a kadmin/krb-tui toolkit, and ldap-tui gets its own scoped admin bind #116
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
just kadmin/princ-*recipes for Kerberos principal management fromishtar, over the network -listprincs/getprinc/addprinc/modprinc/delprinc, parsed into nu tables/recordskadmin/admin/kadmin/changepware protected principals the KDC only derives via a direct AS-REQ ("TGT BASED NOT ALLOWED" regardless ofkadm5.acl), sojust kadminpre-fetches that ticket once into its own ccache (admin_ccache) rather than evicting the login TGT ssh/SPNEGO depend onkrb-tui: an fzf front-end over the samekadminsurface, packaged fleet-wide (modules/packages.nix)expire/policy/deleteactions and agetprincpreview panepolicy-addrecipe +kdc.nix's newdefault_pwd_policygive every future principal a default password policy (history 3, 90-day max life) - existing principals don't retroactively pick it up, attach by hand withprinc-policysvcLdapAdmin@LAMENT.GAY: a new Kerberos principal forldap-tui's admin-capable LDAP bindopenldap.nix'solcAccessgets two new subtree-scoped rules ahead of the catch-all, grantingcn=svcLdapAdminwrite onou=people/ou=groupsonly -cn=configandcn=krbContainerstay out of reach, nocn=admin-equivalent handed out{SASL}princpointer pattern asuid=lament- no password ever lands in LDAP,saslauthdverifies binds straight against the KDCprinc-svc-add: new recipe mints a password-bind principal (kadmin -pw, not-randkey- there's nothing to extract into a keytab here) and stashes the password intosops/<file>.yamlsops/extra.yaml(new): kept separate from the fleet-wide categories on purpose, decryptable bylament+ishtaronly - this credential is consumed locally whereldap-tuiruns, never deployed to a service hostMod+Shift+Popens noctalia's session/power panel;jj'srevsets.logbumped to 10 generations back (jj's own default only showed 2)left for later:
ldap-tuiitself isn't wired up yet -svcLdapAdmin's password lives insops/extra.yaml, consuming it into the TUI's own config is a separate step.ishtarfor a moment b566b8e85c