Skip to content

LDAP directory

Directory

Description

Short description of this directory.

Text. Name in the API: description.

Connection

Server URL

URL of the LDAP server.

An address (URL). Default: ldap://localhost:389. Name in the API: url.

Connection Timeout

Connection timeout to the server.

A length of time. Default: 30s. Name in the API: timeout.

Enable TLS

Use TLS to connect to the remote server.

On or off. Name in the API: useTls.

Allow Invalid Certificates

Allow invalid TLS certificates when connecting to the server.

On or off. Name in the API: allowInvalidCerts.

Bind

Base DN

The base distinguished name (DN) from where searches should begin.

Text. Name in the API: baseDn.

Bind DN

The distinguished name of the account that the server will bind as to connect to the LDAP directory.

Text. Name in the API: bindDn.

Bind Secret

The password or secret for the bind DN account.

Settings of their own: see Secret key optional. Name in the API: bindSecret.

Use Bind Authentication

Whether to use bind authentication. When enabled, the server will use the filterLogin to search for the user account and then attempt to bind as that account using the provided password. When disabled, the server will use the bind DN and secret to connect to the LDAP server and obtain the secret from the account entry using the attrSecret attribute.

On or off. Default: On. Name in the API: bindAuthentication.

Filters

Login Filter

Searches for user accounts by e-mail address during authentication.

Text. Default: (&(objectClass=inetOrgPerson)(mail=?)). Name in the API: filterLogin.

Mailbox Filter

Searches for users or groups matching a recipient e-mail address or alias.

Text. Name in the API: filterMailbox.

Member Of Filter

Searches for groups that an account is member of. Use when the group membership is not provided in the account entry. The ? in the filter will be replaced with the account DN.

Text. Default: (&(objectClass=groupOfNames)(member=?)). Name in the API: filterMemberOf.

Attributes

Account Type Attribute

LDAP attribute for the user's account type, if missing defaults to individual.

A list. Each one: text. Default: objectClass. Name in the API: attrClass.

Description Attribute

LDAP attributes used to store the user's description.

A list. Each one: text. Default: description. Name in the API: attrDescription.

Primary E-mail Attribute

LDAP attribute for the user's primary email address.

A list. Each one: text. Default: mail. Name in the API: attrEmail.

E-mail Alias Attribute

LDAP attribute for the user's email alias(es)

A list. Each one: text. Default: mailAlias. Name in the API: attrEmailAlias.

Member Of Attribute

LDAP attributes for the groups that a user belongs to. Used when filterMemberOf is not configured or when the group membership is also provided in the account entry.

A list. Each one: text. Default: memberOf. Name in the API: attrMemberOf.

Password Attribute

LDAP attribute for the user's password hash. This setting is required when binding as a service user. When using bind authentication, configure the secret-changed attribute instead.

A list. Each one: text. Default: userPassword. Name in the API: attrSecret.

Password Changed Attribute

LDAP attribute that provides a password change hash or a timestamp indicating when the password was last changed. When using bind authentication, this attribute is used to determine when to invalidate OAuth tokens.

A list. Each one: text. Default: pwdChangeTime. Name in the API: attrSecretChanged.

Group Object Class

LDAP object class used to identify group entries.

Text. Default: groupOfNames. Name in the API: groupClass.

Pool

Max Connections

Maximum number of connections that can be maintained simultaneously in the connection pool.

A number. Default: 10. Name in the API: poolMaxConnections.

Create Timeout

Maximum amount of time that the connection pool will wait for a new connection to be created.

A length of time. Default: 30s. Name in the API: poolTimeoutCreate.

Recycle Timeout

Maximum amount of time that the connection pool manager will wait for a connection to be recycled.

A length of time. Default: 30s. Name in the API: poolTimeoutRecycle.

Wait Timeout

Maximum amount of time that the connection pool will wait for a connection to become available.

A length of time. Default: 30s. Name in the API: poolTimeoutWait.

Tenant

Identifier for the tenant this directory belongs to.

One of your Tenants, chosen from a list. Name in the API: memberTenantId.