Files
ldap-auth-service/.env.example
2026-08-27 11:43:56 +05:00

73 lines
3.3 KiB
Plaintext

# ============ LDAP connection ============
LDAP_URL=ldap://dc.school25.ru:389
LDAP_BASE_DN=DC=school25,DC=ru
# Domain used to build "user@domain" and "DOMAIN\user" bind names
LDAP_DOMAIN=school25.ru
# Optional OU filters for listing groups / OUs (empty = whole BaseDN subtree)
# LDAP_GROUP_OU=OU=Groups,DC=school25,DC=ru
# ============ Administrator account ============
# Account that has rights to create / modify / block users in AD.
# May be a sAMAccountName, a UPN (user@domain) or a full DN.
# NOTE: with LDAP_PASSWORD_METHOD=kerberos the account must be a
# sAMAccountName or UPN (a DN cannot be used as a Kerberos principal).
ADMIN_LOGIN=admin
# Passwords containing '#' (dotenv comment marker), spaces or other special chars
# must be wrapped in quotes, e.g. ADMIN_PASSWORD="my#pass"
ADMIN_PASSWORD=password
# ============ Server ============
PORT=8080
# Admin session lifetime in minutes
SESSION_TTL_MINUTES=120
# Use StartTLS on plain ldap:// connections (required by AD to set passwords).
# Set to false if the LDAP server refuses StartTLS (LDAP error 52) or LDAPS is unreachable.
ENCRYPT_TRAFFIC=false
# TLS settings for ldaps:// LDAP_URL connections (implicit TLS, no StartTLS needed).
# Leave reject-unauthorized=true in production if LDAP_CA_FILE points to your CA.
# LDAP_TLS_REJECT_UNAUTHORIZED=false
# LDAP_CA_FILE=./certs/dc-ca.crt
# ============ Password setting ============
# AD only allows setting unicodePwd over a protected channel (LDAPS / StartTLS /
# Kerberos signed+sealed connection). Without TLS the plain LDAP modify returns
# LDAP error 53.
#
# Password method (LDAP_PASSWORD_METHOD):
# kerberos - (default on Linux) kinit + ldapmodify -Y GSSAPI using the admin
# account; requires krb5/openldap-clients/cyrus-sasl-gssapiv2
# packages and /etc/krb5.conf. No TLS needed.
# powershell - (default on Windows) PowerShell/ADSI IADsUser.SetPassword on a
# domain-joined machine (Kerberos protected channel).
# ldap - plain unicodePwd LDAP modify; works only over LDAPS/StartTLS.
# LDAP_PASSWORD_METHOD=kerberos
# Kerberos realm (default: LDAP_DOMAIN in uppercase, e.g. SCHOOL25.RU)
# LDAP_REALM=SCHOOL25.RU
# Legacy switch kept for compatibility (implies LDAP_PASSWORD_METHOD=powershell):
# LDAP_USE_POWERSHELL_PASSWORD=true
# LDAP_POWERSHELL_EXE=powershell.exe
# ============ Kerberos (password setting) ============
# Additional domain controllers for the generated /etc/krb5.conf
# (comma-separated). Default: only the host from LDAP_URL is used,
# the rest is discovered via DNS SRV (_kerberos._tcp.<domain>).
LDAP_KDC_SERVERS=dc.school25.ru,dc3.school25.ru,srv.school25.ru
# Transient GSSAPI/KDC errors (e.g. "Server (ldap/...@REALM) unknown") are
# retried automatically. Number of attempts (default 3) and pause between them
# in milliseconds (default 1000). Applies to the kerberos password method.
# LDAP_PASSWORD_RETRIES=3
# LDAP_PASSWORD_RETRY_DELAY_MS=1000
# ============ Email (registration) ============
# SMTP server used to send verification codes and registration result letters.
# If EMAIL_HOST is empty the registration endpoints return 503.
# EMAIL_HOST=smtp.example.ru
# EMAIL_PORT=587
# EMAIL_SECURE=false
# EMAIL_LOGIN=mail@example.ru
# EMAIL_PASSWORD=password
# Optional "From" address, defaults to EMAIL_LOGIN
# MAIL_FROM=mail@example.ru