LDAPサーバー
Casdoor can act as a simple LDAP server for systems (e.g. Nexus) that use LDAP for authentication. It supports bind and search with Simple Authentication.
ポート
LDAPサーバーはデフォルトでポート389でリッスンしています。 Change it via ldapServerPort in conf/app.conf.
Behavior
- User entries follow the posixAccount style.
- Bind: The server parses
cn(username) andou(organization).dcis ignored. It verifies the user with Casdoor and grants access for subsequent operations. - Search: The server checks that the client has permission (from the bind) and returns results accordingly.
Only Simple Authentication is supported.
Bind
Use a DN in this form: cn=<username>,ou=<organization>,dc=example,dc=com.
Example: cn=admin,ou=built-in,dc=example,dc=com. Set the admin’s DN to this format, then bind with that DN and the user’s password. On success, the client is authorized for search.
検索
After a successful bind:
- One user (e.g. Alice in
built-in): Base DNou=built-in,dc=example,dc=com, filtercn=Alice. - All users in an org (e.g.
built-in): Base DNou=built-in,dc=example,dc=com, filtercn=*. - All users in all orgs (if permitted): Base DN
ou=*,dc=example,dc=com, filtercn=*. - Users in a group: Use a filter such as
(memberOf=organization_name/group_name).
User attributes
| Attribute | 説明 | Source |
|---|---|---|
cn | Common name | User name |
uid | User ID | User id |
homeDirectory | Home directory | /home/{username} |
mail | メールアドレス | User email |
モバイル | 電話 | User phone |
sn | Surname | User last name |
givenName | Given name | User first name |
memberOf | グループ - ツールチップ | User’s groups |
loginShell | Login shell | user.Properties["loginShell"], defaults to /bin/bash |
gecos | GECOS (full name) | user.DisplayName, falls back to user.Name |
sshPublicKey | SSH public key | user.Properties["sshPublicKey"], omitted if empty |
All entries also carry objectClass: posixAccount, which is required by PAM and NSS for Linux authentication.
Linux machine login
Casdoor’s LDAP server exposes posixAccount-compatible entries, so Linux hosts can authenticate users directly against Casdoor via standard tools such as sssd, nss-ldap, or pam_ldap.
To configure per-user values for loginShell and sshPublicKey, set them in the user’s Properties field (key-value map):
{
"loginShell": "/bin/zsh",
"sshPublicKey": "ssh-ed25519 AAAA..."
}
If loginShell is not set, /bin/bash is used. If sshPublicKey is absent, the attribute is omitted from the LDAP entry entirely.