[Freeipa-devel] Hook Infrastructure services

Karl MacMillan kmacmill at redhat.com
Thu Jul 19 17:34:30 UTC 2007


On Mon, 2007-07-16 at 21:40 +0300, Ahmed Kamal wrote:
> Hi,
> Since I've heard of the freeipa project, and I've been very excited
> about it! This kind of "integrated" solution is very much needed in
> the foss world. IMO, identity servers usually become the heart of a
> network infrastructure (think AD in a Windows network), basically,
> something that all services have to integrate with and talk to! 
> 
> That's why I'm wondering if there are current plans to hook essential
> network services (I think postfix, squid for now) with IPA?
> Integration would be something like, people's email address, mail
> quota, authentication, certificates, would be stored in the ldap
> backend. For squid, I'm thinking about creating some ldap groups
> (nolimits, needsToEnterPassword, limitedSpeed, NoMP3s ... etc) then
> assigning users to those ldap groups, and have squid limit/block
> traffic accroding to such rules. 
> 
> I guess I'm asking if you guys see that as part of the freeipa
> project, as opposed to something external to your project ?!
> Personally, I hope you'll provide such infrastructure together with
> docs on how to configure various servers to hook into your
> infrastructure. If someone will be working on that, I would be
> interested to help if I can 
> 

I'm glad that you are excited about making it simple for other solutions
to use freeipa data - that is definitely something we are hoping will
happen. To your specific question of whether that kind of work is in
scope for freeipa, I would say that we want to enable that without
pulling all of that under the same project umbrella.

For example, we would like to make it possible for the kind of
configuration you describe to happen in the same management console as
the rest of freeipa (same infrastructure, auth, etc.). Perhaps through
some plugin mechanism.

So if you are willing, as we get the gui up and running perhaps you
could look for ways to make are tools extensible for your needs.

Thanks - Karl




More information about the Freeipa-devel mailing list