this post was submitted on 24 Aug 2024
29 points (100.0% liked)
Cybersecurity
5835 readers
161 users here now
c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.
THE RULES
Instance Rules
- Be respectful. Everyone should feel welcome here.
- No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
- No Ads / Spamming.
- No pornography.
Community Rules
- Idk, keep it semi-professional?
- Nothing illegal. We're all ethical here.
- Rules will be added/redefined as necessary.
If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.
Learn about hacking
Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]
Notable mention to [email protected]
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Yeah I will make sure to use OpenLDAP/FreeIPA at home. I'd rather play along with RedHat's bullshit than Microsoft's bullshit
That's what I've been doing for a good bit now.
I used to do a split environment on ad but I didn't feel I was really getting anything out of windows, other than ease of use with TrueNAS.
Still haven't gotten TrueNAS working with FreeIPA, but running a NAS off of rocky isn't too bad either if you don't mind the extra setup.
The nice thing about downstream distros is you don't actually have to deal with redhats shit to use their stuff.
I dropped truenas, ran fedora server + zfs dkms module. It's been perfectly fine for a couple of years (even accounting for that nasty silent data corruption bug..)
And domain permissions work properly now. People have been asking Ix for proper support for IPA for over a decade, they aren't interested in solving it.
Which is why I'm no longer interested in supporting them lol.
You don't get to run a commercial entity under the guise of open source software, and giving back to the community, while prioritizing inter-compatibility with the king of EEE over the most popular FLOSS alternative.
Rocky has been good to me, but I still miss centos.
Honestly the only thing I've had trouble getting working with freeIPA with no alternative is some sort of centralized ROM management. Then again they all kinda lack any sync features with retroarch which is what would really bring me to them anywho.
TrueNAS is just better QoL for people who don't want to deal with the cli all the time. I don't care so I don't need it. I have a separate k8s cluster anyway so it's pretty much pointless for me other than specific things like the ACLs which the GUI is good at
Pretty much. Its nice but I find trying to get it to do anything other than cookie cutter operations requires you to not only go around the GUI, but in many cases break it.
Also lotta shit that was supposed to work sucked too. The GUI always seemed to have a 50% chance of clobbering my ACLs when editing them, and encryption was either entirely password based, or the keys where stored with no passphrase on an unencrypted dataset.
My rocky nas has Luks on mdraid for the root which hold the keys for the zfs pools, and CLI based acl management is pretty ezpz once you learn it.