Difference between revisions of "Member management in LDAP and FreeIPA"

From sshcWiki
Jump to navigation Jump to search
(Password resets! Whee!)
(Now with screenshots! Coherent Formatting is for wieners.)
Line 9: Line 9:
 
# Log in to https://auth.sshchicago.org. If you are on the Hackerspace network, you will get a certificate warning. If you are not, you won't. Disregard the certificate warning, or [[SSHCHICAGO.ORG Certificate Authority (CA)|Add the SSHCHICAGO.ORG Certificate Authority (CA)]] to your computer.  
 
# Log in to https://auth.sshchicago.org. If you are on the Hackerspace network, you will get a certificate warning. If you are not, you won't. Disregard the certificate warning, or [[SSHCHICAGO.ORG Certificate Authority (CA)|Add the SSHCHICAGO.ORG Certificate Authority (CA)]] to your computer.  
 
# On the Users screen, click Add.  
 
# On the Users screen, click Add.  
# Type in a username, First Name, Last Name, and a temporary password. We typically use a pattern of first intiial + last name for usernames, though we do permit users to request a new handle. Click Add.  
+
# Type in a username, First Name, Last Name, and a temporary password. We typically use a pattern of first intiial + last name for usernames, though we do permit users to request a new handle. Click Add.[[File:Freeipa-add.png]] <br/>
# Click on the new user you just created.  
+
# Click on the new user you just created. [[File:Freeipa-userlist.png]]
# Set the member's contact information, and click Update.  
+
# Set the member's contact information, and click Update.[[File:Freeipa-contact.png]]
 
# Send the user a welcome email!
 
# Send the user a welcome email!
  
Line 22: Line 22:
 
# Log in to https://auth.sshchicago.org.  
 
# Log in to https://auth.sshchicago.org.  
 
# Find the user's account in the account list, click on it.  
 
# Find the user's account in the account list, click on it.  
# Under "Account Settings", on the right side, click Reset Password.  
+
# Under "Account Settings", on the right side, click Reset Password. [[File:Freeipa-reset-password-link.png]]
# Type a new password, and supply to the user.
+
# Type a new password, and supply to the user.[[File:Freeipa-reset-password-dialog-box.png]]
  
 
Encourage the new member to visit https://auth.sshchicago.org ASAP, where they will be prompted to enter a brand new password.
 
Encourage the new member to visit https://auth.sshchicago.org ASAP, where they will be prompted to enter a brand new password.

Revision as of 19:33, 27 May 2014

Adding members to LDAP

This page is an overview of how we add members into our LDAP database. Currently, this grants access to the wiki, but our identification platform (FreeIPA) is flexible and feature-ful enough to expand to other tasks, including VPN accounts, computer logins, and badge access.

All of the below procedures require special rights on the LDAP database. If you believe you should have these rights and do not, please send an email to tech@sshchicago.org.

Process

  1. Log in to https://auth.sshchicago.org. If you are on the Hackerspace network, you will get a certificate warning. If you are not, you won't. Disregard the certificate warning, or Add the SSHCHICAGO.ORG Certificate Authority (CA) to your computer.
  2. On the Users screen, click Add.
  3. Type in a username, First Name, Last Name, and a temporary password. We typically use a pattern of first intiial + last name for usernames, though we do permit users to request a new handle. Click Add.Freeipa-add.png
  4. Click on the new user you just created. Freeipa-userlist.png
  5. Set the member's contact information, and click Update.Freeipa-contact.png
  6. Send the user a welcome email!

Encourage the new member to visit https://auth.sshchicago.org ASAP, where they will be prompted to enter a brand new password.

Resetting a users password

Particularly with administrative accounts, ensure that you are not being socially engineered! Validate that the requestor is who he/she says they are either in person, or through one or more methods (email, SMS, etc.)

  1. Log in to https://auth.sshchicago.org.
  2. Find the user's account in the account list, click on it.
  3. Under "Account Settings", on the right side, click Reset Password. Freeipa-reset-password-link.png
  4. Type a new password, and supply to the user.Freeipa-reset-password-dialog-box.png

Encourage the new member to visit https://auth.sshchicago.org ASAP, where they will be prompted to enter a brand new password.