governa, to foss
@governa@fosstodon.org avatar
chiefgyk3d, to infosec
@chiefgyk3d@social.chiefgyk3d.com avatar

Step 0 of my homelab rebuild is done. Identity Provider cleaned up so now my domain is doing SAML SSO with 365 and has a few bookmarks in the SSO user portal for my own needs. Planning to add Notion, Matrix, Doppler, Twingate, AWS, and Slack to the SAML SSO portal soon. I at least setup 365 and Avanan for now and bookmarked Tiktok and Twitch.

freiefunken, to linux German
@freiefunken@mastodon.social avatar

Wer mag, kann bei den Chemnitzer Linuxtagen was über Single Sign-on für Webanwendungen von mir hören. Ist aber für die, die sonntags morgens nicht verschlafen. 😉

https://chemnitzer.linux-tage.de/2024/de/programm/beitrag/213

lemonldapng, to overwatch French
fediforum, to fediverse
@fediforum@mastodon.social avatar

@donpdonp is coming to and wants to talk about:

Identity re-use, especially a mastodon account to login to a lemmy server

This would solve so many problems! There are parts of the fediverse where that works, but these are small parts today. Can we make them larger? Join Don and the community to discuss this at https://fediforum.org in March?

passbolt, to opensource
@passbolt@mastodon.social avatar
worteks_com, to opensource French
@worteks_com@mastodon.social avatar
oblomov, to lemmy
@oblomov@sociale.network avatar

I want to check out and more but I dislike having to create another account. We need a way to have across the Fediverse.

nono2357, to random French
lemonldapng, to overwatch French
cryptpad, to random
@cryptpad@fosstodon.org avatar

🚀 CryptPad 5.6 is now live on https://cryptpad.fr and on GitHub

  • 🔑 Start on the much awaited Single-Sign-On () authentication
  • 🗓️☑️ Improvements, fixes, and minor features for Form and Calendar
  • ♿ Accessibility improvements to the drive and toolbars

details 1/5 🧵👇

cryptpad,
@cryptpad@fosstodon.org avatar

🔑 This release paves the way for integrating CryptPad instances with Single-Sign-On () authentication. The 2nd piece of this feature is a plugin which we'll release in January 2024.

This release also adds the option to make mandatory for all users of an instance.

2/5

schalkneethling, to opensource
@schalkneethling@hachyderm.io avatar

🙌 BoxyHQ is now on Mastodon 🙌 #opensource #sso - https://hachyderm.io/@boxyhq

boilingsteam, (edited ) to random
@boilingsteam@mastodon.cloud avatar

Social Networks, what do YOU still use on Nov 11, 2023? If you use something else, skip the poll and comment!

sfunk1x,

@boilingsteam Also, I have to use Facebook because of family and groups. Groups is a huge feature. The car groups I'm involved with have a huge presence and wealth of knowledge/manufacturing/designing in those respective Facebook groups. This used to be facilitated by email mailing lists or forums. There needs to be a good replacement for that, and really, there needs to be a DIY SSO solution for Fediverse platforms.

passbolt, to Cybersecurity
@passbolt@mastodon.social avatar

🚀 Version 4.4 has arrived, what’s new in this version of passbolt:

  • Introducing SSO using generic OAuth2.0.
  • Admin ability to suspend & unsuspend users.
  • Easier TOTP management; create and edit TOTPs in the browser.

Upgrade to v4.4 to improve your passbolt experience.

📄 See the full release notes: https://help.passbolt.com/releases/ce/zombie

spaceflight, to space
@spaceflight@techhub.social avatar

📆 October 19, 2023 The 🇪🇺 Summit that will be held in , Spain 🇪🇸 , on 📆 November 6 and 7 is a crucial event for the continent's technological future. The delay ⏳ of the European and the technical problems are only the tip of the iceberg. For every euro 💶 invested, is ten times more efficient 📊 https://www.lemonde.fr/en/opinion/article/2023/10/19/the-european-space-industry-needs-to-get-its-act-together-before-it-s-too-late_6187587_23.html

"Revolution Space" report 📄 https://esamultimedia.esa.int/docs/corporate/h-lag_brochure.pdf

spaceflight,
@spaceflight@techhub.social avatar

Membership and contribution 💰 to https://en.wikipedia.org/wiki/European_Space_Agency#Membership_and_contribution_to_ESA

🇪🇺 @EUSPA 28.4%
🇫🇷 France 24.5%
🇩🇪 Germany 21.1%
🇮🇹 Italy 14.1%
🇬🇧 United Kingdom 9.1%
🇧🇪 Belgium 5%
🇪🇸 Spain 4.6%
🇨🇭 Switzerland 3.6%

marcel, to random German
@marcel@waldvogel.family avatar

begrüsst seine Besucher des mit einem kleinen .

marcel,
@marcel@waldvogel.family avatar

talking about "Secure-by-Design: How do You Design with a Security Mindset for the User?" at :

  • Design for ease of use
  • Design with misuse in mind
  • How we failed to prevent online access/commerce, word processors, email, supply chains, IoT devices, … being misused

Design approaches:

remixtures, to Cybersecurity Portuguese
@remixtures@tldr.nettime.org avatar

: "Okta, a company that provides identity tools like multi-factor authentication and single sign-on to thousands of businesses, has suffered a security breach involving a compromise of its customer support unit, KrebsOnSecurity has learned. Okta says the incident affected a “very small number” of customers, however it appears the hackers responsible had access to Okta’s support platform for at least two weeks before the company fully contained the intrusion.

In an advisory sent to an undisclosed number of customers on Oct. 19, Okta said it “has identified adversarial activity that leveraged access to a stolen credential to access Okta’s support case management system. The threat actor was able to view files uploaded by certain Okta customers as part of recent support cases.”

Okta explained that when it is troubleshooting issues with customers it will often ask for a recording of a Web browser session (a.k.a. an HTTP Archive or HAR file). These are sensitive files because in this case they include the customer’s cookies and session tokens, which intruders can then use to impersonate valid users."

https://krebsonsecurity.com/2023/10/hackers-stole-access-tokens-from-oktas-support-unit/

EzellaGarnie, to opensource

That's why I love
https://www.surf.nl/en/news/mastodon-pilot-has-a-chance-to-win-open-source-award
added cool features to :

"All students, researchers and staff of institutions can use Mastodon via single sign-on with their own institution account.

Group accounts allow you to use Mastodon as an organisation, faculty or (research) group."

So, no reason for german universities not to setup an instance of their own with via @DFN

lemonldapng, to overwatch French
tek_dmn, to selfhosted
@tek_dmn@mastodon.tekdmn.me avatar

Okay nerds, it's time.

I'm about to move a few parts of my network off-site. Anyone have any input for getting LDAP-based authentication to work across locations?

Like, LDAP+TLS with mutual certificate authentication is just fine, but I don't like the idea of exposing an LDAP port. Though a firewall rule to only allow the other side's IP to access it would probably be okay.

Given that this side still needs to access some internal services, it also makes sense just to it or something, that gives me everything in a manner that I believe is secure, I've yet to hear of any breaks on its encryption... just that if the remote host is compromised I have quite a wide open attack surface.

Any ideas?

tek_dmn,
@tek_dmn@mastodon.tekdmn.me avatar

Additionally, is this what will push me to something like for my services?

I'll need to find a way to get and to work with OAUTH or something...

lemonldapng, to overwatch French
kidehen, to HowTo

Here's a screencast demonstration of Single Sign-On facilitated by loosely-coupling and , courtesy of the protocol.

https://youtu.be/DyRlar9PCvM

kidehen,

What's going on here?

I authenticate using @apple, @linkedin, etc.,
via their respective auth services, but retain control of the post-login identifier.

My Link In Bio style profile doc determines my canonical identity😀

lemonldapng, to opensource

🌟 This is the official Mastodon account for LemonLDAP::NG, a Web Single Sign On free software compatible with many open standards like CAS, SAML and OpenID Connect.

ℹ️ We will publish here information about releases and new features. Please follow us!

🌐 See also our official website: https://www.lemonldap-ng.org

boris, to fediverse
@boris@cosocial.ca avatar

A recap of 2 years of the Treehouse community, including details of challenges around hosting infrastructure.

Matches my conclusion: single sign on is a big blocker to running additional Fediverse services

Infra thread starts here https://social.treehouse.systems/@ariadne/110886130741103158

Anyone building tooling should be thinking about in their architecture.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • anitta
  • kavyap
  • DreamBathrooms
  • InstantRegret
  • magazineikmin
  • cubers
  • GTA5RPClips
  • thenastyranch
  • Youngstown
  • rosin
  • slotface
  • tacticalgear
  • ethstaker
  • modclub
  • JUstTest
  • Durango
  • everett
  • Leos
  • provamag3
  • mdbf
  • ngwrru68w68
  • cisconetworking
  • tester
  • osvaldo12
  • megavids
  • khanakhh
  • normalnudes
  • lostlight
  • All magazines