XCP-ng
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Multiple AD sources to Xen Orchestra

    Scheduled Pinned Locked Moved Xen Orchestra
    11 Posts 6 Posters 152 Views 5 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • lawrencesystemsL Offline
      lawrencesystems Ambassador @tuckertt
      last edited by

      @tuckertt

      Not a direct answer to your question, but something to think about. I get that connecting XO to Active Directory is good for centralized identity management and offers rasier onboarding/offboarding, one password to rule them all. But the reality is that once AD is compromised, attackers can pivot straight into the virtualization layer — the crown jewels.

      T 1 Reply Last reply Reply Quote 0
      • D Offline
        DustinB
        last edited by

        You shouldn't be looking to do this, you're customizing your environment in such a way that the community would likely struggle to assist, although maybe the Vates team would be willing too.

        Lawrence's comments notwithstanding, how would XO know which AD is authoritative, permissions administration is going to be a nightmare.

        While there are multiple plugins for Authentication to XO, I would doubt if you could use multiple plugins at the same time as I've never bothered to try to use multiple, though this may be the most reasonable approach to try to achieve what you're asking for.

        IE maybe one company uses GCP, so you authenticate that org with the auth-google plugin, and the other you authenticate with the auth-ldap plugin.

        T 1 Reply Last reply Reply Quote 0
        • T Offline
          tuckertt @DustinB
          last edited by tuckertt

          @DustinB so its as much a compliance piece as anything else. UK instance of a US company with data sovereignty laws in play.

          D 2 Replies Last reply Reply Quote 0
          • D Offline
            DustinB @tuckertt
            last edited by

            @tuckertt said in Multiple AD sources to Xen Orchestra:

            @DustinB so its as much a compliance piece as anything else. UK instance of a US company with data sovereignty laws in play. The administrator AD is UK only and the other AD can be anyone

            You're allowed to have shared hypervisors? Do these servers operate in the Atlantic ocean? 😉

            1 Reply Last reply Reply Quote 0
            • D Offline
              DustinB @tuckertt
              last edited by DustinB

              @tuckertt said in Multiple AD sources to Xen Orchestra:

              @DustinB so its as much a compliance piece as anything else. UK instance of a US company with data sovereignty laws in play. The administrator AD is UK only and the other AD can be anyone

              GDRP is really a bit of a pain in the butt, because a username is covered under GDRP and that the username has to stay within the user's country.

              The question I would raise is there a better way to limit this data into its required geographic region, like multiple XO instances and pools. Rather than one large pool, which would then be configured to allow people to access the resources from different geographic regions while keeping things GDPR compliant.....

              The Vates team, being from France likely has some ideas on this that would be worth* consulting with them on.

              1 Reply Last reply Reply Quote 0
              • T Offline
                tuckertt @lawrencesystems
                last edited by tuckertt

                @lawrencesystems so again its a compliance piece.. BTW big fan of the videos

                1 Reply Last reply Reply Quote 0
                • olivierlambertO Offline
                  olivierlambert Vates 🪐 Co-Founder CEO
                  last edited by

                  Adding XO PO in the loop @lsouai-vates

                  1 Reply Last reply Reply Quote 0
                  • D Offline
                    Davidj 0
                    last edited by

                    @tuckertt Are both AD domains in the same forest?

                    T 1 Reply Last reply Reply Quote 0
                    • T Offline
                      tuckertt @Davidj 0
                      last edited by tuckertt

                      @Davidj-0 No, from what i gather the UK domain is completely separate. So administrators can restrict access to specific areas for users Potentially via the self service mechanism only allowing the restricted "local" usage .

                      Not sure im phrasing it well enough but not sure how deep i can go officially

                      1 Reply Last reply Reply Quote 0
                      • lsouai-vatesL Offline
                        lsouai-vates Vates 🪐 XO Team @tuckertt
                        last edited by

                        @tuckertt Hello ! We are making some investigations on authentication, users, ACLs etc... topics for the Xen Orchestra 6 version to come. Could you please formalize your need so I can add it to my user suggestions list? 😉
                        Try to make specs as most generic (for all users) as possible, and don't hesitate to add some concrete examples.
                        Have a good day!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post