We're sorry but this page doesn't work properly without JavaScript enabled. Please enable it to continue.
Feedback

Passwordless Linux - where are we?

Formale Metadaten

Titel
Passwordless Linux - where are we?
Serientitel
Anzahl der Teile
542
Autor
Lizenz
CC-Namensnennung 2.0 Belgien:
Sie dürfen das Werk bzw. den Inhalt zu jedem legalen Zweck nutzen, verändern und in unveränderter oder veränderter Form vervielfältigen, verbreiten und öffentlich zugänglich machen, sofern Sie den Namen des Autors/Rechteinhabers in der von ihm festgelegten Weise nennen.
Identifikatoren
Herausgeber
Erscheinungsjahr
Sprache

Inhaltliche Metadaten

Fachgebiet
Genre
Abstract
Passwordless authentication is making a lot noise. Use of FIDO2/WebAuthn tokens and other passwordless means to login to web services is all the rage but there isn't that much available to make the technology usable without troubles for 'traditional' Linux systems, locally and remotely. For past several years FreeIPA and SSSD teams have been working on enabling end to end passwordless access in centralized and local environment, be it corporate or home deployment. This talk will go into details of our progress in passwordless access implementation for Linux systems. In 2022 FreeIPA project introduced ability to authenticate users against OAuth2 identity providers (IdPs). This functionality allows to obtain Kerberos credentials after authentication and authorization has been done by the external IdP. As many OAuth2 IdPs allow passwordless authentication with WebAuthn tokens, a true passwordless transition across Linux systems is now available, from login to console, raising privileges within PAM services (e.g. sudo access), to accessing remote systems over SSH. We hope to expand this support with native FIDO2/WebAuthn integration as well. The work is not complete yet and needs a lot of collaboration across multiple open source projects. Come to this talk to see a demo and discuss how we can improve our passwordless experience together.