From 4ac5ad64bf7883c63ba02ecd1f1091cab08126f0 Mon Sep 17 00:00:00 2001 From: arf20 Date: Fri, 13 Feb 2026 21:21:56 +0100 Subject: LDAP jellyfin --- arfnet2.html | 82 ++++++++++++++++++++++++++++++++++++++++-------------------- 1 file changed, 55 insertions(+), 27 deletions(-) (limited to 'arfnet2.html') diff --git a/arfnet2.html b/arfnet2.html index f28d5c8..4abb8fd 100644 --- a/arfnet2.html +++ b/arfnet2.html @@ -82,7 +82,7 @@ and SSO
  • User certificates for extra secure clients mTLS
  • Steps

    - @@ -852,7 +851,7 @@ unbound config) -dark.arf20.com +default /d/FTPServer/ Allow only VPS and private @@ -1420,24 +1419,11 @@ VPS) 92.60.77.4
    -

    yero-debian VPS DMZ.192 -(yero)

    - -

    exo-debian VPS DMZ.195 (exo)

    +

    exo-vps VPS DMZ.195 (exo)

    -

    loofa-debian VPS DMZ.196 -(loofa)

    -

    *TODO

    Internal Name and Number Assignation Table

    @@ -2167,6 +2153,48 @@ Number Assignation Table +

    PKI, +authentication and authorization architecture

    +
                                  +-------+
    +                              | clCA  |
    +                              +-------+
    +                                  | 
    +                                  v 
    +                             +----------+          
    +      + - - - - - - - - - - -| OpenXPKI |          
    +                             +----------+          
    +      |                           | LDAPS cert and cert store
    +                                  v
    +      |       +-----------------------------------------------------------+
    +              |                      OpenLDAP                             |
    +      |       +-----------------------------------------------------------+
    +                ^           ^         ^         ^                
    +      |         |           |         |         |                
    +           +--------+ +----------+    |     +----------+              
    +      |    |  app   | |   app    |    | +-->| Kerberos |              
    +           | secure | | SSO-less |    | |   +----------+              
    +      |    +--------+ +----------+    | |                  
    +                ^             ^    +----------+ OAuth2  +---------+
    +      |         |             |    | Keycloak |-------->| app     |
    +                |             |    +----------+ /SAML   | SSO-ful |
    +      |         |             |      ^                  +---------+
    +                |             |      | 2FA                   
    +      |         |             |      |
    +           +--------+       +----------+
    +      + - >| client |       | clients  |
    +           +--------+       +----------+
    +       with cert from CA    password based 
    +

    Custom ARFNET software