---
url: https://flip-chart.ru/developers/en/on-premise/installation/other/ldap.md
description: >-
  Set up sign-in to flip on-premise via LDAP: connection parameters in the
  backend configuration (Auth.LdapAuthConfig), a configuration example and
  Active Directory attributes.
---

# LDAP integration

::: tip Note
LDAP integration is configured in the [backend](/en/on-premise/config/backend) configuration file, in the `Auth.LdapAuthConfig` section. Restart the backend container after changing the configuration.
:::

## Connection settings

| Parameter | Description |
|---|---|
| `Address` | LDAP server URL: `ldap://host:389` or `ldaps://host:636` |
| `BaseDN` | Search base for users |
| `BindDN` | DN of the service account with read access to the directory |
| `BindPassword` | Service account password |
| `UseTLS` | `true` — run STARTTLS after connecting via `ldap://` |
| `Attributes` | Attribute names: `DN`, `CN` (display name), `Mail` (email), `AccountStatus` (account status) |

## Configuration example

```yaml
Auth:
  LdapAuthConfig:
    Enable: true
    Address: ldap://ldap.example.ru:389
    BaseDN: ou=users,dc=example,dc=ru
    BindDN: cn=flip-bind,ou=service,dc=example,dc=ru
    BindPassword: secretpasswd
    UseTLS: true
    Attributes:
      DN: dn
      CN: cn
      Mail: mail
      AccountStatus: accountStatus
```

For Active Directory, use the `cn` or `displayName` (name) and `mail` (email) attributes.

::: danger One provider at a time
Only one provider can be enabled at a time: `LdapAuthConfig` or `KeyCloakAuthConfig`. SSO via OIDC/SAML is configured in the [app interface](/en/on-premise/installation/other/sso).
:::
