3 ms·
Interesting. Not sure about the requirement for "an LDAP server with sshPublicKey attributes on user records to store their SSH public keys." https://github.com
by 23david 12y ago
Interesting. Not sure about the requirement for "an LDAP server with sshPublicKey attributes on user records to store their SSH public keys." https://github.com/AdRoll/hologram https://github.com/AdRoll/hologram
I know you can put anything into LDAP, but why treat it like a metadata service? Wouldn't it make more sense to store keys in something like etcd so they're accessible via simple REST api calls? In my experience, the less LDAP does, the happier everyone seems to be.
- tedchs 12y agoMany organizations that have the problem this solves are already complex enough to benefit from LDAP. etcd is not appropriate to use outside a controlled server environment because it's not authenticated.
- epall 12y agoYeah, we connected with LDAP because that's how AdRoll operates, but we'd like to support a more universal backend eventually. That support just didn't make the cut for open-source release. With a bit of code, you could easily plug in a .txt file or a SQLite database, or even etcd if you really don't want to move a file around.
- mdaniel 12y agoI recently heard of someone using the GitHub API to only allow certain GitHub accounts to have access to a bastion server. Given the target audience, if your company uses GitHub (or perhaps even the internally hosted GitHub Enterprise), that might be a much easier sell than modifying LDAP. The GitHub API to list a user's keys doesn't require OAuth or any kind of hoop-jumping: https://api.github.com/users/mdaniel/keys https://api.github.com/users/mdaniel/keys