29
Local Networks Go Global When Domain Names Collide
(krebsonsecurity.com)
c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.
THE RULES
Instance Rules
Community Rules
If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.
Learn about hacking
Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !cybersecurity@lemmy.capebreton.social !securitynews@infosec.pub !netsec@links.hackliberty.org !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub
Notable mention to !cybersecuritymemes@lemmy.world
Unrelated but this pissed me off.
The only Microsoft innovation there was Embracing, Extending, and Extinguishing LDAP and Kerberos.
I will NEVER forgive boomer admins for allowing that. I don't mean to be presumptive, maybe its just where I work, but old guard windows admins seem to be fucking lazy dipshits as a rule.
I've never met sysadmins/engies who give so little a shit about what they're setting up and why. If you only care that it works, and not how, why the fuck are you in this industry? Go get an MBA like the unskilled, uncaring sap you are and fuck off from my special interest.
Man that got derailed quickly lol, though I guess it explains why they're all using domains they don't own...
Is there any hope of return for Kerberos and LDAP?
FreeIPA?
Been using this in my homelab. Pretty great for Linux machines.
If you need to host for a windows network, samba can provide a Windows Server 2008 level AD DC, as well as print and file servers.
You could always install bare LDAP and Kerberos, but then again you could also try eating a cinderblock.
There are alternatives, but they all have their usecases and compromises in comparison. Most businesses want a cookiecutter one size fits all solution. AD is the closest thing.
From what I recall Kerberos didn't work all that well in environments with NAT so it is unlikely to replace modern single sign on systems like OpenID Connect.