<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[LDAP&#x2F;AD Server]]></title><description><![CDATA[<p dir="auto">Hello.</p>
<p dir="auto">I would really love to see an LDAP Server be integrated into Cloudron, where Users can either be selected from Cloudron, or created independently.</p>
]]></description><link>https://forum.cloudron.io/topic/2189/ldap-ad-server</link><generator>RSS for Node</generator><lastBuildDate>Mon, 08 Jun 2026 02:54:33 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/2189.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 26 Feb 2020 10:06:17 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Fri, 18 Mar 2022 18:20:30 GMT]]></title><description><![CDATA[<p dir="auto">Sounds like this is now done and live with 7.1?</p>
<ul>
<li><a href="https://forum.cloudron.io/topic/6654/cloudron-7-1-released">https://forum.cloudron.io/topic/6654/cloudron-7-1-released</a></li>
<li><a href="https://blog.cloudron.io/cloudron-7-1-released/" target="_blank" rel="noopener noreferrer nofollow ugc">https://blog.cloudron.io/cloudron-7-1-released/</a></li>
<li><a href="https://docs.cloudron.io/user-management/#directory-server" target="_blank" rel="noopener noreferrer nofollow ugc">https://docs.cloudron.io/user-management/#directory-server</a></li>
</ul>
]]></description><link>https://forum.cloudron.io/post/44923</link><guid isPermaLink="true">https://forum.cloudron.io/post/44923</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Fri, 18 Mar 2022 18:20:30 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Sun, 07 Nov 2021 18:22:26 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/robi" aria-label="Profile: robi">@<bdi>robi</bdi></a> said in <a href="/post/36293">LDAP/AD Server</a>:</p>
<blockquote>
<p dir="auto">It looks like my friends at <a href="http://Aporeto.com" target="_blank" rel="noopener noreferrer nofollow ugc">Aporeto.com</a> got acquired by PaloAlto Networks. They have an OSS projects called Trireme - <a href="https://github.com/aporeto-inc" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/aporeto-inc</a></p>
</blockquote>
<p dir="auto">I think this needs to be revisited for Cloudron 7+ to easily manage which app can talk to which by policy. /cc <a class="plugin-mentions-group plugin-mentions-a" href="/groups/staff" aria-label="Profile: staff">@<bdi>staff</bdi></a></p>
]]></description><link>https://forum.cloudron.io/post/38929</link><guid isPermaLink="true">https://forum.cloudron.io/post/38929</guid><dc:creator><![CDATA[robi]]></dc:creator><pubDate>Sun, 07 Nov 2021 18:22:26 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Sun, 07 Nov 2021 14:57:45 GMT]]></title><description><![CDATA[<p dir="auto">At my place of work we developed a small golang ldap server some months ago. I have spent some time this weekend packaging this project up for cloudron and also have included an openid connect provider.</p>
<p dir="auto">The ldap server is really simple, it basically takes an existing ldif as input and serves this out to any authenticated user. It does not even allow modifying items through e.g. ldapmodify, but requires the ldif on disk to be changed.</p>
<p dir="auto">LDAP and OpenID Connect Provider are part of the <a href="https://libregraph.github.io/" target="_blank" rel="noopener noreferrer nofollow ugc">https://libregraph.github.io/</a> project.</p>
<p dir="auto">If someone is interested in trying out the app please send me a direct message.</p>
]]></description><link>https://forum.cloudron.io/post/38925</link><guid isPermaLink="true">https://forum.cloudron.io/post/38925</guid><dc:creator><![CDATA[fbartels]]></dc:creator><pubDate>Sun, 07 Nov 2021 14:57:45 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Fri, 10 Sep 2021 00:33:03 GMT]]></title><description><![CDATA[<p dir="auto">It looks like my friends at <a href="http://Aporeto.com" target="_blank" rel="noopener noreferrer nofollow ugc">Aporeto.com</a> got acquired by PaloAlto Networks. They have an OSS projects called Trireme - <a href="https://github.com/aporeto-inc" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/aporeto-inc</a></p>
<p dir="auto">Trireme, an open-source library curated by Aporeto to provide cryptographic isolation for cloud-native applications. Trireme-lib is a Zero-Trust networking library that makes it possible to setup security policies and segment applications by enforcing end-to-end authentication and authorization without the need for complex control planes or IP/port-centric ACLs and east-west firewalls.</p>
<p dir="auto">Trireme-lib supports both containers and Linux processes as well user-based activation, and it allows security policy enforcement between any of these entities.</p>
<p dir="auto">A good tool for Cloudron as well as securing LDAP across machines.</p>
]]></description><link>https://forum.cloudron.io/post/36293</link><guid isPermaLink="true">https://forum.cloudron.io/post/36293</guid><dc:creator><![CDATA[robi]]></dc:creator><pubDate>Fri, 10 Sep 2021 00:33:03 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Wed, 08 Sep 2021 21:11:00 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/fbartels" aria-label="Profile: fbartels">@<bdi>fbartels</bdi></a> Thank you kindly! @vladimir-d is working on this issues, and we may try pulling in extra help too.</p>
<p dir="auto">All ideas are welcome as we are heads-deep in plugging the knock-on consequences if these still unsolved things.</p>
<p dir="auto">I wish I could find the time to show more people what they will get back from us in development investment, but I can't do any of these things while blocker issues have become day &amp; night urgencies.</p>
]]></description><link>https://forum.cloudron.io/post/36243</link><guid isPermaLink="true">https://forum.cloudron.io/post/36243</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Wed, 08 Sep 2021 21:11:00 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Wed, 08 Sep 2021 18:29:47 GMT]]></title><description><![CDATA[<p dir="auto">Not sure if it was already mentioned here, but there is <a href="https://github.com/mitchellurgero/cloudron-ldap-proxy" target="_blank" rel="noopener noreferrer nofollow ugc">https://github.com/mitchellurgero/cloudron-ldap-proxy</a> by <a class="plugin-mentions-user plugin-mentions-a" href="/user/murgero" aria-label="Profile: murgero">@<bdi>murgero</bdi></a>. It's downside is however that the connection is not encrypted.</p>
<p dir="auto">A potential improvement over this would be to have a small app, that generates a custom ssl ca and serves its root cert over a small webserver. Then you use the same ca to provide a certificate to stunnel, which simply passes through the otherwise internal Cloudron ldap.</p>
<p dir="auto">Then at least the communication would be secured, but it may still be an idea to limit who can actually reach that port through your firewall.</p>
<p dir="auto">As a custom build this is quite easily doable, as an official app its probably too special.</p>
]]></description><link>https://forum.cloudron.io/post/36237</link><guid isPermaLink="true">https://forum.cloudron.io/post/36237</guid><dc:creator><![CDATA[fbartels]]></dc:creator><pubDate>Wed, 08 Sep 2021 18:29:47 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Wed, 08 Sep 2021 16:33:00 GMT]]></title><description><![CDATA[<p dir="auto">Related: <a href="https://forum.cloudron.io/topic/5636/quite-urgent-accessing-cloudron-ldap-from-an-external-instance-of-espocrm">https://forum.cloudron.io/topic/5636/quite-urgent-accessing-cloudron-ldap-from-an-external-instance-of-espocrm</a></p>
]]></description><link>https://forum.cloudron.io/post/36234</link><guid isPermaLink="true">https://forum.cloudron.io/post/36234</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Wed, 08 Sep 2021 16:33:00 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Wed, 23 Jun 2021 17:39:40 GMT]]></title><description><![CDATA[<p dir="auto">Thanks <a class="plugin-mentions-user plugin-mentions-a" href="/user/luckow" aria-label="Profile: luckow">@<bdi>luckow</bdi></a></p>
<p dir="auto">Yes, I have seen the question that <a class="plugin-mentions-user plugin-mentions-a" href="/user/brutalbirdie" aria-label="Profile: BrutalBirdie">@<bdi>BrutalBirdie</bdi></a> posted at <a href="https://help.univention.com/t/restrict-username-allowed-characters/17280" target="_blank" rel="noopener noreferrer nofollow ugc">https://help.univention.com/t/restrict-username-allowed-characters/17280</a> as well. But no, I am not aware of a way to limit characters with the ucs self registration.</p>
]]></description><link>https://forum.cloudron.io/post/32970</link><guid isPermaLink="true">https://forum.cloudron.io/post/32970</guid><dc:creator><![CDATA[fbartels]]></dc:creator><pubDate>Wed, 23 Jun 2021 17:39:40 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Wed, 23 Jun 2021 16:56:19 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/fbartels" aria-label="Profile: fbartels">@<bdi>fbartels</bdi></a> Top post. Thank you.<br />
One (maybe) last question: do you have a solution for the different allowed characters in UCS and Cloudron usernames? My idea is to have some kind of profile with only allowed characters on the UCS side. See <a href="https://docs.cloudron.io/user-management/#valid-usernames" target="_blank" rel="noopener noreferrer nofollow ugc">https://docs.cloudron.io/user-management/#valid-usernames</a> for characters allowed in Cloudron.</p>
]]></description><link>https://forum.cloudron.io/post/32967</link><guid isPermaLink="true">https://forum.cloudron.io/post/32967</guid><dc:creator><![CDATA[luckow]]></dc:creator><pubDate>Wed, 23 Jun 2021 16:56:19 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Tue, 22 Jun 2021 21:10:39 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> said in <a href="/post/30175">LDAP/AD Server</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/robi" aria-label="Profile: robi">@<bdi>robi</bdi></a> said in <a href="/post/30132">LDAP/AD Server</a>:</p>
<blockquote>
<p dir="auto">VPN to Cloudron for LDAP is reasonable.</p>
</blockquote>
<p dir="auto">I think that would then mean that the external app has to be in the VPN, no?</p>
</blockquote>
<p dir="auto">I'll be releasing my VPN Client for Cloudron over summer if that helps. <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f605.png?v=74f512c8ff7" class="not-responsive emoji emoji-android emoji--sweat_smile" style="height:23px;width:auto;vertical-align:middle" title="😅" alt="😅" /></p>
]]></description><link>https://forum.cloudron.io/post/32959</link><guid isPermaLink="true">https://forum.cloudron.io/post/32959</guid><dc:creator><![CDATA[Lonkle]]></dc:creator><pubDate>Tue, 22 Jun 2021 21:10:39 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Mon, 21 Jun 2021 20:04:45 GMT]]></title><description><![CDATA[<p dir="auto">I have also made a <a href="https://blog.9wd.eu/posts/cloudron-ucs/" target="_blank" rel="noopener noreferrer nofollow ugc">writeup of this on my blog</a></p>
]]></description><link>https://forum.cloudron.io/post/32938</link><guid isPermaLink="true">https://forum.cloudron.io/post/32938</guid><dc:creator><![CDATA[fbartels]]></dc:creator><pubDate>Mon, 21 Jun 2021 20:04:45 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Fri, 11 Jun 2021 19:22:46 GMT]]></title><description><![CDATA[<p dir="auto">Replying here since this is the largest collection of ldap specific topics on this forum.</p>
<p dir="auto">My cloudron installation is around longer than the cloudron external ldap support. When configuring an external ldap users with a conflicting username (same username already exists on cloudron) get skipped on synchronisation. Which is generally a good thing. But I still wanted to transfer password management for some of these users to my ldap.</p>
<p dir="auto">This can be done by running the following command from the shell of the cloudron host (only change <code>the-user-i-want-to-change</code> to the actual user):</p>
<pre><code class="language-bash">mysql -uroot -ppassword -e 'update users set source="ldap" where username="the-user-i-want-to-change";'
</code></pre>
]]></description><link>https://forum.cloudron.io/post/32643</link><guid isPermaLink="true">https://forum.cloudron.io/post/32643</guid><dc:creator><![CDATA[fbartels]]></dc:creator><pubDate>Fri, 11 Jun 2021 19:22:46 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Wed, 28 Apr 2021 22:34:13 GMT]]></title><description><![CDATA[<p dir="auto">Thank you both <a class="plugin-mentions-user plugin-mentions-a" href="/user/luckow" aria-label="Profile: luckow">@<bdi>luckow</bdi></a> &amp; <a class="plugin-mentions-user plugin-mentions-a" href="/user/fbartels" aria-label="Profile: fbartels">@<bdi>fbartels</bdi></a> I feel this thread is a useful repo for gathering all the experience and getting this it's own Cloudron documentation.</p>
<p dir="auto">We'll add anything we've learned and steps along the way to get whatever we can working.</p>
<p dir="auto">Something I'm not sure that anyone knew before was that both Hetzner and Contabo will offer access to the custom ISO to install from if you ask them nicely and send them the correct public link to it.</p>
<p dir="auto">Hetzner I know we can create a Network within, I've  not needed to try that with Contabo yet though.</p>
<p dir="auto">I've also learned about Proxmox, and that could be worthy of it's own dedicated how-to thread and documentation here, given the utility it can offer self-hosting on bare metal on premises or leased.</p>
<p dir="auto">The community experience here is priceless!</p>
]]></description><link>https://forum.cloudron.io/post/30527</link><guid isPermaLink="true">https://forum.cloudron.io/post/30527</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Wed, 28 Apr 2021 22:34:13 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Wed, 28 Apr 2021 19:24:26 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> said in <a href="/post/30499">LDAP/AD Server</a>:</p>
<blockquote>
<p dir="auto">Does this support SSO?</p>
</blockquote>
<p dir="auto">That is why I suggested to run UCS in your local network. You could SSO with Kerberos from your workstation and then be directly signed into configured saml and oidc applications (and Kerberos of course as well). This only has two downsides:</p>
<ul>
<li>their sso clashes with their lets encrypt app, which requires manual work after the first certificate has been retrieved.</li>
<li>this all does not touch Cloudron anymore, except you mod applications on Cloudron for one of the above auth methods</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/30521</link><guid isPermaLink="true">https://forum.cloudron.io/post/30521</guid><dc:creator><![CDATA[fbartels]]></dc:creator><pubDate>Wed, 28 Apr 2021 19:24:26 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Wed, 28 Apr 2021 14:08:22 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a></p>
<ol>
<li>It's only creates users in Cloudron, if the user exists in UCS. This is where the self-service platform comes in.</li>
<li>No. (not in my understanding of the external LDAP connection from Cloudron side).</li>
<li>good question <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=74f512c8ff7" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /> If you've tried it out, please share your wisdom with us.</li>
</ol>
<p dir="auto">Attention:</p>
<ul>
<li>The allowed characters for UCS &amp; Cloudron users are different. You can create UCS users which never allowed to login into Cloudron because of the character limitations in Cloudron. <a href="https://docs.cloudron.io/user-management/#valid-usernames" target="_blank" rel="noopener noreferrer nofollow ugc">https://docs.cloudron.io/user-management/#valid-usernames</a><br />
Sorry I never managed a kind of policy to disallow special characters on UCS.</li>
<li>The email address which Cloudron needs (without an email, the user doesn't exist) is labeled <code>primary email address</code>on UCS side.</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/30501</link><guid isPermaLink="true">https://forum.cloudron.io/post/30501</guid><dc:creator><![CDATA[luckow]]></dc:creator><pubDate>Wed, 28 Apr 2021 14:08:22 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Wed, 28 Apr 2021 13:46:10 GMT]]></title><description><![CDATA[<p dir="auto">OK, so we have Cloudron and Univention Corporate Server (UCS) connected and seemingly working.</p>
<p dir="auto">A couple of questions:</p>
<ol>
<li>"Automatically create users when they login to Cloudron" - is this just creating Cloudron Users when someone tries to login that has a USC login/pass but not yet a Cloudron User?</li>
<li>Is there any way to sync Cloudron Users upstream to UCS?</li>
<li>Does this support SSO?
<ul>
<li><a href="https://www.univention.com/blog-en/2018/06/one-password-for-all-services-and-networks-with-single-sign-on/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.univention.com/blog-en/2018/06/one-password-for-all-services-and-networks-with-single-sign-on/</a></li>
</ul>
</li>
</ol>
]]></description><link>https://forum.cloudron.io/post/30499</link><guid isPermaLink="true">https://forum.cloudron.io/post/30499</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Wed, 28 Apr 2021 13:46:10 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Mon, 26 Apr 2021 09:38:43 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/friep2" aria-label="Profile: friep2">@<bdi>friep2</bdi></a> haha, someone has to be the lucky person to start any thread.</p>
<p dir="auto">Just happens to be one I need to get to a "once and for all" solution now as it's a PITA without, nothing more frustrating than time wasted that doesn't need to be.</p>
<p dir="auto">Making progress with the UCS setup alternative, and will try and post a step-by-step guide once we've gathered all those good pointers and followed it all through to working.</p>
]]></description><link>https://forum.cloudron.io/post/30376</link><guid isPermaLink="true">https://forum.cloudron.io/post/30376</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Mon, 26 Apr 2021 09:38:43 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Mon, 26 Apr 2021 09:28:40 GMT]]></title><description><![CDATA[<p dir="auto">uff just having read the whole thread: i didn't want to open up a Pandoras box with my comment for anyone, especially <a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a>. <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f604.png?v=74f512c8ff7" class="not-responsive emoji emoji-android emoji--smile" style="height:23px;width:auto;vertical-align:middle" title=":D" alt="😄" /> Thanks for looking into it!!<br />
it's definitely more a nice-to-have feature for our organisation, so its absence won't keep me from pursuing cloudron <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=74f512c8ff7" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p>
]]></description><link>https://forum.cloudron.io/post/30375</link><guid isPermaLink="true">https://forum.cloudron.io/post/30375</guid><dc:creator><![CDATA[friep2]]></dc:creator><pubDate>Mon, 26 Apr 2021 09:28:40 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Mon, 26 Apr 2021 09:20:39 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/infogulch" aria-label="Profile: infogulch">@<bdi>infogulch</bdi></a> to be fair i did not look too much into the process of wrapping up apps in cloudron. if it's quite easy and flexible that could be an alternative for us <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=74f512c8ff7" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p>
<p dir="auto">Still, sometimes i guess it's just easier / more convenient to keep things separated and integrate via LDAP. E.g. in cases where you might not want to give people access to the cloudron server (which i suppose they'd need to deploy the app).</p>
]]></description><link>https://forum.cloudron.io/post/30374</link><guid isPermaLink="true">https://forum.cloudron.io/post/30374</guid><dc:creator><![CDATA[friep2]]></dc:creator><pubDate>Mon, 26 Apr 2021 09:20:39 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Fri, 23 Apr 2021 17:28:11 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/fbartels" aria-label="Profile: fbartels">@<bdi>fbartels</bdi></a> I keep trying to forget my Windows years but it seems the rest of the world is still there <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f605.png?v=74f512c8ff7" class="not-responsive emoji emoji-android emoji--sweat_smile" style="height:23px;width:auto;vertical-align:middle" title=":sweat_smile:" alt="😅" /></p>
<p dir="auto">We'll keep plugging away at this. Considering all we're looking for is just one master LDAP server. It seems a ripe opportunity for Cloudron to be that. Having a whole other VPS, OS &amp; Platform for a single feature is kinda inefficient, but then the other options all look like vendor-lockin options.</p>
]]></description><link>https://forum.cloudron.io/post/30297</link><guid isPermaLink="true">https://forum.cloudron.io/post/30297</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Fri, 23 Apr 2021 17:28:11 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Fri, 23 Apr 2021 17:06:18 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> said in <a href="/post/30272">LDAP/AD Server</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/fbartels" aria-label="Profile: fbartels">@<bdi>fbartels</bdi></a> Thanks - so far UCS is a long way from intuitive. I feel like I got invited around for dinner and pointed at the kitchen while everyone else already ate.</p>
</blockquote>
<p dir="auto">A bit off topic but I love your analogies <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=74f512c8ff7" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":-)" alt="🙂" /></p>
]]></description><link>https://forum.cloudron.io/post/30295</link><guid isPermaLink="true">https://forum.cloudron.io/post/30295</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Fri, 23 Apr 2021 17:06:18 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Fri, 23 Apr 2021 12:08:49 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> said in <a href="/post/30272">LDAP/AD Server</a>:</p>
<blockquote>
<p dir="auto">so far UCS is a long way from intuitive</p>
</blockquote>
<p dir="auto">Yes, I can imagine if you have no experience with windows domain administration there are a lot of foreign concepts in ucs. Plus its a system that has evolved over more than a decade by now so it lacks a few more modern approaches that Cloudron serves very well.</p>
<p dir="auto">On the other hand I always get too much already when only seeing a Wordpress login form <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f604.png?v=74f512c8ff7" class="not-responsive emoji emoji-android emoji--smile" style="height:23px;width:auto;vertical-align:middle" title=":-D" alt="😄" /></p>
]]></description><link>https://forum.cloudron.io/post/30275</link><guid isPermaLink="true">https://forum.cloudron.io/post/30275</guid><dc:creator><![CDATA[fbartels]]></dc:creator><pubDate>Fri, 23 Apr 2021 12:08:49 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Fri, 23 Apr 2021 12:04:07 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> Classic example of platform gatekeeping decisions costing every user the same inordinate amount of time.</p>
<p dir="auto">Option 1: Cloudron does not block external LDAP access. We can then use that with non Cloudron apps and get on with our lives.</p>
<p dir="auto">Option 2: Find someone that knows another platform that might do what could already be done with Option 1, if we are "allowed", then learn all the curiosities of that other platform and maintain it, just for one tiny single feature, that we could have with Option 1, if your discretion allows.</p>
<p dir="auto">So far option 2 has cost myself and another person the last 2 days work lost from doing anything else that we would have otherwise been progressing.</p>
<p dir="auto">OK, so we will learn another platform, and it <em>might</em> have some other useful features - but it is a forced situation based on platform owner decisions more than user needs.</p>
<p dir="auto">Sorry to share the frustrations upstream, but I just see extraordinary value from the simplicity of this being solved, versus vast amounts of unnecessary time from every Admin that might want to solve these time costs for their group or organisation Users.</p>
<p dir="auto">I cannot think of a single reason why anyone would not want this to be just a basic standard features. It's not as if the world didn't already agree LDAP is a solution. Now we have to get every LDAP platform  to agree to allow it to talk to every other LDAP support platform too it seems.</p>
]]></description><link>https://forum.cloudron.io/post/30274</link><guid isPermaLink="true">https://forum.cloudron.io/post/30274</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Fri, 23 Apr 2021 12:04:07 GMT</pubDate></item><item><title><![CDATA[Reply to LDAP&#x2F;AD Server on Fri, 23 Apr 2021 11:54:03 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/fbartels" aria-label="Profile: fbartels">@<bdi>fbartels</bdi></a> Thanks - so far UCS is a long way from intuitive. I feel like I got invited around for dinner and pointed at the kitchen while everyone else already ate.</p>
<p dir="auto">It seems strange to have to install an App for Lets Encrypt, as in that should just be a standard feature enabled for all to use or ignore.</p>
<p dir="auto">I have a feeling we're going to have to start again with reimagine this VPS because guesswork setups and issues are costing way more time that expected.</p>
<p dir="auto">The world really doesn't like solving the obvious needs in obvious ways.</p>
<p dir="auto">Really appreciate the instructions as I'm tearing my hair out with now over a day on something that I really don't think should be this complicated.</p>
<p dir="auto">It's like we have to deal with developers that think: "Well, we could make that possible, but since no-one has explicitly campaigned for it, lets just say its possible but not actually solve it, so everyone has to either learn everything we already know, or spend more time convincing us to make something obvious, then we might think about."</p>
<p dir="auto">My only sanctuary in persevering with all this, is that with Microsoft, Google &amp; AWS they'd also try and sell you some certified course nonsense as well before allowing you to play their specifically different ways.</p>
]]></description><link>https://forum.cloudron.io/post/30272</link><guid isPermaLink="true">https://forum.cloudron.io/post/30272</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Fri, 23 Apr 2021 11:54:03 GMT</pubDate></item></channel></rss>