Flock 2024 Adopting enterprise domain clients to Silverblue: FreeIPA view

Опубликовано: 18 Май 2026
на канале: Fedora Project
239
2

A typical Active Directory or FreeIPA deployment assumes strong trust between the domain controllers and client systems enrolled into the domain. Kerberos configuration, machine credentials, TLS certificates and their CA chains are unique to each environment and not all this information can be made public as a part of a generally available image. Additional packages need to be present in the image to make sure enrollment is succesfull as well. On-demand domain enrollment, adjustment of the configurations to enable use of single sign-on services, and many other features provided by traditional Fedora don't work well with Silverblue images.

This talk is an investigation on what is needed to adjust Samba, FreeIPA, and SSSD clients to work properly with CoreOS/Silverblue-based deployments. It is based on a 1.5 year experiment of running own automatically rebased Silverblue images for a FreeIPA client in custom domain environment.

This talk was originally presented at Flock 2024 in Rochester, NY by Alexander Bokovoy.

You can view the details of this talk at: https://cfp.fedoraproject.org/flock-2...
The full conference schedule can be viewed at: https://cfp.fedoraproject.org/flock-2...

Other Flock talks can be found in the playlist:    • Flock 2024 Talks  

To learn more about Flock, visit the Conference Website: https://flocktofedora.org

---

🖥️ Download your favorite Fedora edition now:
https://fedoraproject.org/

🫂 Become a part of the Fedora community:
https://docs.fedoraproject.org/en-US/...

#fedora #linux #flocktofedora