Re: SSH Connections --- VMWare Hosts

2023-06-05 Thread Michael Hess
Hey Sean, I agree with your desire for security, but there is no air-gap on a network, those are mutually exclusive.  However that being said, having Guac setup with Azure MFA, L7 firewalled with IP restrictions, and all ESXi (and other critical systems) firewalled to ONLY* allow Guac to talk

Re: SSH Settings

2023-05-24 Thread Michael Hess
ECT NOLS.EDU<http://www.nols.edu/> | LINKEDIN<https://www.linkedin.com/in/michaelahess/> From: Nick Couchman Sent: Wednesday, May 24, 2023 8:04 AM To: user@guacamole.apache.org Subject: Re: SSH Settings On Tue, May 23, 2023 at 5:43 PM Michael Hess wrot

SSH Settings

2023-05-23 Thread Michael Hess
I have a couple devices that need old cyphers and crypto settings, what's the best way to go about that? Generally, I'd just add them to the ~/.ssh/config file. I assume it's best to do this somehow in my docker-compose.yaml file though? Thanks, Mike

Still can't get recordings working 100%

2023-04-21 Thread Michael Hess
I've upgraded to 1.5.1 and it fixed the printer issues with Ghostscript, thank you I can't get recordings working right though, they won't show in the log, and when I restart the docker containers, guacamole won't start until I remove all files/folders in the recording path. Here's my

Re: Recordings issue on 1.5.0 and SAML Question

2023-03-27 Thread Michael Hess
way to do this within Docker? From: Michael Hess Sent: Friday, March 24, 2023 4:43 PM To: user@guacamole.apache.org Subject: Re: Recordings issue on 1.5.0 and SAML Question Hi Mike, I have this format in azure: first_last@domain My LDAP and all internal server

Re: Recordings issue on 1.5.0 and SAML Question

2023-03-24 Thread Michael Hess
23 at 3:02 PM Michael Hess wrote: First, can I pass a saml attribute like we can with ldap_{attribute} in some way? I need to pass the Azure onpremisessamaccountname attribute as the username, so LDAP groups work with SAML accounts vs having the full email as the username. I do see it in the

Recordings issue on 1.5.0 and SAML Question

2023-03-24 Thread Michael Hess
First, can I pass a saml attribute like we can with ldap_{attribute} in some way? I need to pass the Azure onpremisessamaccountname attribute as the username, so LDAP groups work with SAML accounts vs having the full email as the username. I do see it in the SAML token coming back when

Upgrade Docker 1.4.0 to 1.5.0

2023-03-22 Thread Michael Hess
Hi, I've got 1.4.0 running fine in docker, but I can't get the upgrade to work. I've stopped the guacamole and guacd containers, removed them, pulled the new versions, and started them. Nothing happens at the URL. I'm running caddyle in front of it, and haven't touched that container/config.

Re: LDAP with SAML, SSH keys, and MacOS issues

2023-02-03 Thread Michael Hess
@guacamole.apache.org Subject: Re: LDAP with SAML, SSH keys, and MacOS issues On Fri, Feb 3, 2023 at 4:54 PM Michael Hess wrote: > > Hey folks! > > I want to enable LDAP in my Guac Docker, I added the ldap environment > variables to the docker-compose.yml, removed the image, and did "

LDAP with SAML, SSH keys, and MacOS issues

2023-02-03 Thread Michael Hess
(whatever it is on mac) doesn't do anything. The slide cut/past box won't work in either direction. Thanks for any insight! Michael Hess

Re: SAML Groups with Azure

2023-02-01 Thread Michael Hess
AML Groups with Azure On Tue, Jan 31, 2023 at 10:39 AM Michael Hess wrote: I have the default saml-group-attribute set to "groups" and in Azure I have the Claim name of http://schemas.microsoft.com/ws/2008/06/identity/claims/groups set to value: user.groups [All], all default stuff. I do

SAML Groups with Azure

2023-01-31 Thread Michael Hess
I have the default saml-group-attribute set to "groups" and in Azure I have the Claim name of http://schemas.microsoft.com/ws/2008/06/identity/claims/groups set to value: user.groups [All], all default stuff. I don't get any mappings from the groups I've added in Guacamole though, they have