Fedora's FreeIPA offers identity, security services

An ambitious open source project hopes to provide a unified directory and authentication server, but needs more interoperability work to become a viable competitor for Novell Identity Manager or Microsoft Active Directory.

Fedora 9, released last month, included the first release of FreeIPA, a new free/open source project that comes out of Red Hat with the goal of becoming a complete and integrated security information management solution. In this article we take a look at exactly what FreeIPA is, both what it can do now and what its developers hope it will be capable of in the future. It seems destined to become a key feature of Red Hat Enterprise Linux 6, and with Fedora 9 released and FreeIPA tightly integrated, now seems to be the perfect time to explore this new technology.

FreeIPA 1.0

The project has been running for a year and has recently made its 1.0 release. While the "IPA" part of the name stands for Identity, Policy and Auditing, the current focus is solely on providing the tools to make the identity part of the solution work, with the others being targeted for future releases. This includes the ability to centrally authenticate and administer user identities, functionality which is available in the 1.0 release through the unification of the Fedora Directory Server and MIT Kerberos, with plans to provide similar functionality for machines and services over the coming year.

Beyond the core functionality, the 1.0 release targeted simplifying the installation and configuration of the IPA environment, along with interfaces that will allow systems administrators to interact with the tool in an efficient manner. Both a command line and a web GUI are available in the 1.0 release, along with installation scripts that walk the administrator through the initial configuration.

Beyond 1.0

Once the identity functionality is in place with regard to machines and services as well as users, the plan is to use the information generated to allow systems administrators to build security policies. Perhaps the two most important features planned for this side of FreeIPA are the ability to centrally manage Fedora servers and their accompanying SELinux policies. The technology has not been developed solely with Fedora in mind either, but is designed to be compatible with all of the major UNIX OSs. Not all UNIX versions, of course are capable of all of the features and so these would be restricted to certain platforms. SELinux, for example, is Linux-only. Most significant, however, is the planned ability to be capable of applying policies to individual boxes depending on which group they belong to, including the ability to target virtual machines separate from their physical hosts.

Microsoft Windows support is on the road map, but not available yet.

Following this, the final piece of the IPA puzzle to be implemented will be auditing, which will allow systems administrators to easily review a number of important security logs so that they can be aware if an incident occurs, and also discover important information such as which user used which machine and when. The major benefit of this particular feature will be to allow organisations to easily comply with a number of new regulations that require detailed information such as user access histories.

Join the newsletter!


Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jonathan Roberts

Show Comments

Brand Post

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Luke Hill


I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Laura Johnston

MSI GS65 Stealth Thin

If you can afford the price tag, it is well worth the money. It out performs any other laptop I have tried for gaming, and the transportable design and incredible display also make it ideal for work.

Andrew Teoh

Brother MFC-L9570CDW Multifunction Printer

Touch screen visibility and operation was great and easy to navigate. Each menu and sub-menu was in an understandable order and category

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?