@@ -194,143 +194,189 @@ $config = [
194194 /*
195195 // Example of a LDAP authentication source.
196196 'example-ldap' => [
197- 'ldap:LDAP ',
197+ 'ldap:Ldap ',
198198
199- // Give the user an option to save their username for future login attempts
200- // And when enabled, what should the default be, to save the username or not
201- //'remember.username.enabled' => false,
202- //'remember.username.checked' => false,
203-
204- // The hostname of the LDAP server.
205- 'hostname' => 'ldap.example.org',
199+ /**
200+ * The connection string for the LDAP-server.
201+ * You can add multiple by separating them with a space.
202+ */
203+ 'connection_string' => 'ldap.example.org',
206204
207- // Whether SSL/TLS should be used when contacting the LDAP server.
208- 'enable_tls' => true,
205+ /**
206+ * Whether SSL/TLS should be used when contacting the LDAP server.
207+ * Possible values are 'ssl', 'tls' or 'none'
208+ */
209+ 'encryption' => 'ssl',
209210
210- // Whether debug output from the LDAP library should be enabled.
211- // Default is FALSE.
212- 'debug' => false,
211+ /**
212+ * The LDAP version to use when interfacing the LDAP-server.
213+ * Defaults to 3
214+ */
215+ 'version' => 3,
213216
214- // The timeout for accessing the LDAP server, in seconds.
215- // The default is 0, which means no timeout.
216- 'timeout' => 0,
217+ /**
218+ * Set to TRUE to enable LDAP debug level. Passed to the LDAP connector class.
219+ *
220+ * Default: FALSE
221+ * Required: No
222+ */
223+ 'ldap.debug' => false,
217224
218- // The port used when accessing the LDAP server.
219- // The default is 389.
220- 'port' => 389,
225+ /**
226+ * The LDAP-options to pass when setting up a connection
227+ * See [Symfony documentation][1]
228+ */
229+ 'options' => [
230+ /**
231+ * Set whether to follow referrals.
232+ * AD Controllers may require 0x00 to function.
233+ * Possible values are 0x00 (NEVER), 0x01 (SEARCHING),
234+ * 0x02 (FINDING) or 0x03 (ALWAYS).
235+ */
236+ 'referrals' => 0x00,
237+
238+ 'network_timeout' => 3,
239+ ],
221240
222- // Set whether to follow referrals. AD Controllers may require FALSE to function.
223- 'referrals' => true,
241+ /**
242+ * The connector to use.
243+ * Defaults to '\SimpleSAML\Module\ldap\Connector\Ldap', but can be set
244+ * to '\SimpleSAML\Module\ldap\Connector\ActiveDirectory' when
245+ * authenticating against Microsoft Active Directory. This will
246+ * provide you with more specific error messages.
247+ */
248+ 'connector' => '\SimpleSAML\Module\ldap\Connector\Ldap',
224249
225- // Which attributes should be retrieved from the LDAP server.
226- // This can be an array of attribute names, or NULL, in which case
227- // all attributes are fetched.
250+ /**
251+ * Which attributes should be retrieved from the LDAP server.
252+ * This can be an array of attribute names, or NULL, in which case
253+ * all attributes are fetched.
254+ */
228255 'attributes' => null,
229256
230- // The pattern which should be used to create the users DN given the username.
231- // %username% in this pattern will be replaced with the users username.
232- //
233- // This option is not used if the search.enable option is set to TRUE.
257+ /**
258+ * Which attributes should be base64 encoded after retrieval from
259+ * the LDAP server.
260+ */
261+ 'attributes.binary' => [
262+ 'jpegPhoto',
263+ 'objectGUID',
264+ 'objectSid',
265+ 'mS-DS-ConsistencyGuid'
266+ ],
267+
268+ /**
269+ * The pattern which should be used to create the user's DN given
270+ * the username. %username% in this pattern will be replaced with
271+ * the user's username.
272+ *
273+ * This option is not used if the search.enable option is set to TRUE.
274+ */
234275 'dnpattern' => 'uid=%username%,ou=people,dc=example,dc=org',
235276
236- // As an alternative to specifying a pattern for the users DN, it is possible to
237- // search for the username in a set of attributes. This is enabled by this option.
277+ /**
278+ * As an alternative to specifying a pattern for the users DN, it is
279+ * possible to search for the username in a set of attributes. This is
280+ * enabled by this option.
281+ */
238282 'search.enable' => false,
239283
240- // The DN which will be used as a base for the search.
241- // This can be a single string, in which case only that DN is searched, or an
242- // array of strings, in which case they will be searched in the order given.
243- 'search.base' => 'ou=people,dc=example,dc=org',
284+ /**
285+ * An array on DNs which will be used as a base for the search. In
286+ * case of multiple strings, they will be searched in the order given.
287+ */
288+ 'search.base' => [
289+ 'ou=people,dc=example,dc=org',
290+ ],
291+
292+ /**
293+ * The scope of the search. Valid values are 'sub' and 'one' and
294+ * 'base', first one being the default if no value is set.
295+ */
296+ 'search.scope' => 'sub',
244297
245- // The attribute(s) the username should match against.
246- //
247- // This is an array with one or more attribute names. Any of the attributes in
248- // the array may match the value the username.
298+ /**
299+ * The attribute(s) the username should match against.
300+ *
301+ * This is an array with one or more attribute names. Any of the
302+ * attributes in the array may match the value the username.
303+ */
249304 'search.attributes' => ['uid', 'mail'],
250305
251- // Additional LDAP filters appended to the search attributes
252- //'search.filter' => '(objectclass=inetorgperson)',
306+ /**
307+ * Additional filters that must match for the entire LDAP search to
308+ * be true.
309+ *
310+ * This should be a single string conforming to [RFC 1960][2]
311+ * and [RFC 2544][3]. The string is appended to the search attributes
312+ */
313+ 'search.filter' => '(&(objectClass=Person)(|(sn=Doe)(cn=John *)))',
253314
254- // The username & password the SimpleSAMLphp should bind to before searching. If
255- // this is left as NULL, no bind will be performed before searching.
315+ /**
316+ * The username & password where SimpleSAMLphp should bind to before
317+ * searching. If this is left NULL, no bind will be performed before
318+ * searching.
319+ */
256320 'search.username' => null,
257321 'search.password' => null,
258-
259- // If the directory uses privilege separation,
260- // the authenticated user may not be able to retrieve
261- // all required attributes, a privileged entity is required
262- // to get them. This is enabled with this option.
263- 'priv.read' => false,
264-
265- // The DN & password the SimpleSAMLphp should bind to before
266- // retrieving attributes. These options are required if
267- // 'priv.read' is set to TRUE.
268- 'priv.username' => null,
269- 'priv.password' => null,
270-
271322 ],
272323 */
273324
274325 /*
275326 // Example of an LDAPMulti authentication source.
276327 'example-ldapmulti' => [
277- 'ldap:LDAPMulti ',
328+ 'ldap:LdapMulti ',
278329
279- // Give the user an option to save their username for future login attempts
280- // And when enabled, what should the default be, to save the username or not
281- //'remember.username.enabled' => false,
282- //'remember.username.checked' => false,
283-
284- // Give the user an option to save their organization choice for future login
285- // attempts. And when enabled, what should the default be, checked or not.
286- //'remember.organization.enabled' => false,
287- //'remember.organization.checked' => false,
288-
289- // The way the organization as part of the username should be handled.
290- // Three possible values:
291- // - 'none': No handling of the organization. Allows '@' to be part
292- // of the username.
293- // - 'allow': Will allow users to type 'username@organization'.
294- // - 'force': Force users to type 'username@organization'. The dropdown
295- // list will be hidden.
296- //
297- // The default is 'none'.
330+ /*
331+ * The way the organization as part of the username should be handled.
332+ * Three possible values:
333+ * - 'none': No handling of the organization. Allows '@' to be part
334+ * of the username.
335+ * - 'allow': Will allow users to type 'username@organization'.
336+ * - 'force': Force users to type 'username@organization'. The dropdown
337+ * list will be hidden.
338+ *
339+ * The default is 'none'.
340+ */
298341 'username_organization_method' => 'none',
299342
300- // Whether the organization should be included as part of the username
301- // when authenticating. If this is set to TRUE, the username will be on
302- // the form <username>@<organization identifier>. If this is FALSE, the
303- // username will be used as the user enters it.
304- //
305- // The default is FALSE.
343+ /*
344+ * Whether the organization should be included as part of the username
345+ * when authenticating. If this is set to TRUE, the username will be on
346+ * the form <username>@<organization identifier>. If this is FALSE, the
347+ * username will be used as the user enters it.
348+ *
349+ * The default is FALSE.
350+ */
306351 'include_organization_in_username' => false,
307352
308- // A list of available LDAP servers.
309- //
310- // The index is an identifier for the organization/group. When
311- // 'username_organization_method' is set to something other than 'none',
312- // the organization-part of the username is matched against the index.
313- //
314- // The value of each element is an array in the same format as an LDAP
315- // authentication source.
316- 'employees' => [
317- // A short name/description for this group. Will be shown in a dropdown list
318- // when the user logs on.
319- //
320- // This option can be a string or an array with language => text mappings.
321- 'description' => 'Employees',
322-
323- // The rest of the options are the same as those available for
324- // the LDAP authentication source.
325- 'hostname' => 'ldap.employees.example.org',
326- 'dnpattern' => 'uid=%username%,ou=employees,dc=example,dc=org',
327- ],
328-
329- 'students' => [
330- 'description' => 'Students',
331-
332- 'hostname' => 'ldap.students.example.org',
333- 'dnpattern' => 'uid=%username%,ou=students,dc=example,dc=org',
353+ /*
354+ * A list of available LDAP servers.
355+ *
356+ * The index is an identifier for the organization/group. When
357+ * 'username_organization_method' is set to something other than 'none',
358+ * the organization-part of the username is matched against the index.
359+ *
360+ * The value of each element is an array in the same format as an LDAP
361+ * authentication source.
362+ */
363+ 'mapping' => [
364+ 'employees' => [
365+ /**
366+ * A short name/description for this group. Will be shown in a
367+ * dropdown list when the user logs on.
368+ *
369+ * This option can be a string or an array with
370+ * language => text mappings.
371+ */
372+ 'description' => 'Employees',
373+ 'authsource' => ''example-ldap,
374+ ],
375+
376+ 'students' => [
377+ 'description' => 'Students',
378+ 'authsource' => 'example-ldap-2',
379+ ],
334380 ],
335381 ],
336382 */
0 commit comments