LDAP integration
Note
LDAP integration is configured in the backend configuration file, in the Auth.LdapAuthConfig section. Restart the backend container after changing the configuration.
Connection settings
| Parameter | Description |
|---|---|
Address | LDAP server URL: ldap://host:389 or ldaps://host:636 |
BaseDN | Search base for users |
BindDN | DN of the service account with read access to the directory |
BindPassword | Service account password |
UseTLS | true — run STARTTLS after connecting via ldap:// |
Attributes | Attribute names: DN, CN (display name), Mail (email), AccountStatus (account status) |
Configuration example
yaml
Auth:
LdapAuthConfig:
Enable: true
Address: ldap://ldap.example.ru:389
BaseDN: ou=users,dc=example,dc=ru
BindDN: cn=flip-bind,ou=service,dc=example,dc=ru
BindPassword: secretpasswd
UseTLS: true
Attributes:
DN: dn
CN: cn
Mail: mail
AccountStatus: accountStatusFor Active Directory, use the cn or displayName (name) and mail (email) attributes.
One provider at a time
Only one provider can be enabled at a time: LdapAuthConfig or KeyCloakAuthConfig. SSO via OIDC/SAML is configured in the app interface.