LDAP / Active Directory login
Admins can also sign in with corporate LDAP. The first login creates an
AdminUser (no local password) with the Case Manager role; an
admin promotes it if needed. TOTP enrollment still follows, as for
every account.
- Accounts with a local password, such as the one the setup wizard created, keep signing in with it.
- A directory user whose name a local account already has is refused, never merged into it.
- The username comes from
LDAP_ATTR_USERNAME. An entry without it is refused.
LDAP uses python-ldap (the OpenLDAP client) and S3 storage uses boto3: optional extras,
both in the container image. From source, install libldap2-dev libsasl2-dev,
then pip install '.[ldap,s3]'.
| Variable | Description |
|---|---|
LDAP_ENABLED Optional |
Set to true to allow admin login via LDAP/AD. Default: false |
LDAP_SERVER Optional |
Hostname or IP of the LDAP server (e.g. ldap.example.com). |
LDAP_PORT Optional |
LDAP port. Use 389 with LDAP_START_TLS or 636 for LDAPS. Plain 389 without either sends passwords in clear. Default: 389 |
LDAP_USE_SSL Optional |
Set to true to use LDAPS (TLS from the start). Set port to 636. The server certificate is verified against the system CA store; for a private CA, mount its PEM file and set LDAPTLS_CACERT to its path. Default: false |
LDAP_START_TLS Optional |
Set to true to upgrade a plain connection on port 389 with StartTLS before any bind, so neither the service account's nor the user's password crosses the network in clear. The certificate is verified exactly as for LDAPS; a server that refuses the upgrade makes the login fail. Ignored when LDAP_USE_SSL=true. Default: false |
LDAP_BIND_DN Optional |
Distinguished name of the service account used to search the directory (e.g. cn=svc-openwhistle,ou=service,dc=example,dc=com). |
LDAP_BIND_PASSWORD Optional |
Password for the service account bind DN. |
LDAP_BASE_DN Optional |
Search base for user lookups (e.g. ou=users,dc=example,dc=com). |
LDAP_USER_FILTER Optional |
LDAP search filter to locate a user entry. {username} is replaced with the entered username at runtime. Default: (uid={username}) |
LDAP_ATTR_USERNAME Optional |
LDAP attribute to use as the username in the provisioned admin record. Default: uid |
LDAP_ATTR_EMAIL Optional |
LDAP attribute to read the user's email address from. Default: mail |