OIDC Demo¶
Purpose¶
This system will be used for the CAcert OpenID Connect demo client application.
Application Links¶
Todo
setup OIDC demo application, add links
Administration¶
System Administration¶
Primary: Jan Dittberner
Application Administration¶
Application |
Administrator(s) |
---|---|
oidcdemo |
Contact¶
Additional People¶
No additional people have sudo access on that machine.
Basics¶
Physical Location¶
This system is located in an LXC container on physical machine Infra03.
Logical Location¶
- IP Internet:
- IP Intranet:
- IP Internal:
- IPv6:
- MAC address:
00:ff:8f:9f:43:76
(eth0)
See also
See Network
Monitoring¶
- internal checks:
- external checks:
DNS¶
Todo
setup public DNS for oidcdemo
Name |
Type |
Content |
---|---|---|
oidcdemo.infra.cacert.org |
IN A |
10.0.3.18 |
See also
Operating System¶
Debian GNU/Linux 11 Bullseye
Services¶
Listening services¶
Port |
Service |
Origin |
Purpose |
---|---|---|---|
22/tcp |
ssh |
ANY |
admin console access |
25/tcp |
smtp |
local |
mail delivery to local MTA |
5665/tcp |
icinga2 |
monitor |
remote monitoring service |
Todo
setup OIDC demo application and add port
Running services¶
Service |
Usage |
Start mechanism |
---|---|---|
cron |
job scheduler |
systemd unit |
dbus-daemon |
System message bus |
systemd unit |
Exim |
SMTP server for local mail submission |
systemd unit |
icinga2 |
Icinga2 monitoring agent |
systemd unit |
openssh server |
ssh daemon for remote administration |
systemd unit |
Puppet agent |
configuration management agent |
systemd unit |
rsyslog |
syslog daemon |
systemd unit |
Todo
setup and document OIDC demo application service
Connected Systems¶
Outbound network connections¶
Security¶
SSH host keys¶
Algorithm |
Fingerprints |
---|---|
RSA |
|
DSA |
- |
ECDSA |
|
ED25519 |
|
See also
Non-distribution packages and modifications¶
Todo
document OIDC demo application installation
Risk assessments on critical packages¶
The Puppet agent package and a few dependencies are installed from the official Puppet APT repository because the versions in Debian are too old to use modern Puppet features.
Critical Configuration items¶
Keys and X.509 certificates¶
<service_x> configuration¶
Tasks¶
Changes¶
Planned¶
Todo
install OIDC demo application
Additional documentation¶
See also