FreeNAS webgui sso

Status
Not open for further replies.

Journer

Dabbler
Joined
Jun 20, 2017
Messages
17
I have a heterogeneous network of macs,windows, and unix machines. I'm annoyed having to login to different web guis and terminals all the time. All of my machines, including even my router and switch, support active directory (or RADIUS, which can auth back to AD). So I'm thinking of running a small AD domain - probably a bit overkill for just one real user, some system users, and a handful of machines - but call it a learning project as well.

Does the FreeNAS gui have any built in support for sso login? I'm mainly hoping for spnego (kerberos)...
 
Last edited by a moderator:

Journer

Dabbler
Joined
Jun 20, 2017
Messages
17
No, the UI as it stands only allows the root user to log-in.
I was in disbelief, but I just now tried to login as another user... what a shame :(

I could understand not having SSO auth built in... but not even being able to login as another user seems odd?
 

SweetAndLow

Sweet'NASty
Joined
Nov 6, 2013
Messages
6,421
I was in disbelief, but I just now tried to login as another user... what a shame :(

I could understand not having SSO auth built in... but not even being able to login as another user seems odd?
Most users should never be configuring anything. And role based access control is a very Enterprise feature that has not been implemented yet.
 
Last edited by a moderator:

themelon

Cadet
Joined
Jul 6, 2016
Messages
1
Most users should never be configuring anything. And role based access control is a very Enterprise feature that has not been implemented yet.

Sure, most END users should not be configuring anything or for that matter would even know FreeNAS was what they were using. But that is a pretty week excuse for not allowing admin users in a designated admin group from being able to log in to the webgui. Not all workplaces share or can share the root password. Even if logging did not show what user initiated a given action the ability to use something other than root for webgui access would be huge. It has nothing to do with true RBAC, it's basic group membership for logon purposes.
 
Status
Not open for further replies.
Top