- what needs should be covered and
- which components should be part of the suite
Make sure we have a Security roadmap with all current chosen components, as we don’t want to change later to improve security.
See also: Tiki Suite Desktop
User have choice, but we should pick a suggested minimal Linux desktop. By default, no apps, and users install / activate what they need.
- Todo: try https://susestudio.com/
- Todo: document shared drives for data
For installation & upgrades
- Subuser - Securing the Linux desktop with Docker
- Zero Install
- Portable Apps for Windows and Linux
- use RPMs
- Apps that self-update like Syncthing
ClearOS permits centralized user & group management. So a user has the same username & password for ClearOS (to update their password and user certificates for OpenVPN), Tiki, XMPP (Openfire & Jitsi), Email (Roundcube & Thunderbird) and Flexshares (Samba shared folders accessible locally or via VPN). The system can also permit / restrict usage of many of the ClearOS apps. BigBlueButton & Kaltura users authenticate through Tiki, but it would be better if they could also authenticate directly to ClearOS. OwnCloud has OpenLDAP integration with ClearOS (Not in Tiki Suite, but still very useful for any ClearOS instance)
“The Account Synchronization app makes it easy to synchronize users, groups and passwords across multiple ClearOS Professional installations.” -> http://www.clearcenter.com/support/documentation/user_guide/account_synchronization
However, users still need to login to each app. We should progress to a Single Sign On solution. ClearOS should be an IdP (Identity Provider) and also should be able to be a SP (Service Provider).
ClearOS: Investigate the addition of a Single Sign On (SSO) solution
ClearOS: Add two-factor authentication
Add Global Address Book app
Brute force attack protection for web config and SSH
- OpenID Connect
- Central Authentication Service (CAS)
- Login to ClearOS (or perhaps to any of the apps)
- Have links to all apps available in SSO. This should be made available to the apps so they can include in their GUI (ex.: nav bar)
- User clicks on any link in the nav bar, which takes to that site, and logs them in transparently and securely
Target apps for Tiki Suite
- Roundcube webmail
- Tiki Wiki CMS Groupware
- Web interface to XMPP server as per http://tracker.clearfoundation.com/view.php?id=1714
Other target apps for ClearOS:
Desktop & mobile apps should also be covered.
Since ideally, ClearOS can act as an IdP, it would be best to support the protocols used by a large enough number of apps
“A library for implementing an OAuth2 Server in PHP. Has been extended to support OpenID Connect identity provider functionality.” Source: http://openid.net/developers/libraries/
- VLC cross-platform, including F-Droid
vi is the default on ClearOS, but it’s unnecessarily complex.
- Replace for crontab editor, svn commit message, etc.
- Ideally, it’s the same tool throughout Tiki Suite (thus same as desktop text editor)
- Syntax highlighter
See also: Kolab