Sitelet https://github.com/simplesamlphp/simplesamlphp/commit/36ff0b12c7a91c5b3af464bf0a2955ec760a0e8f
Skip to content

Commit 36ff0b1

Browse files
committed
Update ldap-authsource config examples
1 parent e885480 commit 36ff0b1

1 file changed

Lines changed: 153 additions & 107 deletions

File tree

‎config/authsources.php.dist‎

Lines changed: 153 additions & 107 deletions
Original file line numberDiff line numberDiff line change
@@ -194,143 +194,189 @@ $config = [
194194
/*
195195
// Example of a LDAP authentication source.
196196
'example-ldap' => [
197-
'ldap:LDAP',
197+
'ldap:Ldap',
198198

199-
// Give the user an option to save their username for future login attempts
200-
// And when enabled, what should the default be, to save the username or not
201-
//'remember.username.enabled' => false,
202-
//'remember.username.checked' => false,
203-
204-
// The hostname of the LDAP server.
205-
'hostname' => 'ldap.example.org',
199+
/**
200+
* The connection string for the LDAP-server.
201+
* You can add multiple by separating them with a space.
202+
*/
203+
'connection_string' => 'ldap.example.org',
206204

207-
// Whether SSL/TLS should be used when contacting the LDAP server.
208-
'enable_tls' => true,
205+
/**
206+
* Whether SSL/TLS should be used when contacting the LDAP server.
207+
* Possible values are 'ssl', 'tls' or 'none'
208+
*/
209+
'encryption' => 'ssl',
209210

210-
// Whether debug output from the LDAP library should be enabled.
211-
// Default is FALSE.
212-
'debug' => false,
211+
/**
212+
* The LDAP version to use when interfacing the LDAP-server.
213+
* Defaults to 3
214+
*/
215+
'version' => 3,
213216

214-
// The timeout for accessing the LDAP server, in seconds.
215-
// The default is 0, which means no timeout.
216-
'timeout' => 0,
217+
/**
218+
* Set to TRUE to enable LDAP debug level. Passed to the LDAP connector class.
219+
*
220+
* Default: FALSE
221+
* Required: No
222+
*/
223+
'ldap.debug' => false,
217224

218-
// The port used when accessing the LDAP server.
219-
// The default is 389.
220-
'port' => 389,
225+
/**
226+
* The LDAP-options to pass when setting up a connection
227+
* See [Symfony documentation][1]
228+
*/
229+
'options' => [
230+
/**
231+
* Set whether to follow referrals.
232+
* AD Controllers may require 0x00 to function.
233+
* Possible values are 0x00 (NEVER), 0x01 (SEARCHING),
234+
* 0x02 (FINDING) or 0x03 (ALWAYS).
235+
*/
236+
'referrals' => 0x00,
237+
238+
'network_timeout' => 3,
239+
],
221240

222-
// Set whether to follow referrals. AD Controllers may require FALSE to function.
223-
'referrals' => true,
241+
/**
242+
* The connector to use.
243+
* Defaults to '\SimpleSAML\Module\ldap\Connector\Ldap', but can be set
244+
* to '\SimpleSAML\Module\ldap\Connector\ActiveDirectory' when
245+
* authenticating against Microsoft Active Directory. This will
246+
* provide you with more specific error messages.
247+
*/
248+
'connector' => '\SimpleSAML\Module\ldap\Connector\Ldap',
224249

225-
// Which attributes should be retrieved from the LDAP server.
226-
// This can be an array of attribute names, or NULL, in which case
227-
// all attributes are fetched.
250+
/**
251+
* Which attributes should be retrieved from the LDAP server.
252+
* This can be an array of attribute names, or NULL, in which case
253+
* all attributes are fetched.
254+
*/
228255
'attributes' => null,
229256

230-
// The pattern which should be used to create the users DN given the username.
231-
// %username% in this pattern will be replaced with the users username.
232-
//
233-
// This option is not used if the search.enable option is set to TRUE.
257+
/**
258+
* Which attributes should be base64 encoded after retrieval from
259+
* the LDAP server.
260+
*/
261+
'attributes.binary' => [
262+
'jpegPhoto',
263+
'objectGUID',
264+
'objectSid',
265+
'mS-DS-ConsistencyGuid'
266+
],
267+
268+
/**
269+
* The pattern which should be used to create the user's DN given
270+
* the username. %username% in this pattern will be replaced with
271+
* the user's username.
272+
*
273+
* This option is not used if the search.enable option is set to TRUE.
274+
*/
234275
'dnpattern' => 'uid=%username%,ou=people,dc=example,dc=org',
235276

236-
// As an alternative to specifying a pattern for the users DN, it is possible to
237-
// search for the username in a set of attributes. This is enabled by this option.
277+
/**
278+
* As an alternative to specifying a pattern for the users DN, it is
279+
* possible to search for the username in a set of attributes. This is
280+
* enabled by this option.
281+
*/
238282
'search.enable' => false,
239283

240-
// The DN which will be used as a base for the search.
241-
// This can be a single string, in which case only that DN is searched, or an
242-
// array of strings, in which case they will be searched in the order given.
243-
'search.base' => 'ou=people,dc=example,dc=org',
284+
/**
285+
* An array on DNs which will be used as a base for the search. In
286+
* case of multiple strings, they will be searched in the order given.
287+
*/
288+
'search.base' => [
289+
'ou=people,dc=example,dc=org',
290+
],
291+
292+
/**
293+
* The scope of the search. Valid values are 'sub' and 'one' and
294+
* 'base', first one being the default if no value is set.
295+
*/
296+
'search.scope' => 'sub',
244297

245-
// The attribute(s) the username should match against.
246-
//
247-
// This is an array with one or more attribute names. Any of the attributes in
248-
// the array may match the value the username.
298+
/**
299+
* The attribute(s) the username should match against.
300+
*
301+
* This is an array with one or more attribute names. Any of the
302+
* attributes in the array may match the value the username.
303+
*/
249304
'search.attributes' => ['uid', 'mail'],
250305

251-
// Additional LDAP filters appended to the search attributes
252-
//'search.filter' => '(objectclass=inetorgperson)',
306+
/**
307+
* Additional filters that must match for the entire LDAP search to
308+
* be true.
309+
*
310+
* This should be a single string conforming to [RFC 1960][2]
311+
* and [RFC 2544][3]. The string is appended to the search attributes
312+
*/
313+
'search.filter' => '(&(objectClass=Person)(|(sn=Doe)(cn=John *)))',
253314

254-
// The username & password the SimpleSAMLphp should bind to before searching. If
255-
// this is left as NULL, no bind will be performed before searching.
315+
/**
316+
* The username & password where SimpleSAMLphp should bind to before
317+
* searching. If this is left NULL, no bind will be performed before
318+
* searching.
319+
*/
256320
'search.username' => null,
257321
'search.password' => null,
258-
259-
// If the directory uses privilege separation,
260-
// the authenticated user may not be able to retrieve
261-
// all required attributes, a privileged entity is required
262-
// to get them. This is enabled with this option.
263-
'priv.read' => false,
264-
265-
// The DN & password the SimpleSAMLphp should bind to before
266-
// retrieving attributes. These options are required if
267-
// 'priv.read' is set to TRUE.
268-
'priv.username' => null,
269-
'priv.password' => null,
270-
271322
],
272323
*/
273324

274325
/*
275326
// Example of an LDAPMulti authentication source.
276327
'example-ldapmulti' => [
277-
'ldap:LDAPMulti',
328+
'ldap:LdapMulti',
278329

279-
// Give the user an option to save their username for future login attempts
280-
// And when enabled, what should the default be, to save the username or not
281-
//'remember.username.enabled' => false,
282-
//'remember.username.checked' => false,
283-
284-
// Give the user an option to save their organization choice for future login
285-
// attempts. And when enabled, what should the default be, checked or not.
286-
//'remember.organization.enabled' => false,
287-
//'remember.organization.checked' => false,
288-
289-
// The way the organization as part of the username should be handled.
290-
// Three possible values:
291-
// - 'none': No handling of the organization. Allows '@' to be part
292-
// of the username.
293-
// - 'allow': Will allow users to type 'username@organization'.
294-
// - 'force': Force users to type 'username@organization'. The dropdown
295-
// list will be hidden.
296-
//
297-
// The default is 'none'.
330+
/*
331+
* The way the organization as part of the username should be handled.
332+
* Three possible values:
333+
* - 'none': No handling of the organization. Allows '@' to be part
334+
* of the username.
335+
* - 'allow': Will allow users to type 'username@organization'.
336+
* - 'force': Force users to type 'username@organization'. The dropdown
337+
* list will be hidden.
338+
*
339+
* The default is 'none'.
340+
*/
298341
'username_organization_method' => 'none',
299342

300-
// Whether the organization should be included as part of the username
301-
// when authenticating. If this is set to TRUE, the username will be on
302-
// the form <username>@<organization identifier>. If this is FALSE, the
303-
// username will be used as the user enters it.
304-
//
305-
// The default is FALSE.
343+
/*
344+
* Whether the organization should be included as part of the username
345+
* when authenticating. If this is set to TRUE, the username will be on
346+
* the form <username>@<organization identifier>. If this is FALSE, the
347+
* username will be used as the user enters it.
348+
*
349+
* The default is FALSE.
350+
*/
306351
'include_organization_in_username' => false,
307352

308-
// A list of available LDAP servers.
309-
//
310-
// The index is an identifier for the organization/group. When
311-
// 'username_organization_method' is set to something other than 'none',
312-
// the organization-part of the username is matched against the index.
313-
//
314-
// The value of each element is an array in the same format as an LDAP
315-
// authentication source.
316-
'employees' => [
317-
// A short name/description for this group. Will be shown in a dropdown list
318-
// when the user logs on.
319-
//
320-
// This option can be a string or an array with language => text mappings.
321-
'description' => 'Employees',
322-
323-
// The rest of the options are the same as those available for
324-
// the LDAP authentication source.
325-
'hostname' => 'ldap.employees.example.org',
326-
'dnpattern' => 'uid=%username%,ou=employees,dc=example,dc=org',
327-
],
328-
329-
'students' => [
330-
'description' => 'Students',
331-
332-
'hostname' => 'ldap.students.example.org',
333-
'dnpattern' => 'uid=%username%,ou=students,dc=example,dc=org',
353+
/*
354+
* A list of available LDAP servers.
355+
*
356+
* The index is an identifier for the organization/group. When
357+
* 'username_organization_method' is set to something other than 'none',
358+
* the organization-part of the username is matched against the index.
359+
*
360+
* The value of each element is an array in the same format as an LDAP
361+
* authentication source.
362+
*/
363+
'mapping' => [
364+
'employees' => [
365+
/**
366+
* A short name/description for this group. Will be shown in a
367+
* dropdown list when the user logs on.
368+
*
369+
* This option can be a string or an array with
370+
* language => text mappings.
371+
*/
372+
'description' => 'Employees',
373+
'authsource' => ''example-ldap,
374+
],
375+
376+
'students' => [
377+
'description' => 'Students',
378+
'authsource' => 'example-ldap-2',
379+
],
334380
],
335381
],
336382
*/

0 commit comments

Comments
 (0)