LDAP directory¶
Directory¶
Description¶
Short description of this directory.
Text. Name in the API: description.
Connection¶
Server URL¶
URL of the LDAP server.
An address (URL). Default: ldap://localhost:389. Name in the API: url.
Connection Timeout¶
Connection timeout to the server.
A length of time. Default: 30s. Name in the API: timeout.
Enable TLS¶
Use TLS to connect to the remote server.
On or off. Name in the API: useTls.
Allow Invalid Certificates¶
Allow invalid TLS certificates when connecting to the server.
On or off. Name in the API: allowInvalidCerts.
Bind¶
Base DN¶
The base distinguished name (DN) from where searches should begin.
Text. Name in the API: baseDn.
Bind DN¶
The distinguished name of the account that the server will bind as to connect to the LDAP directory.
Text. Name in the API: bindDn.
Bind Secret¶
The password or secret for the bind DN account.
Settings of their own: see Secret key optional. Name in the API: bindSecret.
Use Bind Authentication¶
Whether to use bind authentication. When enabled, the server will use the filterLogin to search for the user account and then attempt to bind as that account using the provided password. When disabled, the server will use the bind DN and secret to connect to the LDAP server and obtain the secret from the account entry using the attrSecret attribute.
On or off. Default: On. Name in the API: bindAuthentication.
Filters¶
Login Filter¶
Searches for user accounts by e-mail address during authentication.
Text. Default: (&(objectClass=inetOrgPerson)(mail=?)). Name in the API: filterLogin.
Mailbox Filter¶
Searches for users or groups matching a recipient e-mail address or alias.
Text. Name in the API: filterMailbox.
Member Of Filter¶
Searches for groups that an account is member of. Use when the group membership is not provided in the account entry. The ? in the filter will be replaced with the account DN.
Text. Default: (&(objectClass=groupOfNames)(member=?)). Name in the API: filterMemberOf.
Attributes¶
Account Type Attribute¶
LDAP attribute for the user's account type, if missing defaults to individual.
A list. Each one: text. Default: objectClass. Name in the API: attrClass.
Description Attribute¶
LDAP attributes used to store the user's description.
A list. Each one: text. Default: description. Name in the API: attrDescription.
Primary E-mail Attribute¶
LDAP attribute for the user's primary email address.
A list. Each one: text. Default: mail. Name in the API: attrEmail.
E-mail Alias Attribute¶
LDAP attribute for the user's email alias(es)
A list. Each one: text. Default: mailAlias. Name in the API: attrEmailAlias.
Member Of Attribute¶
LDAP attributes for the groups that a user belongs to. Used when filterMemberOf is not configured or when the group membership is also provided in the account entry.
A list. Each one: text. Default: memberOf. Name in the API: attrMemberOf.
Password Attribute¶
LDAP attribute for the user's password hash. This setting is required when binding as a service user. When using bind authentication, configure the secret-changed attribute instead.
A list. Each one: text. Default: userPassword. Name in the API: attrSecret.
Password Changed Attribute¶
LDAP attribute that provides a password change hash or a timestamp indicating when the password was last changed. When using bind authentication, this attribute is used to determine when to invalidate OAuth tokens.
A list. Each one: text. Default: pwdChangeTime. Name in the API: attrSecretChanged.
Group Object Class¶
LDAP object class used to identify group entries.
Text. Default: groupOfNames. Name in the API: groupClass.
Pool¶
Max Connections¶
Maximum number of connections that can be maintained simultaneously in the connection pool.
A number. Default: 10. Name in the API: poolMaxConnections.
Create Timeout¶
Maximum amount of time that the connection pool will wait for a new connection to be created.
A length of time. Default: 30s. Name in the API: poolTimeoutCreate.
Recycle Timeout¶
Maximum amount of time that the connection pool manager will wait for a connection to be recycled.
A length of time. Default: 30s. Name in the API: poolTimeoutRecycle.
Wait Timeout¶
Maximum amount of time that the connection pool will wait for a connection to become available.
A length of time. Default: 30s. Name in the API: poolTimeoutWait.
Tenant¶
Identifier for the tenant this directory belongs to.
One of your Tenants, chosen from a list. Name in the API: memberTenantId.