouper, https://incommon.org/trusted-access/ https://incommon.org/trusted-access/ Can someone tell me why is this project, or 4 softwares, not more widely known?
- mooreds 5y agoIncommon is focused on .edus, as far as I understand it. That might be why it isn't as well known as it should be. I've definitely heard of Shibboleth, it's one of the big players in OSS SAML implementations.
- chromatin 5y agoWell, objectively, looking at that page or for example the grouper page (https://incommon.org/software/grouper/ https://incommon.org/software/grouper/) I fail to get /exactly/ where grouper fits in, what it does and doesn’t do, and just generally why I would or wouldn’t choose it in my application. Likely, busy people don’t spend a lot of time digging in to software that doesn’t effectively communicate clearly what it is, unless they know from a trusted colleague, friend, or other resource that the software/tool will be essential or a major win for them. That’s a long-winded way to say “marketing” :)
- permalac 5y agoI would have thought that in SCIM provisioning people would invest more time researching for existing projects. Said that, I fully understand why people would not invest enough time to understand the Grouper environment, I going through it and feels like a punishment. If someone wants to see the potential, check this list of known users and their use cases : https://spaces.at.internet2.edu/display/Grouper/Community+Contributions https://spaces.at.internet2.edu/display/Grouper/Community+Co...
- yaleman 5y agoThe front page says "the research and education system for IAM" ... that reads like it's not for production use and would turn me off immediately.
- chromatin 5y agoI like these types of projects (auth) and happy to see this is a thriving area. I was a little puzzled by the very first line in their gitbook [0] documentation: “Kanidm is an identity management server, acting as an authority on accounts and authorisation within a technical environment.” Shouldn’t that be authentication, or am I misunderstanding the purpose of Kanidm? [0] https://kanidm.github.io/kanidm/intro.html https://kanidm.github.io/kanidm/intro.html
- sigg3 5y agoauth is auth. Don't overcomplicate the matter.
- politician 5y agoAuthentication and Authorization are distinct concepts whose English terms both start with the same prefix.
- nick__m 5y agoThe set of possible Authorization policies without having some form of Authentication is quite limited ;)
- politician 5y agoWithin ABAC schemes, Authorization is a boolean function over (Request, Principle, Environment). If you zero the Principle, you can still represent a large number of unique policies considering just the Request and the Environment.
- krono 5y agoYou would be the one overcomplicating the matter by clumping these distinct concepts together. Edit: For those unfamiliar with the concepts: Authentication: subject identity - is the user who they claim to be? Authorization: subject permissions - is this user permitted to execute that action?
- deleted 5y ago[deleted]
- Huma12_ 5y agoYes that's it
- throwaway984393 5y agoTrying to read the docs and look through the code, and it all seems very jumbled, like someone had ADHD and went around implementing a dozen different things that relate to identity and authZ. It would seem like the efforts might be best applied as independent components that combine with other open source solutions, to prevent reinventing the wheel, and create more independent composeable solutions that do one thing well.
- 5faulker 5y agoSeems like the code just grow organically without a super coherent structure. I'm sure there are folks with ADHD who might be able to get through it though.
- firstyear 5y agoThere actually is a plan and set of designs that worked towards these parts. There was a lot of foundational work, and currently the goal is the integrations on top.
- _8j50 5y agoSSH key/ca management is the only thing I can see that makes this different than say AzureAD. I am glad projects like this exist, even though most people can be best served by ping,aad and the like.
- gibsonf1 5y agoMaking this a Solid Server or starting as a Solid IDP would be pretty valuable: https://solidproject.org/ https://solidproject.org/