On this page
Overview
FreeIPA centralizes identity, authentication, and access control for Linux and UNIX environments. It provides CLI and web management while integrating LDAP, Kerberos, PKI, DNS, and related open-source components into one operational layer.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Centralize users, hosts, credentials, and access policy
FreeIPA can apply shared credentials and security settings across machines and centrally manage passwords, SSH public keys, sudo rules, keytabs, and access-control rules.
Sources: [1]
Integrate 389 Directory Server, MIT Kerberos, Dogtag PKI, and BIND
The project combines LDAP, KDC, certificate-authority, and DNS components behind unified installation and management tooling.
Sources: [1]
Connect to Active Directory through Kerberos trust
The README documents Active Directory integration through cross-realm Kerberos trust or user synchronization.
Sources: [1]
Best fit
Fits organizations centralizing identity and authorization across Linux fleets
It is suited to environments that want accounts, authentication, sudo, certificates, DNS, and access policy operated centrally instead of host by host.
Sources: [1]
Before adoption
The current master branch is a 4.14.0 Git snapshot, not a release build
The reviewed VERSION.m4 reports 4.14.0 while IPA_VERSION_IS_GIT_SNAPSHOT is set to yes. Pin a commit when evaluating master and do not treat it as a released package.
Sources: [2]
Source builds and server installation require Fedora/RPM dependencies and system-level setup
BUILD.txt documents dnf build dependencies, the WebUI submodule, RPM builds, and ipa-server-install. This is a server platform involving DNS, Kerberos, and PKI rather than a lightweight library install.
Sources: [3]
Official sources
- [1]FreeIPA source snapshot README(2026-10-04)
- [2]FreeIPA source snapshot VERSION.m4(2026-10-04)
- [3]FreeIPA source build guide(2026-10-04)
- [4]FreeIPA GPLv3 license(2026-10-04)
Supplemental curator note
The reviewed master branch is a 4.14.0 Git snapshot. For production, prefer released distribution packages and validate FreeIPA as a system-level DNS/Kerberos/PKI platform rather than a lightweight application dependency.
Try it in 3 steps
- 1
Fetch the reviewed commit with submodules
Master is a Git snapshot, so pin the reviewed commit and fetch the WebUI submodule as well.
git clone --recurse-submodules https://github.com/freeipa/freeipa.git freeipa-src && git -C freeipa-src checkout f7bdae43057b05161397d5ff52e90fd9aa8d9e61 && git -C freeipa-src submodule update --init --recursive - 2
Confirm the 4.14.0 Git-snapshot version markers
Inspect the major/minor/release values and
IPA_VERSION_IS_GIT_SNAPSHOTso the checkout is not mistaken for a released package.grep -E 'IPA_VERSION_(MAJOR|MINOR|RELEASE|IS_GIT_SNAPSHOT)' freeipa-src/VERSION.m4 - 3
Validate the Autotools build entry point without installing
Stop before server installation or system configuration. A full build requires the Fedora/RPM dependencies documented in BUILD.txt.
cd freeipa-src && autoreconf -i && ./configure --help >/dev/null && echo 'FreeIPA configure entry point OK'
Growth
Growth trends · Last 30 days
1,288 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 60
- Open PRs
- 67
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- freeipa
- python
- linux
- certificates
- certificate-authority
- identity
- identity-management
- user-management
- active-directory-integration
- kerberos
- secret-management
- idm
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Vaultwarden68,476 Stars
1 shared tag(s) · 1 shared category(s)
operate a Bitwarden-client-compatible API and web vault as a lightweight self-hosted server
Rust - HashiCorp Vault36,336 Stars
1 shared tag(s) · 1 shared category(s)
manage secret storage, issuance, encryption, leases, and revocation under one policy model
Go - JumpServer31,708 Stars
2 shared tag(s) · 1 shared category(s) · Same language
centralize privileged access to SSH, RDP, Kubernetes, and databases in one PAM platform
Python - Keycloak37,112 Stars
2 shared tag(s) · 1 shared category(s)
an IAM server providing authentication and authorization to applications
Java - Auth.js28,368 Stars
2 shared tag(s) · 1 shared category(s)
Compose OAuth/OIDC, passwordless, WebAuthn, and stateless or database-backed sessions from packages built around standard Web APIs
TypeScript - Devise24,354 Stars
2 shared tag(s) · 1 shared category(s)
compose Rails authentication workflows from modular features on top of Warden
Ruby
Report incorrect information
Tell us if any listing information is incorrect or outdated.