<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/xsl" href="../assets/xml/rss.xsl" media="all"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Knowledge Base (Posts about floss)</title><link>https://bgstack15.ddns.net/blog/</link><description></description><atom:link href="https://bgstack15.ddns.net/blog/categories/floss.xml" rel="self" type="application/rss+xml"></atom:link><language>en</language><copyright>Contents © 2024 &lt;a href="mailto:bgstack15@gmail.com"&gt;bgstack15&lt;/a&gt; 
&lt;a rel="license" href="https://creativecommons.org/licenses/by-sa/4.0/"&gt;
&lt;img alt="Creative Commons License BY-SA"
style="border-width:0; margin-bottom:12px;"
src="https://bgstack15.ddns.net/.images/l_by-sa_4.0_88x31.png"&gt;&lt;/a&gt;</copyright><lastBuildDate>Sun, 28 Jul 2024 13:16:42 GMT</lastBuildDate><generator>Nikola (getnikola.com)</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><item><title>AndBible compared to BibleTimeMini</title><link>https://bgstack15.ddns.net/blog/posts/2024/07/28/andbible-compared-to-bibletimemini/</link><dc:creator>bgstack15</dc:creator><description>&lt;p&gt;I use two different main Bible programs on my mobile device (with apologies to a &lt;a href="https://bgstack15.ddns.net/blog/outbound/https:/adamthiede.com/blog/phones-in-church.html"&gt;random dude I follow&lt;/a&gt;):&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://bgstack15.ddns.net/blog/outbound/https:/sourceforge.net/projects/bibletimemini/"&gt;BibleTimeMini&lt;/a&gt; (from Play Store but not visible now?)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://bgstack15.ddns.net/blog/outbound/https:/andbible.org/"&gt;AndBible: Bible Study&lt;/a&gt; (&lt;a href="https://bgstack15.ddns.net/blog/outbound/https:/f-droid.org/en/packages/net.bible.android.activity/"&gt;on F-droid&lt;/a&gt;) (&lt;a href="https://bgstack15.ddns.net/blog/outbound/https:/github.com/AndBible/and-bible"&gt;source&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Both of these are &lt;a href="https://bgstack15.ddns.net/blog/outbound/http:/www.crosswire.org/sword/index.jsp"&gt;SWORD project&lt;/a&gt; clients, which means they can use the mostly-open-source Bible contents and distribution mechanisms to get more content.&lt;/p&gt;
&lt;p&gt;While I grew up reading the King James Version (KJV), aka Authorized Version (AV), of the Holy Bible, I now primarily use the English Standard Version (ESV). I also am interested in a few other translations, and both of these programs let you download and use and switch between multiple versions. In addition to other Bible texts, there are commentaries, dictionaries, and other types of mostly-print media available as &lt;a href="https://bgstack15.ddns.net/blog/outbound/http:/www.crosswire.org/sword/modules/index.jsp"&gt;modules to the SWORD project&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Because of BibleTimeMini's disappearance &lt;sup id="fnref:1"&gt;&lt;a class="footnote-ref" href="https://bgstack15.ddns.net/blog/posts/2024/07/28/andbible-compared-to-bibletimemini/#fn:1"&gt;1&lt;/a&gt;&lt;/sup&gt; from the Play Store, I started researching presently-available Bible apps for mobile devices, starting in the free-software F-Droid app store, and found AndBible.&lt;/p&gt;
&lt;p&gt;Each app has a different-generation mobile UI to navigate. I like the traditional view of BibleTimeMini, but I guess I'm getting used to the Material Design/modernness of AndBible.&lt;/p&gt;
&lt;p&gt;BibleTimeMini would download additional modules to my visible internal storage, at &lt;code&gt;/.sword/&lt;/code&gt;, so it was easy for me to manually manipulate the modules (i.e., back them up with other means). AndBible stores them... somewhere, that I haven't found. I found that frustrating. However, AndBible supports &lt;a href="https://bgstack15.ddns.net/blog/outbound/https:/github.com/AndBible/and-bible/wiki/Custom-repositories"&gt;custom web repositories&lt;/a&gt; for modules (and you know how much I love &lt;a href="https://bgstack15.ddns.net/blog/categories/repo/"&gt;repositories&lt;/a&gt;, so it's not too hard to get custom selections available as kind of a reverse-backup.&lt;/p&gt;
&lt;p&gt;I much prefer the book-and-chapter navigation of BibleTimeMini, but I fear that AndBible is the only one to be available on the web in the long term, so I'm trying to get used to AndBible. I have backed up the apk of BibleTimeMini though, just like I &lt;a href="https://bgstack15.ddns.net/blog/posts/2024/06/10/fdroid-partial-mirror/"&gt;partially mirror F-droid's repository&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Basically, I like carrying the Word of God in my pocket &lt;sup id="fnref:2"&gt;&lt;a class="footnote-ref" href="https://bgstack15.ddns.net/blog/posts/2024/07/28/andbible-compared-to-bibletimemini/#fn:2"&gt;2&lt;/a&gt;&lt;/sup&gt;, in all the various translations I care about, alongside all the electronic conveniences I would have in my pocket already anyways. And these two apps both do the job. And they're both FLOSS!&lt;/p&gt;
&lt;div class="footnote"&gt;
&lt;hr&gt;
&lt;ol&gt;
&lt;li id="fn:1"&gt;
&lt;p&gt;Probably merely through lack of recent development; a finished product doesn't need updates, but you know how marketplaces seem to think no updates means it's dead. &lt;a class="footnote-backref" href="https://bgstack15.ddns.net/blog/posts/2024/07/28/andbible-compared-to-bibletimemini/#fnref:1" title="Jump back to footnote 1 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id="fn:2"&gt;
&lt;p&gt;And not just a New Testament; How big do you think my pockets are?! &lt;a class="footnote-backref" href="https://bgstack15.ddns.net/blog/posts/2024/07/28/andbible-compared-to-bibletimemini/#fnref:2" title="Jump back to footnote 2 in the text"&gt;↩&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;</description><category>android</category><category>bible</category><category>floss</category><category>narrative</category><guid>https://bgstack15.ddns.net/blog/posts/2024/07/28/andbible-compared-to-bibletimemini/</guid><pubDate>Sun, 28 Jul 2024 13:09:00 GMT</pubDate></item><item><title>Android and my printer</title><link>https://bgstack15.ddns.net/blog/posts/2024/07/04/android-and-my-printer/</link><dc:creator>bgstack15</dc:creator><description>&lt;h2&gt;Default Print Service&lt;/h2&gt;
&lt;p&gt;For the built-in Android Default Print Service, omit the protocol.&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code literal-block"&gt;print.ipa.example.com:631/printers/ml1865w
&lt;/pre&gt;&lt;/div&gt;

&lt;h2&gt;CUPS Printing&lt;/h2&gt;
&lt;p&gt;To use &lt;a href="https://bgstack15.ddns.net/blog/outbound/https:/f-droid.org/en/packages/io.github.benoitduffez.cupsprint/"&gt;CUPS Printing&lt;/a&gt; with my printer, use this url:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code literal-block"&gt;https://print.ipa.example.com:631/printers/ml1865w
&lt;/pre&gt;&lt;/div&gt;

&lt;p&gt;It complained about the untrusted cert, which suggests that CUPS Printing does not rely on the user-added certificates.&lt;/p&gt;
&lt;h3&gt;Alternative research&lt;/h3&gt;
&lt;p&gt;I researched, and unfortunately this fix for this app is not eough.&lt;/p&gt;
&lt;p&gt;Perhaps the application needs to update the &lt;code&gt;network_security_config.xml&lt;/code&gt; to include &lt;code&gt;&amp;lt;certificates src="user" /&amp;gt;&lt;/code&gt; like F-droid itself &lt;a href="https://bgstack15.ddns.net/blog/outbound/https:/gitlab.com/fdroid/fdroidclient/-/merge_requests/1402/diffs"&gt;needed&lt;/a&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;div class="code"&gt;&lt;pre class="code literal-block"&gt;&lt;span class="cp"&gt;&amp;lt;?xml version="1.0" encoding="utf-8"?&amp;gt;&lt;/span&gt;
&lt;span class="nt"&gt;&amp;lt;network-security-config&amp;gt;&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;lt;base-config&lt;/span&gt; &lt;span class="na"&gt;cleartextTrafficPermitted=&lt;/span&gt;&lt;span class="s"&gt;"true"&lt;/span&gt;&lt;span class="nt"&gt;&amp;gt;&lt;/span&gt;
        &lt;span class="nt"&gt;&amp;lt;trust-anchors&amp;gt;&lt;/span&gt;
            \&lt;span class="cp"&gt;&amp;lt;!-- Trust preinstalled CAs --\&amp;gt;&lt;/span&gt;
            &lt;span class="nt"&gt;&amp;lt;certificates&lt;/span&gt; &lt;span class="na"&gt;src=&lt;/span&gt;&lt;span class="s"&gt;"system"&lt;/span&gt; &lt;span class="nt"&gt;/&amp;gt;&lt;/span&gt;
            \&lt;span class="cp"&gt;&amp;lt;!-- Additionally trust user added CAs --\&amp;gt;&lt;/span&gt;
            &lt;span class="nt"&gt;&amp;lt;certificates&lt;/span&gt; &lt;span class="na"&gt;src=&lt;/span&gt;&lt;span class="s"&gt;"user"&lt;/span&gt; &lt;span class="nt"&gt;/&amp;gt;&lt;/span&gt;
        &lt;span class="nt"&gt;&amp;lt;/trust-anchors&amp;gt;&lt;/span&gt;
    &lt;span class="nt"&gt;&amp;lt;/base-config&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;

&lt;/blockquote&gt;</description><category>android</category><category>floss</category><category>print</category><guid>https://bgstack15.ddns.net/blog/posts/2024/07/04/android-and-my-printer/</guid><pubDate>Thu, 04 Jul 2024 13:11:00 GMT</pubDate></item><item><title>Calendar solution for internal network</title><link>https://bgstack15.ddns.net/blog/posts/2022/05/21/calendar-solution-for-internal-network/</link><dc:creator>bgstack15</dc:creator><description>&lt;h3&gt;Overview&lt;/h3&gt;
&lt;p&gt;As part of my efforts to de-google my life, the Calendar solution is a fully self-hosted and FLOSS project. This project uses Radicale caldav server, which is already packaged for EL7 (but I repackage a newer version). The project also uses InfCloud which is a web client for caldav, which is loosely hardcoded to use this existing radicale instance.&lt;/p&gt;
&lt;p&gt;Additional components include the F-droid packages of davX⁵ (carddav sync utility) and ETar, a calendar client.&lt;/p&gt;
&lt;h3&gt;Prequisites&lt;/h3&gt;
&lt;p&gt;Apache httpd is installed. TLS certificates are in use, to protect the password traffic.&lt;/p&gt;
&lt;h3&gt;Building&lt;/h3&gt;
&lt;p&gt;CentOS 7 provides radicale 1.1, which is not the current version. I adapted the radicale and various python dependencies from Fedora, and also wrote the rpm spec for InfCloud. A copy of Git repository for &lt;a href="https://gitlab.com/bgstack15/build-radicale-el7.git"&gt;build-radicale-el7&lt;/a&gt; exists here. See &lt;a href="https://gitlab.com/bgstack15/build-radicale-el7"&gt;build-radicale-el7/README.md&lt;/a&gt; for this whole process. NOTE: this includes one patch that I wrote to allow automatic login using the reverse proxy apache ldap authentication.&lt;/p&gt;
&lt;p&gt;I established a &lt;a href="https://copr.fedorainfracloud.org/coprs/bgstack15/radicale-el7/"&gt;copr&lt;/a&gt; to hold the rpm packages.&lt;/p&gt;
&lt;h3&gt;Installing on production&lt;/h3&gt;
&lt;p&gt;On server1, I ran a number of steps which are also documented in the [main server log][3].&lt;/p&gt;
&lt;p&gt;Add the copr repo.&lt;/p&gt;
&lt;pre class="code literal-block"&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;curl https://copr.fedorainfracloud.org/coprs/bgstack15/radicale-el7/repo/epel-7/bgstack15-radicale-el7-epel-7.repo | sudo tee /etc/yum.repos.d/bgstack15-radicale-el7.repo
sudo yum install radicale3 infcloud
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;Customize &lt;code&gt;/etc/radicale/config&lt;/code&gt; and &lt;code&gt;/etc/infcloud/config.js&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Add redirects for my http virtual host in httpd:&lt;/p&gt;
&lt;pre class="code literal-block"&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;# &lt;span class="nv"&gt;Force&lt;/span&gt; &lt;span class="nv"&gt;https&lt;/span&gt; &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="nv"&gt;these&lt;/span&gt; &lt;span class="nv"&gt;pages&lt;/span&gt; &lt;span class="nv"&gt;or&lt;/span&gt; &lt;span class="nv"&gt;apps&lt;/span&gt;
&lt;span class="nv"&gt;RewriteCond&lt;/span&gt; &lt;span class="o"&gt;%&lt;/span&gt;{&lt;span class="nv"&gt;HTTPS&lt;/span&gt;} &lt;span class="o"&gt;!=&lt;/span&gt;&lt;span class="nv"&gt;on&lt;/span&gt;
&lt;span class="nv"&gt;Redirect&lt;/span&gt; &lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="nv"&gt;radicale&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt; &lt;span class="nv"&gt;https&lt;/span&gt;:&lt;span class="o"&gt;//&lt;/span&gt;&lt;span class="nv"&gt;www&lt;/span&gt;.&lt;span class="nv"&gt;example&lt;/span&gt;.&lt;span class="nv"&gt;com&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="nv"&gt;radicale&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;
&lt;span class="nv"&gt;RewriteCond&lt;/span&gt; &lt;span class="o"&gt;%&lt;/span&gt;{&lt;span class="nv"&gt;HTTPS&lt;/span&gt;} &lt;span class="o"&gt;!=&lt;/span&gt;&lt;span class="nv"&gt;on&lt;/span&gt;
&lt;span class="nv"&gt;Redirect&lt;/span&gt; &lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="nv"&gt;calendar&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt; &lt;span class="nv"&gt;https&lt;/span&gt;:&lt;span class="o"&gt;//&lt;/span&gt;&lt;span class="nv"&gt;www&lt;/span&gt;.&lt;span class="nv"&gt;example&lt;/span&gt;.&lt;span class="nv"&gt;com&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="nv"&gt;calendar&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;Also add useful VirtualHost contents to my apache config file &lt;code&gt;ssl-common.cnf&lt;/code&gt;:&lt;/p&gt;
&lt;pre class="code literal-block"&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;# &lt;span class="mi"&gt;2022&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;05&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;17&lt;/span&gt;
#&lt;span class="nv"&gt;ServerName&lt;/span&gt; &lt;span class="nv"&gt;calendar&lt;/span&gt;.&lt;span class="nv"&gt;example&lt;/span&gt;.&lt;span class="nv"&gt;com&lt;/span&gt;
&lt;span class="nv"&gt;RewriteEngine&lt;/span&gt; &lt;span class="nv"&gt;On&lt;/span&gt;
&lt;span class="nv"&gt;RewriteRule&lt;/span&gt; &lt;span class="o"&gt;^/&lt;/span&gt;&lt;span class="nv"&gt;radicale&lt;/span&gt;$ &lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="nv"&gt;radicale&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt; [&lt;span class="nv"&gt;R&lt;/span&gt;,&lt;span class="nv"&gt;L&lt;/span&gt;]
&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nv"&gt;Location&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;/radicale/&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt;
   &lt;span class="nv"&gt;ProxyPreserveHost&lt;/span&gt; &lt;span class="nv"&gt;On&lt;/span&gt;
   &lt;span class="nv"&gt;Order&lt;/span&gt; &lt;span class="nv"&gt;deny&lt;/span&gt;,&lt;span class="nv"&gt;allow&lt;/span&gt;
   &lt;span class="nv"&gt;Deny&lt;/span&gt; &lt;span class="nv"&gt;from&lt;/span&gt; &lt;span class="nv"&gt;all&lt;/span&gt;
   &lt;span class="nv"&gt;AuthType&lt;/span&gt; &lt;span class="nv"&gt;Basic&lt;/span&gt;
   &lt;span class="nv"&gt;AuthName&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;LDAP protected&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;
   &lt;span class="nv"&gt;AuthBasicProvider&lt;/span&gt; &lt;span class="nv"&gt;ldap&lt;/span&gt;
   &lt;span class="nv"&gt;AuthLDAPGroupAttribute&lt;/span&gt; &lt;span class="nv"&gt;member&lt;/span&gt;
   &lt;span class="nv"&gt;AuthLDAPSubGroupClass&lt;/span&gt; &lt;span class="nv"&gt;group&lt;/span&gt;
   # &lt;span class="k"&gt;If&lt;/span&gt; &lt;span class="nv"&gt;anonymous&lt;/span&gt; &lt;span class="nv"&gt;search&lt;/span&gt; &lt;span class="nv"&gt;is&lt;/span&gt; &lt;span class="nv"&gt;disabled&lt;/span&gt;, &lt;span class="nv"&gt;provide&lt;/span&gt; &lt;span class="nv"&gt;dn&lt;/span&gt; &lt;span class="nv"&gt;and&lt;/span&gt; &lt;span class="nv"&gt;pw&lt;/span&gt;.
   #&lt;span class="nv"&gt;AuthLDAPBindDN&lt;/span&gt; &lt;span class="nv"&gt;uid&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="nv"&gt;service&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="nv"&gt;account&lt;/span&gt;,&lt;span class="nv"&gt;cn&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="nv"&gt;users&lt;/span&gt;,&lt;span class="nv"&gt;cn&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="nv"&gt;accounts&lt;/span&gt;,&lt;span class="nv"&gt;dc&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="nv"&gt;ipa&lt;/span&gt;,&lt;span class="nv"&gt;dc&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="nv"&gt;example&lt;/span&gt;,&lt;span class="nv"&gt;dc&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="nv"&gt;com&lt;/span&gt;
   #&lt;span class="nv"&gt;AuthLDAPBindPassword&lt;/span&gt; &lt;span class="nv"&gt;mypw&lt;/span&gt;
   &lt;span class="nv"&gt;AuthLDAPGroupAttributeIsDN&lt;/span&gt; &lt;span class="nv"&gt;On&lt;/span&gt;
   &lt;span class="nv"&gt;AuthLDAPURL&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;ldaps://dns1.ipa.internal.com:636 dns2.ipa.internal.com:636/cn=users,cn=accounts,dc=ipa,dc=internal,dc=com?uid,memberof,gecos?sub?(objectClass=person)&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;
   #?&lt;span class="nv"&gt;sub&lt;/span&gt;?&lt;span class="ss"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;objectClass&lt;/span&gt;&lt;span class="o"&gt;=*&lt;/span&gt;&lt;span class="ss"&gt;)&lt;/span&gt;
   &lt;span class="nv"&gt;Require&lt;/span&gt; &lt;span class="nv"&gt;valid&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="nv"&gt;user&lt;/span&gt;
   &lt;span class="nv"&gt;Satisfy&lt;/span&gt; &lt;span class="nv"&gt;any&lt;/span&gt;
   # &lt;span class="nv"&gt;My&lt;/span&gt; &lt;span class="nv"&gt;radical&lt;/span&gt; &lt;span class="nv"&gt;set&lt;/span&gt; &lt;span class="nv"&gt;up&lt;/span&gt; &lt;span class="nv"&gt;uses&lt;/span&gt; &lt;span class="nv"&gt;HTTP_X_REMOTE_USER&lt;/span&gt; &lt;span class="nv"&gt;as&lt;/span&gt; &lt;span class="nv"&gt;username&lt;/span&gt; &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="nv"&gt;authentication&lt;/span&gt;
   &lt;span class="nv"&gt;RequestHeader&lt;/span&gt; &lt;span class="nv"&gt;set&lt;/span&gt; &lt;span class="nv"&gt;X_REMOTE_USER&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;%{AUTHENTICATE_uid}e&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;
   # &lt;span class="nv"&gt;This&lt;/span&gt; &lt;span class="nv"&gt;does&lt;/span&gt; &lt;span class="nv"&gt;not&lt;/span&gt; &lt;span class="nv"&gt;populate&lt;/span&gt; &lt;span class="nv"&gt;correctly&lt;/span&gt;. &lt;span class="nv"&gt;Probably&lt;/span&gt; &lt;span class="nv"&gt;the&lt;/span&gt; &lt;span class="nv"&gt;ldap&lt;/span&gt; &lt;span class="nv"&gt;memberOf&lt;/span&gt; &lt;span class="nv"&gt;attribute&lt;/span&gt; &lt;span class="nv"&gt;is&lt;/span&gt; &lt;span class="nv"&gt;derived&lt;/span&gt; &lt;span class="nv"&gt;and&lt;/span&gt; &lt;span class="nv"&gt;not&lt;/span&gt; &lt;span class="nv"&gt;real&lt;/span&gt;?
   &lt;span class="nv"&gt;RequestHeader&lt;/span&gt; &lt;span class="nv"&gt;set&lt;/span&gt; &lt;span class="nv"&gt;X_GROUPS&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;%{AUTHENTICATE_memberOf}e&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;
   # &lt;span class="nv"&gt;This&lt;/span&gt; &lt;span class="nv"&gt;populates&lt;/span&gt; &lt;span class="nv"&gt;correctly&lt;/span&gt;
   &lt;span class="nv"&gt;RequestHeader&lt;/span&gt; &lt;span class="nv"&gt;set&lt;/span&gt; &lt;span class="nv"&gt;X_GECOS&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;%{AUTHENTICATE_gecos}e&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;
   &lt;span class="nv"&gt;ProxyPass&lt;/span&gt;        &lt;span class="nv"&gt;http&lt;/span&gt;:&lt;span class="o"&gt;//&lt;/span&gt;&lt;span class="nv"&gt;localhost&lt;/span&gt;:&lt;span class="mi"&gt;5232&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt; &lt;span class="nv"&gt;retry&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;20&lt;/span&gt; &lt;span class="nv"&gt;connectiontimeout&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;300&lt;/span&gt; &lt;span class="nb"&gt;timeout&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;300&lt;/span&gt;
   &lt;span class="nv"&gt;ProxyPassReverse&lt;/span&gt; &lt;span class="nv"&gt;http&lt;/span&gt;:&lt;span class="o"&gt;//&lt;/span&gt;&lt;span class="nv"&gt;localhost&lt;/span&gt;:&lt;span class="mi"&gt;5232&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;
   &lt;span class="nv"&gt;RequestHeader&lt;/span&gt;    &lt;span class="nv"&gt;set&lt;/span&gt; &lt;span class="nv"&gt;X&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="nv"&gt;Script&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="nv"&gt;Name&lt;/span&gt; &lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="nv"&gt;radicale&lt;/span&gt;
&lt;span class="o"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="nv"&gt;Location&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;I customized the storage of calendars (aka collections) to be on the main storage area:&lt;/p&gt;
&lt;pre class="code literal-block"&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="n"&gt;sudo&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;mkdir&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;p&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="k"&gt;var&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;server1&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;shares&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;public&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;Support&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;Systems&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;server1&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="k"&gt;var&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;lib&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;radicale&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;collections&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;span class="n"&gt;sudo&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;mv&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="k"&gt;var&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;lib&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;radicale&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;collections&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="k"&gt;var&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;server1&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;shares&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;public&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;Support&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;Systems&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;server1&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="k"&gt;var&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;lib&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;radicale&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;span class="n"&gt;sudo&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;ln&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;s&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="k"&gt;var&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;server1&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;shares&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;public&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;Support&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;Systems&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;server1&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="k"&gt;var&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;lib&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;radicale&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;collections&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="k"&gt;var&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;lib&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;radicale&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;collections&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;span class="n"&gt;sudo&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;semanage&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;fcontext&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;a&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;t&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;radicale_var_lib_t&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s1"&gt;'/var/server1/shares/public/Support/Systems/server1/var/lib/radicale/collections(/.*)?'&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;I also added all these aforementioned config files to the host-bup config file.&lt;/p&gt;
&lt;p&gt;Start and enable radicale service.&lt;/p&gt;
&lt;pre class="code literal-block"&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;sudo systemctl enable radicale
sudo systemctl start radicale
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;Make a symlink in the web root directory that points to the infcloud contents.&lt;/p&gt;
&lt;pre class="code literal-block"&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="n"&gt;sudo&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;ln&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;s&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;usr&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;share&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;infcloud&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;radicale_infcloud&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;web&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="k"&gt;var&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;www&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;html&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;calendar&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;h3&gt;Making good config choices&lt;/h3&gt;
&lt;p&gt;In order for InfCloud to save which calendars are enabled/visible by default, you need to turn "settingsAccount" on in config.js. This attribute causes InfCloud to store some metadata about the user choices on the caldav server (Radicale). Without this feature, the InfCloud user cannot even change which calendars are visible!&lt;/p&gt;
&lt;h3&gt;Summary of associated files&lt;/h3&gt;
&lt;p&gt;On server1, the production server:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;/etc/radicale/config&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;/etc/infcloud/config.js&lt;/code&gt; symlinked to with /var/www/calendar/&lt;/li&gt;
&lt;li&gt;&lt;code&gt;/etc/infcloud/cache.manifest&lt;/code&gt; symlinked to within /var/www/html/calendar/&lt;/li&gt;
&lt;li&gt;&lt;code&gt;/usr/sbin/update-infcloud-cache&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;/var/www/html/calendar&lt;/code&gt; is a symlink to &lt;code&gt;/usr/share/infcloud/radicale_infcloud/web&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Operations&lt;/h3&gt;
&lt;p&gt;Some tasks that will happen over time are listed here.&lt;/p&gt;
&lt;h4&gt;Modifying InfCloud files or config&lt;/h4&gt;
&lt;p&gt;After making any changes to anything for InfCloud (the web client), you need to update the cache manifest file. It is possible that touching the file works, but a method for updating the version number in the file is with script:&lt;/p&gt;
&lt;pre class="code literal-block"&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;sudo update-infcloud-cache
&lt;/code&gt;&lt;/pre&gt;

&lt;h4&gt;Controling collections&lt;/h4&gt;
&lt;p&gt;To add, modify, or remove personal collections (calendars, address books, and todo lists), visit &lt;a href="https://www.example.com/radicale/"&gt;https://www.example.com/radicale/&lt;/a&gt;. Log in with a domain credential.&lt;/p&gt;
&lt;h4&gt;Adding a client&lt;/h4&gt;
&lt;p&gt;To connect a carddav/caldav client to the Calendar service, use url &lt;a href="https://www.example.com/radicale/"&gt;https://www.example.com/radicale/&lt;/a&gt; and select "Use username and password."&lt;/p&gt;
&lt;h4&gt;Using a web calendar&lt;/h4&gt;
&lt;p&gt;To use a rich web client, visit &lt;a href="https://www.example.com/calendar/"&gt;https://www.example.com/calendar/&lt;/a&gt; and type in your domain username and password.&lt;/p&gt;
&lt;h5&gt;Sending invitations for event from web calendar&lt;/h5&gt;
&lt;p&gt;In the web client, select an event. Select button "Download," which saves a .ics file. Send this .ics file in your preferred mail client to your guests.&lt;/p&gt;
&lt;h5&gt;Importing event to web calendar&lt;/h5&gt;
&lt;p&gt;Feature not implemented yet. Gotta say unh!&lt;/p&gt;
&lt;h4&gt;Sharing calendar with other Radicale user&lt;/h4&gt;
&lt;p&gt;This step has to happen first, before the following Sharing operations can work.&lt;/p&gt;
&lt;p&gt;An admin has to modify file storage:&lt;code&gt;/etc/radicale/rights&lt;/code&gt; and add some steps. Create one rule per &lt;strong&gt;[uniquely-named-section]&lt;/strong&gt;. Use uppercase permission letters for a "root" collection, i.e., a username. Use lowercase letters for any child collections. The uuid of a collection is required: the pretty name is not accepted.&lt;/p&gt;
&lt;p&gt;The following is a way to allow all authenticated users to enumerate the items owned by domainjoin, and also read all those items.&lt;/p&gt;
&lt;pre class="code literal-block"&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="k"&gt;[public-principal]&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;span class="na"&gt;user: .+&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;span class="na"&gt;collection: domainjoin&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;span class="na"&gt;permissions: rRi&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;span class="k"&gt;[public-calendars]&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;span class="na"&gt;user: .+&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;span class="na"&gt;collection: domainjoin/[^/]+&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;span class="na"&gt;permissions: rRi&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;Adding a "w" or "W" as appropriate to the &lt;em&gt;permissions:&lt;/em&gt; entry would enable write access. Another example, for username2 to write to a specific bgstack15 calendar:&lt;/p&gt;
&lt;pre class="code literal-block"&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="k"&gt;[rule1]&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;span class="na"&gt;user: username2&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;span class="na"&gt;collection: bgstack15&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;span class="na"&gt;permissions: R&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;span class="k"&gt;[rule2]&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;span class="na"&gt;user: username2&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;span class="na"&gt;collection: bgstack15/68cb9dbf-7546-8023-ca4c-c69bc64918a2&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;span class="na"&gt;permissions: rwi&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;It is probable that read access to the root collection is required in order for the web calendar to be able to enumerate the one shared calendar, but further experimentation should be done.&lt;/p&gt;
&lt;h4&gt;Opening a shared calendar in web calendar&lt;/h4&gt;
&lt;p&gt;Unfortunately this so far is only known to work by modifying &lt;code&gt;/etc/infcloud/config.js&lt;/code&gt; which requires admin access to server1. If all users of the web calendar should be able to view/edit a collection, add the owning user to attribute &lt;code&gt;additionalResources: ['user5']&lt;/code&gt; inside var &lt;strong&gt;globalNetworkCheckSettings&lt;/strong&gt;. In this example, user5 owns a shared collection, as defined by heading &lt;em&gt;Sharing calendar with other Radicale user&lt;/em&gt;. Of course, after modifying config.js, run &lt;code&gt;update-infcloud-cache&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;For a specific login to access another specific login root collection (because InfCloud relies on enumerating collections underneath a root collection, i.e., user, rather than pointing to a specific collectioN), you can use the custom stackrpms attribute &lt;strong&gt;perUserAdditionalResources&lt;/strong&gt; such as this example:&lt;/p&gt;
&lt;pre class="code literal-block"&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="k"&gt;var&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;globalNetworkCheckSettings&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="n"&gt;perUserAdditionalResources&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;span class="w"&gt;     &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;"bgstack15"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;allowed&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;"username2"&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;span class="w"&gt;     &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;"username2"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;allowed&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;"bgstack15"&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;Now, the shared collections should populate in the web calendar. If the logged-in user does not have access to this resource, an unfixable and unhideable exclamation mark "!" will appear in the web calendar in the left-hand side menu. It will not be clear to the user what has gone wrong.&lt;/p&gt;
&lt;h4&gt;Opening a shared calendar with davX⁵&lt;/h4&gt;
&lt;p&gt;Unfortunately the only plan for accessing shared calendars is to set up a new connection in DavX⁵ with the exact url of the target calendar, e.g. &lt;strong&gt;https://www.example.com/radicale/domainjoin/338119a7-3556-0a9b-67ab-be391db1ae77/&lt;/strong&gt; which is selectable for copy-paste when the owning user visits &lt;a href="https://www.example.com/radicale/"&gt;/radicale/&lt;/a&gt; and enumerates his collections.&lt;/p&gt;
&lt;p&gt;This task will make a new entry that enumerates that logged-in user collections, and also this one exact collection.&lt;/p&gt;
&lt;h3&gt;Future improvements&lt;/h3&gt;
&lt;p&gt;Investigate more calendar sharing.
Migrate address books.&lt;/p&gt;
&lt;h3&gt;References&lt;/h3&gt;
&lt;h4&gt;Internal files&lt;/h4&gt;
&lt;p&gt;[3]: server1 history log&lt;/p&gt;
&lt;h4&gt;Git repositories&lt;/h4&gt;
&lt;p&gt;[6]: &lt;a href="https://gitlab.com/bgstack15/radicale_auth_ldap.git"&gt;https://gitlab.com/bgstack15/radicale_auth_ldap.git&lt;/a&gt; I ended up not using this, but it is worthy of mentioning.&lt;/p&gt;
&lt;h4&gt;Weblinks&lt;/h4&gt;
&lt;blockquote&gt;
&lt;p&gt;conaclos
 An interesting alternative is Radicale &lt;a href="https://bgstack15.ddns.net/blog/posts/2022/05/21/calendar-solution-for-internal-network/research-caldav.txt"&gt;1&lt;/a&gt;. Both are very lightweight. I mainly chose Radicale over Baïkal because it is written in Python. On the client side DAVx⁵ &lt;a href="https://bgstack15.ddns.net/blog/posts/2022/05/21/calendar-solution-for-internal-network/replace-google-research.txt"&gt;2&lt;/a&gt; do a good job.
&lt;a href="https://bgstack15.ddns.net/blog/posts/2022/05/21/calendar-solution-for-internal-network/research-caldav.txt"&gt;1&lt;/a&gt; https://radicale.org/v3.html &lt;a href="https://bgstack15.ddns.net/blog/posts/2022/05/21/calendar-solution-for-internal-network/replace-google-research.txt"&gt;2&lt;/a&gt; https://www.davx5.com/
  cube00
  I've been using Radicale for a few years now and it has been fantastic. Extremely lightweight but also quite flexible with its permissions model since we have a shared family calendar.
  The backend storage is simply ics/vcf files and while I'm sure it's not the most efficient if you had a large number of users, for our small group it's been perfect and very satisfying knowing your data is there in plain text files.
  Although if I'm honest I'm just cheap and wanted to get by on the smallest VM offered by my cloud provider and NextCloud was too demanding for that.
    jamessb
    &amp;gt; Extremely lightweight but also quite flexible with its permissions model since we have a shared family calendar.
    How are you doing this?
    A while ago I skimmed the documentation for a couple of CalDAV servers to try and figure out how I could self-host a shared calendar, but couldn't see an easy way to do this.
    I've just done some more searching, and it seems there are two suggested ways to do this with Radicale:
    * create a separate account for the shared calendar, and tell everyone who needs write access the password
    * create the calendar in one use's directory, and add a symlink to it in the user directories for any other users who need write access.
    Both of which seem like a bit of hack compared to bring able to explicitly state that a list of users have write access to a calendar in a config file or through a UI.
      cube00
      I created a collection with the name of our domain name and then used this example&lt;a href="https://bgstack15.ddns.net/blog/posts/2022/05/21/calendar-solution-for-internal-network/research-caldav.txt"&gt;1&lt;/a&gt; to regex the domain out of the user's login email address to allow them access to the shared collection.
      &lt;a href="https://bgstack15.ddns.net/blog/posts/2022/05/21/calendar-solution-for-internal-network/research-caldav.txt"&gt;1&lt;/a&gt;: https://github.com/Kozea/Radicale/blob/497b5141b066d266c318e...&lt;/p&gt;
&lt;h2&gt;Example: Grant users of the form user@domain.tld read access to the&lt;/h2&gt;
&lt;h2&gt;collection "domain.tld"&lt;/h2&gt;
&lt;h2&gt;Allow reading the domain collection&lt;/h2&gt;
&lt;h2&gt;[read-domain-principal]&lt;/h2&gt;
&lt;h2&gt;user: .+@([^@]+)&lt;/h2&gt;
&lt;h2&gt;collection:&lt;/h2&gt;
&lt;h2&gt;permissions: R&lt;/h2&gt;
&lt;h2&gt;Allow reading all calendars and address books that are direct children of&lt;/h2&gt;
&lt;h2&gt;the domain collection&lt;/h2&gt;
&lt;h2&gt;[read-domain-calendars]&lt;/h2&gt;
&lt;h2&gt;user: .+@([^@]+)&lt;/h2&gt;
&lt;h2&gt;collection: {0}/[^/]+&lt;/h2&gt;
&lt;h2&gt;permissions: r&lt;/h2&gt;
&lt;/blockquote&gt;</description><category>calendar</category><category>floss</category><category>infcloud</category><category>radicale</category><category>selfhosting</category><guid>https://bgstack15.ddns.net/blog/posts/2022/05/21/calendar-solution-for-internal-network/</guid><pubDate>Sat, 21 May 2022 12:58:53 GMT</pubDate></item></channel></rss>