kanidm-expert

Configure and manage Kanidm identity management with authentication protocols and policies.

45|4|Updated Nov 25, 2025
One-click install
npx skills add https://github.com/martinholovsky/claude-skills-generator --skill kanidm-expert
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: kanidm-expert
Source: https://github.com/martinholovsky/claude-skills-generator/tree/main/skills/kanidm-expert
Command: npx skills add https://github.com/martinholovsky/claude-skills-generator --skill kanidm-expert

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides expert guidance and actionable commands for configuring, securing, and integrating the Kanidm modern identity management system, ensuring robust and secure access control.

Core Features & Use Cases

  • Comprehensive Configuration: Covers user/group management, OAuth2/OIDC, LDAP, RADIUS, SSH, and PAM integration.
  • Security Hardening: Implements best practices for authentication, authorization, and operational security.
  • Use Case: Securely integrate Kanidm with your applications using OAuth2/OIDC, set up RADIUS for network authentication, or manage SSH keys for server access.

Quick Start

Use the kanidm-expert skill to create a new OAuth2 client for a web application.

Frequently Asked Questions about kanidm-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I configure an OAuth2 or OIDC client in Kanidm for web application authentication?

To configure OAuth2 or OIDC in Kanidm, you create a new client configuration defining the redirect URIs and scopes. This establishes secure authentication flows for web applications using industry-standard protocols.

What is the best way to integrate Kanidm with Linux server authentication using PAM and SSH keys?

Kanidm integrates with Linux servers via PAM modules and SSH key management to provide centralized authentication. This allows SSH access control to be managed directly through identity policies.

Does Kanidm support RADIUS for network device authentication and legacy LDAP clients?

Yes, Kanidm supports both RADIUS for network device authentication and LDAP protocol compatibility for legacy clients. This ensures broad integration across diverse infrastructure components.

How do I set up multi-factor authentication with WebAuthn and TOTP in Kanidm?

Kanidm enables multi-factor authentication by configuring WebAuthn hardware tokens and TOTP applications. This enforces security best practices by requiring multiple verification methods for user logins.

What are the security best practices for managing user and group authorization policies in Kanidm?

Kanidm security hardening involves defining strict user and group authorization policies based on least privilege. This ensures robust access control and operational excellence across the identity management system.

Why use Kanidm over other identity management systems for OAuth2 and LDAP integration?

Kanidm provides a modern identity management system focused on security best practices and performance optimization. It natively supports OAuth2, OIDC, LDAP, and RADIUS integration for robust access control.