2022-04-27 13:22:11 +02:00
<!DOCTYPE HTML>
< html lang = "en" class = "sidebar-visible no-js light" >
< head >
<!-- Book generated using mdBook -->
< meta charset = "UTF-8" >
< title > Installing client tools - Kanidm Administration< / title >
<!-- Custom HTML head -->
< meta content = "text/html; charset=utf-8" http-equiv = "Content-Type" >
< meta name = "description" content = "" >
< meta name = "viewport" content = "width=device-width, initial-scale=1" >
< meta name = "theme-color" content = "#ffffff" / >
< link rel = "shortcut icon" href = "favicon.png" >
< link rel = "stylesheet" href = "css/variables.css" >
< link rel = "stylesheet" href = "css/general.css" >
< link rel = "stylesheet" href = "css/chrome.css" >
< link rel = "stylesheet" href = "css/print.css" media = "print" >
<!-- Fonts -->
< link rel = "stylesheet" href = "FontAwesome/css/font-awesome.css" >
< link rel = "stylesheet" href = "fonts/fonts.css" >
<!-- Highlight.js Stylesheets -->
< link rel = "stylesheet" href = "highlight.css" >
< link rel = "stylesheet" href = "tomorrow-night.css" >
< link rel = "stylesheet" href = "ayu-highlight.css" >
<!-- Custom theme stylesheets -->
< / head >
< body >
<!-- Provide site root to javascript -->
< script type = "text/javascript" >
var path_to_root = "";
var default_theme = window.matchMedia("(prefers-color-scheme: dark)").matches ? "navy" : "light";
< / script >
<!-- Work around some values being stored in localStorage wrapped in quotes -->
< script type = "text/javascript" >
try {
var theme = localStorage.getItem('mdbook-theme');
var sidebar = localStorage.getItem('mdbook-sidebar');
if (theme.startsWith('"') & & theme.endsWith('"')) {
localStorage.setItem('mdbook-theme', theme.slice(1, theme.length - 1));
}
if (sidebar.startsWith('"') & & sidebar.endsWith('"')) {
localStorage.setItem('mdbook-sidebar', sidebar.slice(1, sidebar.length - 1));
}
} catch (e) { }
< / script >
<!-- Set the theme before any content is loaded, prevents flash -->
< script type = "text/javascript" >
var theme;
try { theme = localStorage.getItem('mdbook-theme'); } catch(e) { }
if (theme === null || theme === undefined) { theme = default_theme; }
var html = document.querySelector('html');
html.classList.remove('no-js')
html.classList.remove('light')
html.classList.add(theme);
html.classList.add('js');
< / script >
<!-- Hide / unhide sidebar before it is displayed -->
< script type = "text/javascript" >
var html = document.querySelector('html');
var sidebar = 'hidden';
if (document.body.clientWidth >= 1080) {
try { sidebar = localStorage.getItem('mdbook-sidebar'); } catch(e) { }
sidebar = sidebar || 'visible';
}
html.classList.remove('sidebar-visible');
html.classList.add("sidebar-" + sidebar);
< / script >
< nav id = "sidebar" class = "sidebar" aria-label = "Table of contents" >
< div class = "sidebar-scrollbox" >
2022-11-04 01:07:22 +01:00
< ol class = "chapter" > < li class = "chapter-item expanded " > < a href = "intro.html" > < strong aria-hidden = "true" > 1.< / strong > Introduction to Kanidm< / a > < / li > < li class = "chapter-item expanded " > < a href = "glossary.html" > < strong aria-hidden = "true" > 2.< / strong > Glossary of Technical Terms< / a > < / li > < li class = "chapter-item expanded " > < a href = "installing_the_server.html" > < strong aria-hidden = "true" > 3.< / strong > Installing the Server< / a > < / li > < li > < ol class = "section" > < li class = "chapter-item expanded " > < a href = "choosing_a_domain_name.html" > < strong aria-hidden = "true" > 3.1.< / strong > Choosing a Domain Name< / a > < / li > < li class = "chapter-item expanded " > < a href = "prepare_the_server.html" > < strong aria-hidden = "true" > 3.2.< / strong > Preparing for your Deployment< / a > < / li > < li class = "chapter-item expanded " > < a href = "server_configuration.html" > < strong aria-hidden = "true" > 3.3.< / strong > Server Configuration and Install< / a > < / li > < li class = "chapter-item expanded " > < a href = "server_update.html" > < strong aria-hidden = "true" > 3.4.< / strong > Server Updates< / a > < / li > < li class = "chapter-item expanded " > < a href = "security_hardening.html" > < strong aria-hidden = "true" > 3.5.< / strong > Platform Security Hardening< / a > < / li > < / ol > < / li > < li class = "chapter-item expanded " > < a href = "client_tools.html" > < strong aria-hidden = "true" > 4.< / strong > Client Tools< / a > < / li > < li > < ol class = "section" > < li class = "chapter-item expanded " > < a href = "installing_client_tools.html" class = "active" > < strong aria-hidden = "true" > 4.1.< / strong > Installing client tools< / a > < / li > < / ol > < / li > < li class = "chapter-item expanded " > < a href = "accounts_and_groups.html" > < strong aria-hidden = "true" > 5.< / strong > Accounts and Groups< / a > < / li > < li class = "chapter-item expanded " > < a href = "administrivia.html" > < strong aria-hidden = "true" > 6.< / strong > Administration< / a > < / li > < li > < ol class = "section" > < li class = "chapter-item expanded " > < a href = "backup_restore.html" > < strong aria-hidden = "true" > 6.1.< / strong > Backup and Restore< / a > < / li > < li class = "chapter-item expanded " > < a href = "database_maint.html" > < strong aria-hidden = "true" > 6.2.< / strong > Database Maintenance< / a > < / li > < li class = "chapter-item expanded " > < a href = "domain_rename.html" > < strong aria-hidden = "true" > 6.3.< / strong > Domain Rename< / a > < / li > < li class = "chapter-item expanded " > < a href = "monitoring.html" > < strong aria-hidden = "true" > 6.4.< / strong > Monitoring the platform< / a > < / li > < li class = "chapter-item expanded " > < a href = "password_quality.html" > < strong aria-hidden = "true" > 6.5.< / strong > Password Quality and Badlisting< / a > < / li > < li class = "chapter-item expanded " > < a href = "posix_accounts.html" > < strong aria-hidden = "true" > 6.6.< / strong > POSIX Accounts and Groups< / a > < / li > < li class = "chapter-item expanded " > < a href = "ssh_key_dist.html" > < strong aria-hidden = "true" > 6.7.< / strong > SSH Key Distribution< / a > < / li > < li class = "chapter-item expanded " > < a href = "recycle_bin.html" > < strong aria-hidden = "true" > 6.8.< / strong > The Recycle Bin< / a > < / li > < li class = "chapter-item expanded " > < a href = "why_tls.html" > < strong aria-hidden = "true" > 6.9.< / strong > Why TLS?< / a > < / li > < / ol > < / li > < li class = "chapter-item expanded " > < a href = "frequently_asked_questions.html" > < strong aria-hidden = "true" > 7.< / strong > Frequently Asked Questions< / a > < / li > < li class = "chapter-item expanded " > < a href = "troubleshooting.html" > < strong aria-hidden = "true" > 8.< / strong > Troubleshooting< / a > < / li > < li class = "chapter-item expanded affix " > < li class = "part-title" > Integrations< / li > < li class = "chapter-item expanded " > < a href = "integrations/oauth2.html" > < strong aria-hidden = "true" > 9.< / strong > Oauth2< / a > < / li > < li class = "chapter-item expanded " > < a href = "integrations/pam_and_nsswitch.html" > < strong aria-hidden = "true" > 10.< / strong > PAM and nsswitch< / a > < / li > < li class = "chapter-item expanded " > < a href = "integrations/radius.html" > < strong aria-hidden = "true" > 11.< / strong > RADIUS< / a > < / li > < li class = "chapter-item expanded " > < a href = "integrations/ldap.html" > < strong aria-hidden = "true" > 12.< / strong > LDAP< / a > < / li > < li class = "chapter-item expanded " > < a href = "integrations/traefik.html" > < strong aria-hidden = "true" > 13.< / strong > Traefik< / a > < / li > < li class = "chapter-item expanded affix " > < li class = "part-title" > Integration Examples< / li > < li
2022-04-27 13:22:11 +02:00
< / div >
< div id = "sidebar-resize-handle" class = "sidebar-resize-handle" > < / div >
< / nav >
< div id = "page-wrapper" class = "page-wrapper" >
< div class = "page" >
< div id = "menu-bar-hover-placeholder" > < / div >
< div id = "menu-bar" class = "menu-bar sticky bordered" >
< div class = "left-buttons" >
< button id = "sidebar-toggle" class = "icon-button" type = "button" title = "Toggle Table of Contents" aria-label = "Toggle Table of Contents" aria-controls = "sidebar" >
< i class = "fa fa-bars" > < / i >
< / button >
< button id = "theme-toggle" class = "icon-button" type = "button" title = "Change theme" aria-label = "Change theme" aria-haspopup = "true" aria-expanded = "false" aria-controls = "theme-list" >
< i class = "fa fa-paint-brush" > < / i >
< / button >
< ul id = "theme-list" class = "theme-popup" aria-label = "Themes" role = "menu" >
< li role = "none" > < button role = "menuitem" class = "theme" id = "light" > Light (default)< / button > < / li >
< li role = "none" > < button role = "menuitem" class = "theme" id = "rust" > Rust< / button > < / li >
< li role = "none" > < button role = "menuitem" class = "theme" id = "coal" > Coal< / button > < / li >
< li role = "none" > < button role = "menuitem" class = "theme" id = "navy" > Navy< / button > < / li >
< li role = "none" > < button role = "menuitem" class = "theme" id = "ayu" > Ayu< / button > < / li >
< / ul >
< button id = "search-toggle" class = "icon-button" type = "button" title = "Search. (Shortkey: s)" aria-label = "Toggle Searchbar" aria-expanded = "false" aria-keyshortcuts = "S" aria-controls = "searchbar" >
< i class = "fa fa-search" > < / i >
< / button >
< / div >
< h1 class = "menu-title" > Kanidm Administration< / h1 >
< div class = "right-buttons" >
< a href = "print.html" title = "Print this book" aria-label = "Print this book" >
< i id = "print-button" class = "fa fa-print" > < / i >
< / a >
2022-07-05 03:51:41 +02:00
< a href = "https://github.com/kanidm/kanidm" title = "Git repository" aria-label = "Git repository" >
< i id = "git-repository-button" class = "fa fa-github" > < / i >
< / a >
< a href = "https://github.com/kanidm/kanidm/edit/master/kanidm_book/src/installing_client_tools.md" title = "Suggest an edit" aria-label = "Suggest an edit" >
< i id = "git-edit-button" class = "fa fa-edit" > < / i >
< / a >
2022-04-27 13:22:11 +02:00
< / div >
< / div >
< div id = "search-wrapper" class = "hidden" >
< form id = "searchbar-outer" class = "searchbar-outer" >
< input type = "search" id = "searchbar" name = "searchbar" placeholder = "Search this book ..." aria-controls = "searchresults-outer" aria-describedby = "searchresults-header" >
< / form >
< div id = "searchresults-outer" class = "searchresults-outer hidden" >
< div id = "searchresults-header" class = "searchresults-header" > < / div >
< ul id = "searchresults" >
< / ul >
< / div >
< / div >
<!-- Apply ARIA attributes after the sidebar and the sidebar toggle button are added to the DOM -->
< script type = "text/javascript" >
document.getElementById('sidebar-toggle').setAttribute('aria-expanded', sidebar === 'visible');
document.getElementById('sidebar').setAttribute('aria-hidden', sidebar !== 'visible');
Array.from(document.querySelectorAll('#sidebar a')).forEach(function(link) {
link.setAttribute('tabIndex', sidebar === 'visible' ? 0 : -1);
});
< / script >
< div id = "content" class = "content" >
< main >
< h1 id = "installing-client-tools" > < a class = "header" href = "#installing-client-tools" > Installing Client Tools< / a > < / h1 >
< blockquote >
2022-11-09 23:01:41 +01:00
< p > < strong > NOTE< / strong > As this project is in a rapid development phase, running different
release versions will likely present incompatibilities. Ensure you're running
matching release versions of client and server binaries. If you have any issues,
2022-05-27 01:20:56 +02:00
check that you are running the latest software.< / p >
2022-04-27 13:22:11 +02:00
< / blockquote >
< h2 id = "from-packages" > < a class = "header" href = "#from-packages" > From packages< / a > < / h2 >
2022-11-09 23:01:41 +01:00
< p > Kanidm currently is packaged for the following systems:< / p >
2022-04-27 13:22:11 +02:00
< ul >
< li > OpenSUSE Tumbleweed< / li >
< li > OpenSUSE Leap 15.3/15.4< / li >
2022-11-09 23:01:41 +01:00
< li > MacOS< / li >
< li > Arch Linux< / li >
< li > NixOS< / li >
< li > Fedora 36< / li >
2022-05-10 03:03:16 +02:00
< li > CentOS Stream 9< / li >
2022-04-27 13:22:11 +02:00
< / ul >
2022-05-31 06:26:03 +02:00
< p > The < code > kanidm< / code > client has been built and tested from Windows, but is not (yet) packaged routinely.< / p >
2022-04-27 13:22:11 +02:00
< h3 id = "opensuse-tumbleweed" > < a class = "header" href = "#opensuse-tumbleweed" > OpenSUSE Tumbleweed< / a > < / h3 >
2022-05-27 01:20:56 +02:00
< p > Kanidm has been part of OpenSUSE Tumbleweed since October 2020. You can install
2022-04-27 13:22:11 +02:00
the clients with:< / p >
< pre > < code > zypper ref
zypper in kanidm-clients
< / code > < / pre >
< h3 id = "opensuse-leap-153154" > < a class = "header" href = "#opensuse-leap-153154" > OpenSUSE Leap 15.3/15.4< / a > < / h3 >
2022-11-09 23:01:41 +01:00
< p > Using zypper you can add the Kanidm leap repository with:< / p >
2022-04-27 13:22:11 +02:00
< pre > < code > zypper ar -f obs://network:idm network_idm
< / code > < / pre >
< p > Then you need to refresh your metadata and install the clients.< / p >
< pre > < code > zypper ref
zypper in kanidm-clients
< / code > < / pre >
2022-11-09 23:01:41 +01:00
< h3 id = "macos---brew" > < a class = "header" href = "#macos---brew" > MacOS - Brew< / a > < / h3 >
< p > < a href = "https://brew.sh/" > Homebrew< / a > allows addition of third party repositories for installing tools. On
MacOS you can use this to install the Kanidm tools.< / p >
< pre > < code > brew tap kanidm/kanidm
brew install kanidm
< / code > < / pre >
< h3 id = "arch-linux" > < a class = "header" href = "#arch-linux" > Arch Linux< / a > < / h3 >
< p > < a href = "https://aur.archlinux.org/packages?O=0&K=kanidm" > Kanidm on AUR< / a > < / p >
< h3 id = "nixos" > < a class = "header" href = "#nixos" > NixOS< / a > < / h3 >
< p > < a href = "https://search.nixos.org/packages?sort=relevance&type=packages&query=kanidm" > Kanidm in NixOS< / a > < / p >
2022-04-27 13:22:11 +02:00
< h3 id = "fedora--centos-stream" > < a class = "header" href = "#fedora--centos-stream" > Fedora / Centos Stream< / a > < / h3 >
2022-11-09 23:01:41 +01:00
< table >
< tr >
< td rowspan = 2 > < img src = "images/kani-warning.png" alt = "Kani Warning" / > < / td >
< td > < strong > Take Note!< / strong > < / td >
< / tr >
< tr >
< td > Kanidm frequently uses new Rust versions and features, however Fedora and Centos frequently are behind in Rust releases. As a result, they may not always have the latest Kanidm versions available.< / td >
< / tr >
< / table >
< p > Fedora has limited support through the development repository. You need to add the repository
2022-05-27 01:20:56 +02:00
metadata into the correct directory:< / p >
2022-11-09 23:01:41 +01:00
< pre > < code > # Fedora
wget https://download.opensuse.org/repositories/network:/idm/Fedora_36/network:idm.repo
2022-04-27 13:22:11 +02:00
# Centos Stream 9
2022-05-27 01:20:56 +02:00
wget https://download.opensuse.org/repositories/network:/idm/CentOS_9_Stream/network:idm.repo
2022-04-27 13:22:11 +02:00
< / code > < / pre >
< p > You can then install with:< / p >
2022-05-27 01:20:56 +02:00
< pre > < code > dnf install kanidm-clients
2022-04-27 13:22:11 +02:00
< / code > < / pre >
2022-11-09 23:01:41 +01:00
< h2 id = "cargo" > < a class = "header" href = "#cargo" > Cargo< / a > < / h2 >
< p > The tools are available as a cargo download if you have a rust tool chain available. To install
rust you should follow the documentation for < a href = "https://rustup.rs/" > rustup< / a > . These will be installed
into your home directory. To update these, re-run the install command with the new version.< / p >
< pre > < code > cargo install --version 1.1.0-alpha.10 kanidm_tools
< / code > < / pre >
< h2 id = "tools-container" > < a class = "header" href = "#tools-container" > Tools Container< / a > < / h2 >
< p > In some cases if your distribution does not have native kanidm-client support, and you can't access
cargo for the install for some reason, you can use the cli tools from a docker container instead.< / p >
< pre > < code > docker pull kanidm/tools:latest
docker run --rm -i -t \
-v /etc/kanidm/config:/etc/kanidm/config:ro \
-v ~/.config/kanidm:/home/kanidm/.config/kanidm:ro \
-v ~/.cache/kanidm_tokens:/home/kanidm/.cache/kanidm_tokens \
kanidm/tools:latest \
/sbin/kanidm --help
< / code > < / pre >
< p > If you have a ca.pem you may need to bind mount this in as required.< / p >
< blockquote >
< p > < strong > TIP< / strong > You can alias the docker run command to make the tools easier to access such as:< / p >
< / blockquote >
< pre > < code > alias kanidm=" docker run ..."
2022-04-27 13:22:11 +02:00
< / code > < / pre >
< h2 id = "checking-that-the-tools-work" > < a class = "header" href = "#checking-that-the-tools-work" > Checking that the tools work< / a > < / h2 >
< p > Now you can check your instance is working. You may need to provide a CA certificate for verification
with the -C parameter:< / p >
< pre > < code > kanidm login --name anonymous
kanidm self whoami -H https://localhost:8443 --name anonymous
2022-10-07 11:23:12 +02:00
kanidm self whoami -C ../path/to/ca.pem -H https://localhost:8443 --name anonymous
2022-04-27 13:22:11 +02:00
< / code > < / pre >
2022-10-07 11:23:12 +02:00
< p > Now you can take some time to look at what commands are available - please
2022-05-27 01:20:56 +02:00
< a href = "https://github.com/kanidm/kanidm#getting-in-contact--questions" > ask for help at any time< / a > .< / p >
2022-04-27 13:22:11 +02:00
< / main >
< nav class = "nav-wrapper" aria-label = "Page navigation" >
<!-- Mobile navigation buttons -->
< a rel = "prev" href = "client_tools.html" class = "mobile-nav-chapters previous" title = "Previous chapter" aria-label = "Previous chapter" aria-keyshortcuts = "Left" >
< i class = "fa fa-angle-left" > < / i >
< / a >
< a rel = "next" href = "accounts_and_groups.html" class = "mobile-nav-chapters next" title = "Next chapter" aria-label = "Next chapter" aria-keyshortcuts = "Right" >
< i class = "fa fa-angle-right" > < / i >
< / a >
< div style = "clear: both" > < / div >
< / nav >
< / div >
< / div >
< nav class = "nav-wide-wrapper" aria-label = "Page navigation" >
< a rel = "prev" href = "client_tools.html" class = "nav-chapters previous" title = "Previous chapter" aria-label = "Previous chapter" aria-keyshortcuts = "Left" >
< i class = "fa fa-angle-left" > < / i >
< / a >
< a rel = "next" href = "accounts_and_groups.html" class = "nav-chapters next" title = "Next chapter" aria-label = "Next chapter" aria-keyshortcuts = "Right" >
< i class = "fa fa-angle-right" > < / i >
< / a >
< / nav >
< / div >
< script type = "text/javascript" >
window.playground_copyable = true;
< / script >
< script src = "elasticlunr.min.js" type = "text/javascript" charset = "utf-8" > < / script >
< script src = "mark.min.js" type = "text/javascript" charset = "utf-8" > < / script >
< script src = "searcher.js" type = "text/javascript" charset = "utf-8" > < / script >
< script src = "clipboard.min.js" type = "text/javascript" charset = "utf-8" > < / script >
< script src = "highlight.js" type = "text/javascript" charset = "utf-8" > < / script >
< script src = "book.js" type = "text/javascript" charset = "utf-8" > < / script >
<!-- Custom JS scripts -->
< / body >
< / html >