Skip to content

LDAP integration ​

Note

LDAP integration is configured in the backend configuration file, in the Auth.LdapAuthConfig section. Restart the backend container after changing the configuration.

Connection settings ​

ParameterDescription
AddressLDAP server URL: ldap://host:389 or ldaps://host:636
BaseDNSearch base for users
BindDNDN of the service account with read access to the directory
BindPasswordService account password
UseTLStrue — run STARTTLS after connecting via ldap://
AttributesAttribute names: DN, CN (display name), Mail (email), AccountStatus (account status)

Configuration example ​

yaml
Auth:
  LdapAuthConfig:
    Enable: true
    Address: ldap://ldap.example.ru:389
    BaseDN: ou=users,dc=example,dc=ru
    BindDN: cn=flip-bind,ou=service,dc=example,dc=ru
    BindPassword: secretpasswd
    UseTLS: true
    Attributes:
      DN: dn
      CN: cn
      Mail: mail
      AccountStatus: accountStatus

For Active Directory, use the cn or displayName (name) and mail (email) attributes.

One provider at a time

Only one provider can be enabled at a time: LdapAuthConfig or KeyCloakAuthConfig. SSO via OIDC/SAML is configured in the app interface.

flip on-premise and cloud documentation