Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - Fasio

#1
General Discussion / Re: Active Directory - SSO
August 22, 2020, 04:27:11 PM
Quote from: BeanAnimal on September 28, 2018, 01:37:42 AM
My initial research shows that the only AD-sync that can be done is manually... While pfSense and most other enterprise platforms offer an AD sync option.

In most business networks, AD is used and AD credentials are reset regularly, most often by end users. If this firewall is used as the VPN concentrator, then user's will be constantly locked out until a resync is done or user's are manually added to the firewall....

Previously, there was indeed such a problem associated with both the Active Directory product itself and the server part, but the solution can be an additional protection in the form of two-factor authentication using one-time passwords using the adfs method. This method also works on adfs server which can act as a guarantor of such protection. Then you do not have to do manual synchronization and remove locks because all users will be securely logged in and have the same adfs sso support in the system. For this reason, I advise you to consider this analogy.
#2
20.7 Legacy Series / Re: updatedb locate proper usage
August 22, 2020, 04:18:07 PM
Updates depend on the current user rights, try creating them with full administrator rights and making changes through them.
#3
This is the problem of updating the pocket itself, I had a similar situation only on versions earlier, try to do a rollback.