Someone asked how to get Slack SAML SSO working with a Shibboleth IdP. It's pretty straightforward, despite the lack of SP metadata from Slack and the inability of Slack to import IdP metadata. Slack will attempt an authentication when you save its SAML configuration, so you need to set up the IdP first.
Just trying out our latest LAMP build.
In Yubikey PIV for SSH on Macs I described the full process for setting up and using Yubikeys for SSH. This is an abbreviated version that only describes how to use the Yubikey; the assumption is that some admin has already configured your Yubikey.
Kerberos, and therefore LDAP with GSSAPI, has issues with servers behind NAT, or anywhere the forward DNS lookup does not match the reverse DNS lookup. For instance, in our lab we have an OpenLDAP LDAP server: $ dig +noall +answer ldap.itlab.stanford.edu ldap.itlab.stanford.edu. 207 IN CNAME idp.itlab.stanford.edu. idp.itlab.stanford.edu. 200 IN A 22.214.171.124 However, since it's running … Continue reading Kerberos, LDAP, SSH, and NAT/AWS
Amazon documents how reserved instances and consolidated billing work together, but it's apparently still confusing because Bob's account has instances and is also the paying account. Our setup is different - the only resource created inside the paying account is the S3 bucket where Amazon posts our billing data. Here's my edited version of the … Continue reading AWS Reserved Instances and Consolidated Billing
While messing around with Raspberry Pis, Docker, bridged networks, wireless networks, etc. I managed to bork my Pis. If this happened at home, I could use a serial console cable, or plug the Pi into the spare HDMI port on my monitor and use a USB keyboard, or attach a USB SD card reader to … Continue reading I Broke My Pi’s Networking!
We generally use Duo for two factor authentication, including SSH. We have some scenarios where people would like to use two factor authentication, but Duo is considered too intrusive. For example, when using Duo for SSH-based git push and git pull there's no Duo prompt, it only works with Duo push, and you have to … Continue reading Yubikey PIV for SSH on Macs
We have a group who would like to use our internal University IDs to map campus users to Salesforce users for SSO. There are several ways to achieve this with a Shibboleth IdP and Salesforce, but this is the simplest.
Previously, I tried setting up a more efficient Shibboleth Attribute Authority - one where I could query for a specific attribute value for a specific attribute for a specific user (e.g. does firstname.lastname@example.org have an experimentId attribute with the value 2?). While you can add attribute values to the attribute elements in a SimpleAggregation AttributeResolver … Continue reading Authentication and Authorization with Shibboleth and LDAP
Shiny Toys Since it was Google I/O, every attendee received some shiny toys: a Nexus phone and Nexus 7 tablet, a Nexus Q streaming media player, and a Chromebox (the ChromeOS version of a Mac Mini). The Nexus Q doesn't really have any impact on IT, and it's an odd system: it costs over 3 … Continue reading Google I/O 2012