Thorsten Scherf
Identity Management & Platform Security

SLAC 2024 talk: Using FIDO2 tokens for centralized user authentication

My SLAC 2024 presentation about how to use FIDO2 tokens how to authenticate centrally managed users is now online Read more

SLAC 2023 talk: FreeIPA and external Identity Providers

My SLAC 2023 presentation about FreeIPA and external Identity Providers is now online. Read more

How to export a private key from NSSDB

I recently had an issue where I accidentally lost the private key for my webserver certificate. The webserver is running as part of a FreeIPA environment. Luckily in such a setup the LDAP-Server share the same certificate and key with the webserver. So all I had to do is to copy the private key from the LDAP-Server certificate database to the we... Read more

Remote sudo and podman systemd integration articles in ADMIN magazine

Two more article I wrote for the ADMIN magazine have now been published also online. Save sudo logs on a remote computer Integrating Podman and systemd Happy reading. Read more

PKINIT with IPA and user certificates

The following article was inspired by a question on StackOverflow. In Kerberos world many different preauthentication mechanism exist. PKINIT is one of those mechanism. It basically uses X.509 certificates to authenticate the Kerberos Key Distribution Center (KDC) against the client and also the client against the KDC. The latter use-case mostl... Read more