The user manager of Ixolate allows for controlling access to the different part (pages) of the configurator as well as controlling access to particular services on a per user bases.
Authentication
Ixolate offers integration with external servers for services that require user authentication. These services include:
- IPsec
- OpenVPN
- Captive Portal
- Proxy
Integrated into Ixolate are the Local User Database and Voucher Server. The Voucher Server is intended to be used with the Captive portal.
External services currently supported are:
- LDAP (OpenLDAP, MS Active Directory, Novell eDirectory)
- Radius
- OpenID connect (BE only)
Authorization
Besides authenticating, user authorization to access parts of the configuration can also be setup with an external server, but in order to grant the appropriate privileges to the users they need to exist in Ixolate’s local user manager. This way one can validate a user against its externally stored password and have a fine grained control over the configuration pages that user may access.
Users, Groups & Privileges
When using the local user manager, either stand alone or on combination with an external authentication server one can define groups to combine a set of privileges for a specific user group. A user should be an individual, a group needs to be specific in such a way that anyone of that group can be granted the same access rights, called privileges.
Settings (Users)
| Option | Description |
|---|---|
| Defined By | Informational, defines source |
| uid | Internal number |
| Disabled | Option to disable to user for authentication |
| Username | This users name |
| Password | Configure a password for local login |
| Scrambled Password | Generate a random password for this login to avoid login |
| Full name | Informational, users full name |
| Informational, email address this user has | |
| Comments | Informational, custom notes |
| Preferred landing page | Preferred landing page after login or authentication failure |
| Language | Language to use in the GUI |
| Login shell | (admin users only) shell to use |
| Expiration date | Account valid until |
| Group membership | Groups this user is a member of |
| Privileges | Privileges to assign to this user, we prefer to use groups instead |
| OTP seed | One time password token |
| Authorized Keys | SSH Authorized Keys for this user (when a shell is configured) |
Settings (Groups)
| Option | Description |
|---|---|
| Defined By | Informational, defines source |
| gid | Internal number |
| Group name | Name for this group |
| Description | Informational, description |
| Privileges | Defines the roles for users in this group |
| Members | Members of this group (can also be selected from the user) |
| Source Networks | Optional constrain this group to specific networks, when not connected via one defined here, the groups privileges do not apply. |
Settings (Privileges)
| Option | Description |
|---|---|
| Id | Internal identifier |
| Users | Users having this privilege directly assigned |
| Groups | Groups having this privilege directly assigned |
| Match (grid only) | Shows GUI paths this privilege allows |
Authentication services
Authentication services can be configured using the settings in System › Access › Servers. This includes both local accounts and remote authentication.
By default, Ixolate GUI login will use local accounts. This can be changed, however, by going to System › Settings › Administration, scrolling down to the “Authentication” group, and changing the ‘Server’ option.
Local account configuration
Settings for handling login via local accounts can be set by going to System › Access › Servers, then clicking the ‘Edit’ icon (a pencil) for ‘Local Database’. Here, you can improve security of local user accounts by setting password length and complexity constraints.
An overview of available settings:
| Policy | Enable password policy constraints. |
| Duration | [Policy] Password duration, optionally define how often the user should change his or her password. |
| Length | [Policy] Minimum password length to require. |
| Complexity | [Policy] Enforce password complexity checks. |
| Compliance | [Policy] Require SHA-512 password hashing instead of Blowfish |