Hello, everyone. I am planning to set up Single Sign-On (SSO). I wonder if I can use something like Red Hat SSO with two separate domains. I have one domain for Windows AD and one for Linux IDM. My idea is to use Red Hat SSO so that both domains will be able to access the same services. For example, I have one Nextcloud instance, and I would like users from both domains to use it with SSO.

  • Lem453@lemmy.ca
    link
    fedilink
    English
    arrow-up
    15
    ·
    6 months ago

    Highly recommend Authentik for SSO.

    I run it on it’s own sub domain and all my other apps on their own sub domains.

    It has pretty much every login protocol you could want (oauth, saml, ldap) etc.

    Currently using it for jellyfin, immich, linkwarden, freshrss, and seafile.

    • PlexSheep@feddit.de
      link
      fedilink
      English
      arrow-up
      2
      ·
      6 months ago

      Does it work for multiple domains (not Subdomains)? I’m currently using authelia, which can’t do that, which sucks.

      • Lem453@lemmy.ca
        link
        fedilink
        English
        arrow-up
        1
        ·
        6 months ago

        I can’t imagine why it wouldn’t. The configuration just needs a URL, what domain they are actually on should be irrelevant.

        • PlexSheep@feddit.de
          link
          fedilink
          English
          arrow-up
          1
          ·
          6 months ago

          For authelia, iirc it’s a problem with the way cookies work, but also with how they set their system up structurally. I don’t know the details anymore.

  • spaghetti_carbanana@krabb.org
    link
    fedilink
    English
    arrow-up
    7
    ·
    6 months ago

    Authelia is popular, as is Keycloak. I believe Red Hat develops Keycloak or at least has a hand in it.

    I’m on this journey as well, figuring out what I’m going to use. Currently most of my services just use LDAP back to AD but I’m looking to do something more modern like SAML, oAuth or OpenID Connect so that I can simplify the number of MFA tokens I have.

    Just as an anecdote you may find useful - Personally I used to run an Active Directory for Windows and FreeIPA for my Linux machines and have managed to simplify this to just AD. Linux machines can be joined, you can still use sudo and all the other good stuff while only having one source of truth for identity.

    • kylian0087@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      2
      ·
      6 months ago

      you can still use sudo and all the other good stuff while only having one source of truth for identity.

      I am aware that linux devices can join the AD domain. The reasons i setup up FreeIPA/IDM is the linux specific rules I can make. Like the Sudo rules for example. As far as i am aware you can not do this with a windows domain controller.

    • bless@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      6 months ago

      Looking for a good guide on getting this setup via docker and AD LDAP, any pointers?