Authorized Entities Directory
Admin UI (web2ldap) // Password self-service // OATH enrollment
The agile IAM for DevOps
Authorized Entities Directory (Æ-DIR) is a Privileged Identity and Access Management (IAM/PIM/PAM) based on OpenLDAP
News
- 2020-10-29: ansible-ae-dir-server 0.24.0 -- Symas OpenLDAP for Linux (SOFL) used on CentOS/RHEL 8.
- 2020-10-05: ansible-ae-dir-server 0.23.0 -- Support for running on CentOS 8.2+, dropped support for CentOS 7.x.
Main Objectives
- Strictly follow need to know and least privilege principles
- Agile data maintenance by consequent delegation of manageable small areas
- Provide meaningful audit trails for compliance checks
- Secure defaults
Key Features
- Fine-grained authorization
- Fine-grained delegation, ready-to-use role-model
- Role separation, multiple accounts per person
- Secure password handling, SSH key distribution
- Password self-service web application
- Compatible to all LDAP enabled applications without complicated client-side schema mapping
- Two-factor authentication integrated with LDAP, usable by any LDAP enabled application
- High availability out-of-the-box with LDAP server replicas
- Automated installation of turnkey solution with ansible
- TLS everywhere
- Service hardening out-of-the-box (e.g. with AppArmor)
Find longer introductions: Æ-DIR conference presentations.