mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 07:26:45 +00:00
Add docs for LDAP groups
This commit is contained in:
@@ -93,7 +93,14 @@ export const registerLdapRouter = async (server: FastifyZodProvider) => {
|
|||||||
const ldapClient = ldapjs.createClient({
|
const ldapClient = ldapjs.createClient({
|
||||||
url: ldapConfig.url,
|
url: ldapConfig.url,
|
||||||
bindDN: ldapConfig.bindDN,
|
bindDN: ldapConfig.bindDN,
|
||||||
bindCredentials: ldapConfig.bindPass
|
bindCredentials: ldapConfig.bindPass,
|
||||||
|
...(ldapConfig.caCert !== ""
|
||||||
|
? {
|
||||||
|
tlsOptions: {
|
||||||
|
ca: [ldapConfig.caCert]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
: {})
|
||||||
});
|
});
|
||||||
|
|
||||||
ldapClient.bind(ldapConfig.bindDN, ldapConfig.bindPass, (err) => {
|
ldapClient.bind(ldapConfig.bindDN, ldapConfig.bindPass, (err) => {
|
||||||
@@ -109,7 +116,6 @@ export const registerLdapRouter = async (server: FastifyZodProvider) => {
|
|||||||
|
|
||||||
searchGroups(ldapClient, searchFilter, ldapConfig.groupSearchBase)
|
searchGroups(ldapClient, searchFilter, ldapConfig.groupSearchBase)
|
||||||
.then((groups) => {
|
.then((groups) => {
|
||||||
// groups here
|
|
||||||
ldapClient.unbind();
|
ldapClient.unbind();
|
||||||
return server.services.ldap.ldapLogin({
|
return server.services.ldap.ldapLogin({
|
||||||
ldapConfigId: ldapConfig.id,
|
ldapConfigId: ldapConfig.id,
|
||||||
|
|||||||
@@ -22,10 +22,6 @@ const addAcceptedUsersToGroup = async ({
|
|||||||
projectBotDAL,
|
projectBotDAL,
|
||||||
tx
|
tx
|
||||||
}: TAddUsersToGroup) => {
|
}: TAddUsersToGroup) => {
|
||||||
console.log("addAcceptedUsersToGroup args: ", {
|
|
||||||
userIds,
|
|
||||||
group
|
|
||||||
});
|
|
||||||
const users = await userDAL.findUserEncKeyByUserIdsBatch(
|
const users = await userDAL.findUserEncKeyByUserIdsBatch(
|
||||||
{
|
{
|
||||||
userIds
|
userIds
|
||||||
|
|||||||
@@ -3,6 +3,8 @@ import jwt from "jsonwebtoken";
|
|||||||
|
|
||||||
import { OrgMembershipRole, OrgMembershipStatus, SecretKeyEncoding, TLdapConfigsUpdate } from "@app/db/schemas";
|
import { OrgMembershipRole, OrgMembershipStatus, SecretKeyEncoding, TLdapConfigsUpdate } from "@app/db/schemas";
|
||||||
import { TGroupDALFactory } from "@app/ee/services/group/group-dal";
|
import { TGroupDALFactory } from "@app/ee/services/group/group-dal";
|
||||||
|
import { addUsersToGroupByUserIds, removeUsersFromGroupByUserIds } from "@app/ee/services/group/group-fns";
|
||||||
|
import { TUserGroupMembershipDALFactory } from "@app/ee/services/group/user-group-membership-dal";
|
||||||
import { getConfig } from "@app/lib/config/env";
|
import { getConfig } from "@app/lib/config/env";
|
||||||
import {
|
import {
|
||||||
decryptSymmetric,
|
decryptSymmetric,
|
||||||
@@ -14,8 +16,12 @@ import {
|
|||||||
} from "@app/lib/crypto/encryption";
|
} from "@app/lib/crypto/encryption";
|
||||||
import { BadRequestError } from "@app/lib/errors";
|
import { BadRequestError } from "@app/lib/errors";
|
||||||
import { AuthMethod, AuthTokenType } from "@app/services/auth/auth-type";
|
import { AuthMethod, AuthTokenType } from "@app/services/auth/auth-type";
|
||||||
|
import { TGroupProjectDALFactory } from "@app/services/group-project/group-project-dal";
|
||||||
import { TOrgBotDALFactory } from "@app/services/org/org-bot-dal";
|
import { TOrgBotDALFactory } from "@app/services/org/org-bot-dal";
|
||||||
import { TOrgDALFactory } from "@app/services/org/org-dal";
|
import { TOrgDALFactory } from "@app/services/org/org-dal";
|
||||||
|
import { TProjectDALFactory } from "@app/services/project/project-dal";
|
||||||
|
import { TProjectBotDALFactory } from "@app/services/project-bot/project-bot-dal";
|
||||||
|
import { TProjectKeyDALFactory } from "@app/services/project-key/project-key-dal";
|
||||||
import { TUserDALFactory } from "@app/services/user/user-dal";
|
import { TUserDALFactory } from "@app/services/user/user-dal";
|
||||||
import { normalizeUsername } from "@app/services/user/user-fns";
|
import { normalizeUsername } from "@app/services/user/user-fns";
|
||||||
import { TUserAliasDALFactory } from "@app/services/user-alias/user-alias-dal";
|
import { TUserAliasDALFactory } from "@app/services/user-alias/user-alias-dal";
|
||||||
@@ -43,8 +49,19 @@ type TLdapConfigServiceFactoryDep = {
|
|||||||
"createMembership" | "updateMembershipById" | "findMembership" | "findOrgById" | "findOne" | "updateById"
|
"createMembership" | "updateMembershipById" | "findMembership" | "findOrgById" | "findOne" | "updateById"
|
||||||
>;
|
>;
|
||||||
orgBotDAL: Pick<TOrgBotDALFactory, "findOne" | "create" | "transaction">;
|
orgBotDAL: Pick<TOrgBotDALFactory, "findOne" | "create" | "transaction">;
|
||||||
groupDAL: TGroupDALFactory; // TODO: Pick
|
groupDAL: Pick<TGroupDALFactory, "find" | "findOne">;
|
||||||
userDAL: Pick<TUserDALFactory, "create" | "findOne" | "transaction" | "updateById">;
|
groupProjectDAL: Pick<TGroupProjectDALFactory, "find">;
|
||||||
|
projectKeyDAL: Pick<TProjectKeyDALFactory, "find" | "findLatestProjectKey" | "insertMany" | "delete">;
|
||||||
|
projectDAL: Pick<TProjectDALFactory, "findProjectGhostUser">;
|
||||||
|
projectBotDAL: Pick<TProjectBotDALFactory, "findOne">;
|
||||||
|
userGroupMembershipDAL: Pick<
|
||||||
|
TUserGroupMembershipDALFactory,
|
||||||
|
"find" | "transaction" | "insertMany" | "filterProjectsByUserMembership" | "delete"
|
||||||
|
>;
|
||||||
|
userDAL: Pick<
|
||||||
|
TUserDALFactory,
|
||||||
|
"create" | "findOne" | "transaction" | "updateById" | "findUserEncKeyByUserIdsBatch" | "find"
|
||||||
|
>;
|
||||||
userAliasDAL: Pick<TUserAliasDALFactory, "create" | "findOne">;
|
userAliasDAL: Pick<TUserAliasDALFactory, "create" | "findOne">;
|
||||||
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
||||||
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
||||||
@@ -58,6 +75,11 @@ export const ldapConfigServiceFactory = ({
|
|||||||
orgDAL,
|
orgDAL,
|
||||||
orgBotDAL,
|
orgBotDAL,
|
||||||
groupDAL,
|
groupDAL,
|
||||||
|
groupProjectDAL,
|
||||||
|
projectKeyDAL,
|
||||||
|
projectDAL,
|
||||||
|
projectBotDAL,
|
||||||
|
userGroupMembershipDAL,
|
||||||
userDAL,
|
userDAL,
|
||||||
userAliasDAL,
|
userAliasDAL,
|
||||||
permissionService,
|
permissionService,
|
||||||
@@ -345,7 +367,7 @@ export const ldapConfigServiceFactory = ({
|
|||||||
};
|
};
|
||||||
|
|
||||||
const ldapLogin = async ({
|
const ldapLogin = async ({
|
||||||
// ldapConfigId,
|
ldapConfigId,
|
||||||
externalId,
|
externalId,
|
||||||
username,
|
username,
|
||||||
firstName,
|
firstName,
|
||||||
@@ -431,26 +453,75 @@ export const ldapConfigServiceFactory = ({
|
|||||||
const user = await userDAL.findOne({ id: userAlias.userId });
|
const user = await userDAL.findOne({ id: userAlias.userId });
|
||||||
|
|
||||||
if (groups) {
|
if (groups) {
|
||||||
// TODO
|
const ldapGroupIdsToBePartOf = (
|
||||||
// const m = await ldapGroupMapDAL.find({
|
await ldapGroupMapDAL.find({
|
||||||
// ldapConfigId,
|
ldapConfigId,
|
||||||
// $in: {
|
$in: {
|
||||||
// ldapGroupCN: groups.map((group) => group.cn)
|
ldapGroupCN: groups.map((group) => group.cn)
|
||||||
// }
|
}
|
||||||
// });
|
})
|
||||||
/**
|
).map((groupMap) => groupMap.groupId);
|
||||||
* TODO:
|
|
||||||
* - Find relevant group maps
|
const groupsToBePartOf = await groupDAL.find({
|
||||||
* - Query for groups matching name
|
orgId,
|
||||||
* - Provision, de-provision user to groups accordingly
|
$in: {
|
||||||
*/
|
id: ldapGroupIdsToBePartOf
|
||||||
// console.log("there are groups");
|
}
|
||||||
// const matchingGroups = await groupDAL.find({
|
});
|
||||||
// $in: {
|
const toBePartOfGroupIdsSet = new Set(groupsToBePartOf.map((groupToBePartOf) => groupToBePartOf.id));
|
||||||
// name: groups.map((group) => group.cn)
|
|
||||||
// }
|
const allLdapGroupMaps = await ldapGroupMapDAL.find({
|
||||||
// });
|
ldapConfigId
|
||||||
// console.log("found matching groups");
|
});
|
||||||
|
|
||||||
|
const ldapGroupIdsCurrentlyPartOf = (
|
||||||
|
await userGroupMembershipDAL.find({
|
||||||
|
userId: user.id,
|
||||||
|
$in: {
|
||||||
|
groupId: allLdapGroupMaps.map((groupMap) => groupMap.groupId)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
).map((userGroupMembership) => userGroupMembership.groupId);
|
||||||
|
|
||||||
|
const userGroupMembershipGroupIdsSet = new Set(ldapGroupIdsCurrentlyPartOf);
|
||||||
|
|
||||||
|
for await (const group of groupsToBePartOf) {
|
||||||
|
if (!userGroupMembershipGroupIdsSet.has(group.id)) {
|
||||||
|
// add user to group that they should be part of
|
||||||
|
await addUsersToGroupByUserIds({
|
||||||
|
group,
|
||||||
|
userIds: [user.id],
|
||||||
|
userDAL,
|
||||||
|
userGroupMembershipDAL,
|
||||||
|
orgDAL,
|
||||||
|
groupProjectDAL,
|
||||||
|
projectKeyDAL,
|
||||||
|
projectDAL,
|
||||||
|
projectBotDAL
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const groupsCurrentlyPartOf = await groupDAL.find({
|
||||||
|
orgId,
|
||||||
|
$in: {
|
||||||
|
id: ldapGroupIdsCurrentlyPartOf
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
for await (const group of groupsCurrentlyPartOf) {
|
||||||
|
if (!toBePartOfGroupIdsSet.has(group.id)) {
|
||||||
|
// remove user from group that they should no longer be part of
|
||||||
|
await removeUsersFromGroupByUserIds({
|
||||||
|
group,
|
||||||
|
userIds: [user.id],
|
||||||
|
userDAL,
|
||||||
|
userGroupMembershipDAL,
|
||||||
|
groupProjectDAL,
|
||||||
|
projectKeyDAL
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
const isUserCompleted = Boolean(user.isAccepted);
|
const isUserCompleted = Boolean(user.isAccepted);
|
||||||
|
|||||||
@@ -306,6 +306,11 @@ export const registerRoutes = async (
|
|||||||
orgDAL,
|
orgDAL,
|
||||||
orgBotDAL,
|
orgBotDAL,
|
||||||
groupDAL,
|
groupDAL,
|
||||||
|
groupProjectDAL,
|
||||||
|
projectKeyDAL,
|
||||||
|
projectDAL,
|
||||||
|
projectBotDAL,
|
||||||
|
userGroupMembershipDAL,
|
||||||
userDAL,
|
userDAL,
|
||||||
userAliasDAL,
|
userAliasDAL,
|
||||||
permissionService,
|
permissionService,
|
||||||
|
|||||||
@@ -1,36 +0,0 @@
|
|||||||
---
|
|
||||||
title: "LDAP"
|
|
||||||
description: "Log in to Infisical with LDAP"
|
|
||||||
---
|
|
||||||
|
|
||||||
<Info>
|
|
||||||
LDAP is a paid feature.
|
|
||||||
|
|
||||||
If you're using Infisical Cloud, then it is available under the **Enterprise Tier**. If you're self-hosting Infisical,
|
|
||||||
then you should contact [email protected] to purchase an enterprise license to use it.
|
|
||||||
</Info>
|
|
||||||
|
|
||||||
You can configure your organization in Infisical to have members authenticate with the platform via [LDAP](https://en.wikipedia.org/wiki/Lightweight_Directory_Access_Protocol).
|
|
||||||
|
|
||||||
<Steps>
|
|
||||||
<Step title="Prepare the LDAP configuration in Infisical">
|
|
||||||
In Infisical, head to your Organization Settings > Authentication > LDAP Configuration and select **Set up LDAP**.
|
|
||||||
|
|
||||||
Next, input your LDAP server settings.
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
Here's some guidance for each field:
|
|
||||||
|
|
||||||
- URL: The LDAP server to connect to such as `ldap://ldap.your-org.com`, `ldaps://ldap.myorg.com:636` (for connection over SSL/TLS), etc.
|
|
||||||
- Bind DN: The distinguished name of object to bind when performing the user search such as `cn=infisical,ou=Users,dc=acme,dc=com`.
|
|
||||||
- Bind Pass: The password to use along with `Bind DN` when performing the user search.
|
|
||||||
- Search Base / User DN: Base DN under which to perform user search such as `ou=Users,dc=example,dc=com`
|
|
||||||
- CA Certificate: The CA certificate to use when verifying the LDAP server certificate.
|
|
||||||
</Step>
|
|
||||||
<Step title="Enable LDAP in Infisical">
|
|
||||||
Enabling LDAP allows members in your organization to log into Infisical via LDAP.
|
|
||||||
|
|
||||||

|
|
||||||
</Step>
|
|
||||||
</Steps>
|
|
||||||
@@ -4,16 +4,17 @@ description: "Learn how to log in to Infisical with LDAP."
|
|||||||
---
|
---
|
||||||
|
|
||||||
<Info>
|
<Info>
|
||||||
LDAP is a paid feature.
|
LDAP is a paid feature. If you're using Infisical Cloud, then it is available
|
||||||
If you're using Infisical Cloud, then it is available under the **Enterprise Tier**. If you're self-hosting Infisical,
|
under the **Enterprise Tier**. If you're self-hosting Infisical, then you
|
||||||
then you should contact [email protected] to purchase an enterprise license to use it.
|
should contact [email protected] to purchase an enterprise license to use
|
||||||
|
it.
|
||||||
</Info>
|
</Info>
|
||||||
|
|
||||||
You can configure your organization in Infisical to have members authenticate with the platform via [LDAP](https://en.wikipedia.org/wiki/Lightweight_Directory_Access_Protocol)
|
You can configure your organization in Infisical to have members authenticate with the platform via [LDAP](https://en.wikipedia.org/wiki/Lightweight_Directory_Access_Protocol)
|
||||||
|
|
||||||
<Steps>
|
<Steps>
|
||||||
<Step title="Prepare the LDAP configuration in Infisical">
|
<Step title="Prepare the LDAP configuration in Infisical">
|
||||||
In Infisical, head to your Organization Settings > Authentication > LDAP Configuration and select **Set up LDAP**.
|
In Infisical, head to your Organization Settings > Security > LDAP and select **Manage**.
|
||||||
|
|
||||||
Next, input your LDAP server settings.
|
Next, input your LDAP server settings.
|
||||||
|
|
||||||
@@ -24,11 +25,41 @@ You can configure your organization in Infisical to have members authenticate wi
|
|||||||
- URL: The LDAP server to connect to such as `ldap://ldap.your-org.com`, `ldaps://ldap.myorg.com:636` (for connection over SSL/TLS), etc.
|
- URL: The LDAP server to connect to such as `ldap://ldap.your-org.com`, `ldaps://ldap.myorg.com:636` (for connection over SSL/TLS), etc.
|
||||||
- Bind DN: The distinguished name of object to bind when performing the user search such as `cn=infisical,ou=Users,dc=acme,dc=com`.
|
- Bind DN: The distinguished name of object to bind when performing the user search such as `cn=infisical,ou=Users,dc=acme,dc=com`.
|
||||||
- Bind Pass: The password to use along with `Bind DN` when performing the user search.
|
- Bind Pass: The password to use along with `Bind DN` when performing the user search.
|
||||||
- Search Base / User DN: Base DN under which to perform user search such as `ou=Users,dc=example,dc=com`
|
- Search Base / User DN: Base DN under which to perform user search such as `ou=Users,dc=acme,dc=com`
|
||||||
|
- Group Search Base / Group DN (optional): LDAP search base to use for group membership search such as `ou=Groups,dc=acme,dc=com`.
|
||||||
|
- Group Filter (optional): Template used when constructing the group membership query such as `(objectClass=posixGroup)`. The template can access the following context variables: [`UserDN`, `UserUID`, `UserName`]. The default is `(|(memberUid={{.Username}})(member={{.UserDN}})(uniqueMember={{.UserDN}}))` which is compatible with several common directory schemas.
|
||||||
- CA Certificate: The CA certificate to use when verifying the LDAP server certificate.
|
- CA Certificate: The CA certificate to use when verifying the LDAP server certificate.
|
||||||
|
|
||||||
|
<Note>
|
||||||
|
The **Group Search Base / Group DN** and **Group Filter** fields are both required if you wish to sync LDAP groups to Infisical.
|
||||||
|
</Note>
|
||||||
|
|
||||||
|
</Step>
|
||||||
|
<Step title="Define mappings from LDAP groups to groups in Infisical">
|
||||||
|
In order to sync LDAP groups to Infisical, head to the **LDAP Group Mappings** section to define mappings from LDAP groups to groups in Infisical.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Group mappings ensure that users who log into Infisical via LDAP are added to or removed from the Infisical group(s) that corresponds to the LDAP group(s) they are a member of.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Each group mapping consists of two parts:
|
||||||
|
- LDAP Group CN: The common name of the LDAP group to map.
|
||||||
|
- Infisical Group: The Infisical group to map the LDAP group to.
|
||||||
|
|
||||||
|
For example, suppose you want to automatically add a user who is part of the LDAP group with CN `Engineers` to the Infisical group `Engineers` when the user sets up their account with Infisical.
|
||||||
|
|
||||||
|
In this case, you would specify a mapping from the LDAP group with CN `Engineers` to the Infisical group `Engineers`.
|
||||||
|
Now when the user logs into Infisical via LDAP, Infisical will check the LDAP groups that the user is a part of whilst referencing the group mappings you created earlier. Since the user is a member of the LDAP group with CN `Engineers`, they will be added to the Infisical group `Engineers`.
|
||||||
|
In the future, if the user is no longer part of the LDAP group with CN `Engineers`, they will be removed from the Infisical group `Engineers` upon their next login.
|
||||||
|
<Note>
|
||||||
|
Prior to defining any group mappings, ensure that you've created the Infisical groups that you want to map the LDAP groups to.
|
||||||
|
You can read more about creating (user) groups in Infisical [here](/documentation/platform/groups).
|
||||||
|
</Note>
|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Enable LDAP in Infisical">
|
<Step title="Enable LDAP in Infisical">
|
||||||
Enabling LDAP allows members in your organization to log into Infisical via LDAP.
|
Enabling LDAP allows members in your organization to log into Infisical via LDAP.
|
||||||

|

|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|||||||
@@ -4,9 +4,10 @@ description: "Learn how to configure JumpCloud LDAP for authenticating into Infi
|
|||||||
---
|
---
|
||||||
|
|
||||||
<Info>
|
<Info>
|
||||||
LDAP is a paid feature.
|
LDAP is a paid feature. If you're using Infisical Cloud, then it is available
|
||||||
If you're using Infisical Cloud, then it is available under the **Enterprise Tier**. If you're self-hosting Infisical,
|
under the **Enterprise Tier**. If you're self-hosting Infisical, then you
|
||||||
then you should contact [email protected] to purchase an enterprise license to use it.
|
should contact [email protected] to purchase an enterprise license to use
|
||||||
|
it.
|
||||||
</Info>
|
</Info>
|
||||||
|
|
||||||
<Steps>
|
<Steps>
|
||||||
@@ -17,13 +18,13 @@ description: "Learn how to configure JumpCloud LDAP for authenticating into Infi
|
|||||||
When creating the user, input their **First Name**, **Last Name**, **Username** (required), **Company Email** (required), and **Description**.
|
When creating the user, input their **First Name**, **Last Name**, **Username** (required), **Company Email** (required), and **Description**.
|
||||||
Also, create a password for the user.
|
Also, create a password for the user.
|
||||||
|
|
||||||
Next, under User Security Settings and Permissions > Permission Settings, check the box next to **Enable as LDAP Bind DN**.
|
Next, under User Security Settings and Permissions > Permission Settings, check the box next to **Enable as LDAP Bind DN**.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Prepare the LDAP configuration in Infisical">
|
<Step title="Prepare the LDAP configuration in Infisical">
|
||||||
In Infisical, head to your Organization Settings > Authentication > LDAP Configuration and select **Set up LDAP**.
|
In Infisical, head to your Organization Settings > Security > LDAP and select **Manage**.
|
||||||
|
|
||||||
Next, input your JumpCloud LDAP server settings.
|
Next, input your JumpCloud LDAP server settings.
|
||||||
|
|
||||||
@@ -35,20 +36,48 @@ description: "Learn how to configure JumpCloud LDAP for authenticating into Infi
|
|||||||
- Bind DN: The distinguished name of object to bind when performing the user search (`uid=<ldap-user-username>,ou=Users,o=<your-org-id>,dc=jumpcloud,dc=com`).
|
- Bind DN: The distinguished name of object to bind when performing the user search (`uid=<ldap-user-username>,ou=Users,o=<your-org-id>,dc=jumpcloud,dc=com`).
|
||||||
- Bind Pass: The password to use along with `Bind DN` when performing the user search.
|
- Bind Pass: The password to use along with `Bind DN` when performing the user search.
|
||||||
- Search Base / User DN: Base DN under which to perform user search (`ou=Users,o=<your-org-id>,dc=jumpcloud,dc=com`).
|
- Search Base / User DN: Base DN under which to perform user search (`ou=Users,o=<your-org-id>,dc=jumpcloud,dc=com`).
|
||||||
|
- Group Search Base / Group DN (optional): LDAP search base to use for group membership search (`ou=Users,o=<your-org-id>,dc=jumpcloud,dc=com`).
|
||||||
|
- Group Filter (optional): Template used when constructing the group membership query (`(objectClass=groupOfNames)`).
|
||||||
- CA Certificate: The CA certificate to use when verifying the LDAP server certificate (instructions to obtain the certificate for JumpCloud [here](https://jumpcloud.com/support/connect-to-ldap-with-tls-ssl)).
|
- CA Certificate: The CA certificate to use when verifying the LDAP server certificate (instructions to obtain the certificate for JumpCloud [here](https://jumpcloud.com/support/connect-to-ldap-with-tls-ssl)).
|
||||||
|
|
||||||
<Tip>
|
<Tip>
|
||||||
When filling out the **Bind DN** and **Bind Pass** fields, refer to the username and password of the user created in Step 1.
|
When filling out the **Bind DN** and **Bind Pass** fields, refer to the username and password of the user created in Step 1.
|
||||||
|
|
||||||
Also, for the **Bind DN** and **Search Base / User DN** fields, you'll want to use the organization ID that appears
|
Also, for the **Bind DN** and **Search Base / User DN** fields, you'll want to use the organization ID that appears
|
||||||
in your LDAP instance **ORG DN**.
|
in your LDAP instance **ORG DN**.
|
||||||
</Tip>
|
</Tip>
|
||||||
</Step>
|
</Step>
|
||||||
|
<Step title="Define mappings from LDAP groups to groups in Infisical">
|
||||||
|
In order to sync LDAP groups to Infisical, head to the **LDAP Group Mappings** section to define mappings from LDAP groups to groups in Infisical.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Group mappings ensure that users who log into Infisical via LDAP are added to or removed from the Infisical group(s) that corresponds to the LDAP group(s) they are a member of.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Each group mapping consists of two parts:
|
||||||
|
- LDAP Group CN: The common name of the LDAP group to map.
|
||||||
|
- Infisical Group: The Infisical group to map the LDAP group to.
|
||||||
|
|
||||||
|
For example, suppose you want to automatically add a user who is part of the LDAP group with CN `Engineers` to the Infisical group `Engineers` when the user sets up their account with Infisical.
|
||||||
|
|
||||||
|
In this case, you would specify a mapping from the LDAP group with CN `Engineers` to the Infisical group `Engineers`.
|
||||||
|
Now when the user logs into Infisical via LDAP, Infisical will check the LDAP groups that the user is a part of whilst referencing the group mappings you created earlier. Since the user is a member of the LDAP group with CN `Engineers`, they will be added to the Infisical group `Engineers`.
|
||||||
|
In the future, if the user is no longer part of the LDAP group with CN `Engineers`, they will be removed from the Infisical group `Engineers` upon their next login.
|
||||||
|
<Note>
|
||||||
|
Prior to defining any group mappings, ensure that you've created the Infisical groups that you want to map the LDAP groups to.
|
||||||
|
You can read more about creating (user) groups in Infisical [here](/documentation/platform/groups).
|
||||||
|
</Note>
|
||||||
|
|
||||||
|
</Step>
|
||||||
<Step title="Enable LDAP in Infisical">
|
<Step title="Enable LDAP in Infisical">
|
||||||
Enabling LDAP allows members in your organization to log into Infisical via LDAP.
|
Enabling LDAP allows members in your organization to log into Infisical via LDAP.
|
||||||

|

|
||||||
</Step>
|
</Step>
|
||||||
|
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|
||||||
Resources:
|
Resources:
|
||||||
- [JumpCloud Cloud LDAP Guide](https://jumpcloud.com/support/use-cloud-ldap)
|
|
||||||
|
- [JumpCloud Cloud LDAP Guide](https://jumpcloud.com/support/use-cloud-ldap)
|
||||||
|
|||||||
Binary file not shown.
|
Before Width: | Height: | Size: 427 KiB After Width: | Height: | Size: 439 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 721 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 456 KiB |
Binary file not shown.
|
Before Width: | Height: | Size: 537 KiB After Width: | Height: | Size: 599 KiB |
+3
-2
@@ -23,7 +23,8 @@ import {
|
|||||||
Td,
|
Td,
|
||||||
Th,
|
Th,
|
||||||
THead,
|
THead,
|
||||||
Tr} from "@app/components/v2";
|
Tr
|
||||||
|
} from "@app/components/v2";
|
||||||
import { useOrganization } from "@app/context";
|
import { useOrganization } from "@app/context";
|
||||||
import {
|
import {
|
||||||
useCreateLDAPGroupMapping,
|
useCreateLDAPGroupMapping,
|
||||||
@@ -193,7 +194,7 @@ export const LDAPGroupMapModal = ({ popUp, handlePopUpOpen, handlePopUpToggle }:
|
|||||||
<THead>
|
<THead>
|
||||||
<Tr>
|
<Tr>
|
||||||
<Th>LDAP Group CN</Th>
|
<Th>LDAP Group CN</Th>
|
||||||
<Th>Group Slug</Th>
|
<Th>Infisical Group</Th>
|
||||||
<Th className="w-5" />
|
<Th className="w-5" />
|
||||||
</Tr>
|
</Tr>
|
||||||
</THead>
|
</THead>
|
||||||
|
|||||||
Reference in New Issue
Block a user