Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
is there such a thing as a wpa2 enterprise cert that macos & ios just accept or do i just gotta slum it with a let's encrypt cert that has a subject i control and click ok on every three months

Adbot
ADBOT LOVES YOU

abigserve
Sep 13, 2009

this is a better avatar than what I had before

Cocoa Crispies posted:

it's not the network client to radius client thing that people want rest, it's the radius client to radius server part, and i bet you could design it so your authentication/accounting services would work in an edge cloud or something because *faaaart*

RADIUS is just a transport around EAP, as far as authentication is concerned. You could potentially replace radius authorisation & accounting with another protocol and, in fact, some solutions do this (some VPN' solutions use Radius to auth the user, then LDAP to then map that user to groups, for example).

What you could do, is make the NAS devices capable of authenticating users by having them parse and respond to EAP messages, as opposed to forwarding them to a AAA server, which then lets you do whatever the gently caress you want, and many solutions like that do exist out there. Contemporary VPN solutions, for example, often support SAML, LDAP, certificate based auth, etc without the use of RADIUS.

Nomnom Cookie
Aug 30, 2009



abigserve posted:

(some VPN' solutions use Radius to auth the user, then LDAP to then map that user to groups, for example).

fuuuuuck palo alto

e: palo alto also uses ldap for group mapping when your auth method supports returning group membership, e.g. saml. every single thing about the product is like that

abigserve
Sep 13, 2009

this is a better avatar than what I had before

Nomnom Cookie posted:

fuuuuuck palo alto

e: palo alto also uses ldap for group mapping when your auth method supports returning group membership, e.g. saml. every single thing about the product is like that

nah they'll map groups onto fuckin anything if there is a username in the db and group mapping is configured. You can do it that way too though, where the authentication server returns the group membership but then it depends on the protocol (RADIUS/SAML/whatever)

Jimmy Carter
Nov 3, 2005

THIS MOTHERDUCKER
FLIES IN STYLE
TIL iOS and Android support using QR codes for sharing wifi credentials. Go help your local bar with this.

Only registered members can see post attachments!

Nomnom Cookie
Aug 30, 2009



abigserve posted:

nah they'll map groups onto fuckin anything if there is a username in the db and group mapping is configured. You can do it that way too though, where the authentication server returns the group membership but then it depends on the protocol (RADIUS/SAML/whatever)

like hell am I gonna dig through the docs again but this is something that was specifically called out. I remember because I was still at a point where I was capable of being astonished by Palo Alto. you can do saml auth for globalprotect but the firewall will ignore any groups procided by the saml callback. also groups obtained from group mapping can’t be used as gateway selection criteria, presumably because group mapping hasn’t happened yet

akadajet
Sep 14, 2003


i'm not scanning that goatse link. i know better

Turnquiet
Oct 24, 2002

My friend is an eloquent speaker.

my radius beef is when apps try to use if to user authn. the stuff i build with my stupid fartastic cloud deployments is premised upon ephemeral infrastructure, so when loving cyberark wants to use radius for user auth and my pam guy just assumes i will turn on my pingfederate's radius capabilities i get irked because i am stupidly trying to get us into the cloud like what the last 8 years of c-levels have said is the strategy, which is a place where we can't guarantee a fixed ip address. gently caress you, in preparation for zero trust we are using federated protocols for all authentication, so use saml2 or oidc or die in a fire- looking at you, microsoft, who literally built azuread on openid flows but still demands ws-trust/ws-fed if you want to retain control of your idp.

abigserve
Sep 13, 2009

this is a better avatar than what I had before

Turnquiet posted:

my radius beef is when apps try to use if to user authn. the stuff i build with my stupid fartastic cloud deployments is premised upon ephemeral infrastructure, so when loving cyberark wants to use radius for user auth and my pam guy just assumes i will turn on my pingfederate's radius capabilities i get irked because i am stupidly trying to get us into the cloud like what the last 8 years of c-levels have said is the strategy, which is a place where we can't guarantee a fixed ip address. gently caress you, in preparation for zero trust we are using federated protocols for all authentication, so use saml2 or oidc or die in a fire- looking at you, microsoft, who literally built azuread on openid flows but still demands ws-trust/ws-fed if you want to retain control of your idp.

there is no legitimate use case for RADIUS for user auth on web apps aside from "we already have radius servers", that's dumb as hell (yes I am aware that most MFA providers use on-prem radius proxies to insert MFA into auth flows that would otherwise not be supported)

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Turnquiet posted:

looking at you, microsoft, who literally built azuread on openid flows but still demands ws-trust/ws-fed if you want to retain control of your idp.

weird that Microsoft would combine two unfashionable protocols in a baffling way

Nomnom Cookie
Aug 30, 2009



Turnquiet posted:

my radius beef is when apps try to use if to user authn. the stuff i build with my stupid fartastic cloud deployments is premised upon ephemeral infrastructure, so when loving cyberark wants to use radius for user auth and my pam guy just assumes i will turn on my pingfederate's radius capabilities i get irked because i am stupidly trying to get us into the cloud like what the last 8 years of c-levels have said is the strategy, which is a place where we can't guarantee a fixed ip address. gently caress you, in preparation for zero trust we are using federated protocols for all authentication, so use saml2 or oidc or die in a fire- looking at you, microsoft, who literally built azuread on openid flows but still demands ws-trust/ws-fed if you want to retain control of your idp.

are you on aws, because you definitely can get a fixed IP on aws

graph
Nov 22, 2006

aaag peanuts

Nomnom Cookie posted:

are you on aws, because you definitely can get a fixed IP on aws

but this costs money

Nomnom Cookie
Aug 30, 2009



graph posted:

but this costs money

nah just dont delete the eni

cowboy beepboop
Feb 24, 2001

asdf

abigserve
Sep 13, 2009

this is a better avatar than what I had before

my stepdads beer posted:

we use RADIUS for PPPoE because cisco's IPoE is buggy af on one of the agg routers we use and inertia. sorry about your 8 bytes of overhead everyone.

PPPoE is real good for certain situations and realising you can functionally operate as an ISP for stuff like tenants and student accommodation is baller as hell

cowboy beepboop
Feb 24, 2001

yeah it works okay and it would be far too annoying to change at this point

Bored Online
May 25, 2009

We don't need Rome telling us what to do.
in all of yospos this thread most closely aligns with my profession and it js also the thread i understand the least in

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Bored Online posted:

in all of yospos this thread most closely aligns with my profession and it js also the thread i understand the least in

:discourse:

vanity slug
Jul 20, 2010

Bored Online posted:

in all of yospos this thread most closely aligns with my profession and it js also the thread i understand the least in

ignorance is bliss

Turnquiet
Oct 24, 2002

My friend is an eloquent speaker.

Nomnom Cookie posted:

are you on aws, because you definitely can get a fixed IP on aws

you get 5 elastic IPs per account, and they cost money and are usually (and justifiably) reserved by your cloud folk for some other, stupider use cases. just counting on never destroying the eni almost sounds like it would work if you didn't design your cluster for scaling and you connected directly to a combo admin/engine instance. for a clustered deployment you have n engines fielding requests, and those nodes attach to an nlb which is what the dns resolves to. and you don't get to control when/how was cycles your ip addresses behind your nlb/albs.

i came up w/ a design that would allow us to fake a fixed ip via a proxy to our cluster, but it is an awful lot of effort when user auth should move on, and with oidc capable fo doing browser/mobile/back channel stuff i don't get why vendors haven't matured (psych i do, it's laziness/effort/money).

Nomnom Cookie
Aug 30, 2009



Turnquiet posted:

you get 5 elastic IPs per account, and they cost money and are usually (and justifiably) reserved by your cloud folk for some other, stupider use cases. just counting on never destroying the eni almost sounds like it would work if you didn't design your cluster for scaling and you connected directly to a combo admin/engine instance. for a clustered deployment you have n engines fielding requests, and those nodes attach to an nlb which is what the dns resolves to. and you don't get to control when/how was cycles your ip addresses behind your nlb/albs.

i came up w/ a design that would allow us to fake a fixed ip via a proxy to our cluster, but it is an awful lot of effort when user auth should move on, and with oidc capable fo doing browser/mobile/back channel stuff i don't get why vendors haven't matured (psych i do, it's laziness/effort/money).

how much radius are you doing that a single instance isn't enough, holy poo poo

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Nomnom Cookie posted:

how much radius are you doing that a single instance isn't enough, holy poo poo

Comcast has a nationwide wpa2 enterprise network

Nomnom Cookie
Aug 30, 2009



Cocoa Crispies posted:

Comcast has a nationwide wpa2 enterprise network

they need to do more than several thousand requests/sec?

Bloody
Mar 3, 2013

Turnquiet
Oct 24, 2002

My friend is an eloquent speaker.

Nomnom Cookie posted:

how much radius are you doing that a single instance isn't enough, holy poo poo

i don't build for radius at scale, i build for saml/oauth/oidc at scale.

abigserve
Sep 13, 2009

this is a better avatar than what I had before

Bored Online posted:

in all of yospos this thread most closely aligns with my profession and it js also the thread i understand the least in

Proast about what you are doing then

Infrastructure and networking Jobs cum in different shapes and sizes but one way or another they are all terrible

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Nomnom Cookie posted:

they need to do more than several thousand requests/sec?

multiple instances aren't just for throughput and radius isn't just for yes/no authentication, so if there's a bunch of like accounting traffic that needs to be sharted that's going to mean you need to fan out those requests to a handful of hosts

Nomnom Cookie
Aug 30, 2009



Cocoa Crispies posted:

multiple instances aren't just for throughput and radius isn't just for yes/no authentication, so if there's a bunch of like accounting traffic that needs to be sharted that's going to mean you need to fan out those requests to a handful of hosts

so it gets a load balancer and a dozen instances because thats how things are done in 2019. ok, fair enough

Turnquiet
Oct 24, 2002

My friend is an eloquent speaker.

...it can get stupider depending on the authentication product you are working with.

i had a dream of a global authentication service that would determine the origination point of the request and georoute it to a cluster geographically close to the requestor to issue the auth token. this was easy enough to build using route53 and cloud formation with a product like pingfed- but the next bit would be figuring out how to do re-auth without generating consensus across all the global nodes once again. fortunately, pingfed allows you to do something called regional sub-clustering where you can validate existing tokens using a consensus algorithm across nodes within the indicated region (e.g. ap-southeast-12 has 3 nodes, and those 3 nodes only need to achieve consensus amongst themselves to validate an existing authentication session for some contractors authenticating our of noida india). so yeah, i need to run like 9 engines across 3 regions because the minimum count of nodes in a sub-cluster required to generate consensus on re-authentication is 3.

funny thing is i like the pingfederate. like, a lot.

it IS wasteful after a fashion, but depending upon what you care about running a couple extra nodes to give folk a good ux is worth the extra couple hundred dollars a year.

yeah, i don't know much (like most overpaid idiots)- i'm an identity guy who bumbled into devops/cloud/ephemeral infrastructural to try to spare himself late night ops support calls. and it turns out i built something that did the job pretty well :shrug:

Bored Online
May 25, 2009

We don't need Rome telling us what to do.

abigserve posted:

Proast about what you are doing then

Infrastructure and networking Jobs cum in different shapes and sizes but one way or another they are all terrible

i reset passwords, read hashicorp manuals, and write awful python to automate administrative tasks. its actually pretty chill cause the smarties let me pretend i do infrastructure sometimes

Partycat
Oct 25, 2004

that is how eduroam operates


https://www.eduroam.org/how/

cowboy beepboop
Feb 24, 2001

thinking about doing the juniper service provider track to brush up, anyone know any decent online courses? also I only have cisco experience so it will be nice to branch out a bit

distortion park
Apr 25, 2011


Partycat posted:

that is how eduroam operates


https://www.eduroam.org/how/

"3 easy steps"

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki
why do so many linux systems still default to absurdly low open file limits. who is running anything approximating a multiuser system in tyool 2020.

you would think overriding this would be a thing infra people bake into their images but nope. not even if you put a nice "HEY THIS SETTING IS hosed" message into application startup on the assumption they haven't

my homie dhall
Dec 9, 2010

honey, oh please, it's just a machine
ah, the thread of my people

my homie dhall
Dec 9, 2010

honey, oh please, it's just a machine
any of y’all tenants trying to get you to run a god dang “service mesh”? idk what real problems these things are trying to solve, I think they’re just inventing stuff for themselves to do

carry on then
Jul 10, 2010

by VideoGames

(and can't post for 10 years!)

Ploft-shell crab posted:

any of y’all tenants trying to get you to run a god dang “service mesh”? idk what real problems these things are trying to solve, I think they’re just inventing stuff for themselves to do
MICROSERVICES!!!!!

akadajet
Sep 14, 2003

carry on then posted:

MICROSERVICES!!!!!

post/avatar synergy

MrMoo
Sep 14, 2000

CMYK BLYAT! posted:

why do so many linux systems still default to absurdly low open file limits. who is running anything approximating a multiuser system in tyool 2020.

Also with Docker images, so easy to eat up hundreds of sockets with AWS health-check and client connections across Route 53. RHEL has been incredibly conservative on its settings for a long time.

Adbot
ADBOT LOVES YOU

Progressive JPEG
Feb 19, 2003

Ploft-shell crab posted:

any of y’all tenants trying to get you to run a god dang “service mesh”? idk what real problems these things are trying to solve, I think they’re just inventing stuff for themselves to do

it’s purely to increase latency and resource overhead and to put more money in bezos’ pocket

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply