!NPRUEisLjcaMtHIzDr:kamax.io

mxisd

259 Members
Federated Matrix Identity Server | https://github.com/kamax-io/mxisd | Version: 0.8.2 | Dev discussions: #mxisd-dev:kamax.io | Related: #matrix-identity:matrix.org104 Servers

Load older messages


SenderMessageTime
28 Apr 2019
@park:mgp.ax.lt@park:mgp.ax.lt 😃 13:06:12
@eggy:eggy.ccMatt (eggy)fyi, when I run dpkg -i on the releases, it'll stop mxisd, but I have to manually restart it13:11:46
@max:kamax.ioMaximus that's expected as there might be changes needed 13:12:53
@max:kamax.ioMaximuslike in the config files13:13:11
@eggy:eggy.ccMatt (eggy)ok13:13:52
@eggy:eggy.ccMatt (eggy)Upgrade complete13:23:08
@max:kamax.ioMaximus Matt (eggy): ty for the feedbakc. Let me know if you encounter any issues with usage 13:33:31
@eggy:eggy.ccMatt (eggy)No problem13:36:06
@popi:matrix.nomagic.ukNomagic joined the room.17:52:57
@max:kamax.ioMaximus Nomagic: go for the questions :) 18:05:52
@popi:matrix.nomagic.ukNomagicyeah sorry, started reading the github again while room was loading18:06:29
@popi:matrix.nomagic.ukNomagic

so basically, I am looking for a way to use a Matrix server which:

  • use LDAP and maps username from DisplayName
  • does not allow internal search of other users via any attribute. I know mxisd thrives on mapping LDAP attributes, but for me the upside is more on hiding the real username, and having my own, local ID server
18:10:29
@popi:matrix.nomagic.ukNomagicCould mxsid fit my requirements?18:10:58
@max:kamax.ioMaximusyes and no... but let's clarify a few things18:12:19
@max:kamax.ioMaximus
  1. Display name is by definition a changing and non-unique value, which contains illegal characters for Matrix usernames. It doesn't make sense, so I'm thinking using the display name is a mean to an end, so you should tell me what you want to achieve, not how.
  2. About the search, do you mean directory search of 3PID lookups?
18:14:16
@popi:matrix.nomagic.ukNomagic
  1. Well, I want my users' usernames to be different than their real username, if that is possible.
  2. yes. It's not a huge deal, but it would be nice.
18:16:45
@max:kamax.ioMaximus
  1. the LDAP Identity store allows you to use whatever attribute you want as a username. Up to you to map it to whatever makes sense, it doesn't have to be their "real" usernames
  2. You answered "yes" but my question was a choice :)
18:18:20
@max:kamax.ioMaximus There was a typo for 2), it should read "directory search or 3PID lookups" 18:18:55
@popi:matrix.nomagic.ukNomagicoh, ok :)18:19:11
@popi:matrix.nomagic.ukNomagicdirectory search I guess I could limit it with LDAP ACLs18:19:38
@max:kamax.ioMaximusDirectory is an optional, opt-in feature of mxisd. It's not part of the Matrix specification for an Identity Server. So if you don't want it, there is nothing for you to do18:20:15
@popi:matrix.nomagic.ukNomagicWell I want to use it, but only because it allows same userid/password as the rest of services using LDAP auth. But other than that, I would like to keep users as unaware of each others as possible.18:23:04
@popi:matrix.nomagic.ukNomagicor maybe I misread, directory as in https://github.com/kamax-matrix/mxisd/blob/master/docs/features/directory.md18:25:03
@popi:matrix.nomagic.ukNomagicin that case ok yeah, I'll just not use it.18:25:31
@max:kamax.ioMaximusyes, that's opt-in. The overview section also explains what happens without, and with18:26:15
@popi:matrix.nomagic.ukNomagicok, sounds good.18:26:53
@popi:matrix.nomagic.ukNomagicregarding perf/stability, is there anything I should be aware of when switching to mxisd?18:27:55
@max:kamax.ioMaximusnot really. mxisd is used rarely by clients, compared to the homeserver18:28:44
@popi:matrix.nomagic.ukNomagicand... what's your current view on Riot? (I read through the github discussion on PRISM from last year)18:30:49
@popi:matrix.nomagic.ukNomagictalking about Riot-web and F-Droid app only18:33:56

Show newer messages


Back to Room ListRoom Version: