73 lines
3.3 KiB
Plaintext
73 lines
3.3 KiB
Plaintext
# ============ LDAP connection ============
|
|
LDAP_URL=ldap://dc.school25.ru:389
|
|
LDAP_BASE_DN=DC=school25,DC=ru
|
|
# Domain used to build "user@domain" and "DOMAIN\user" bind names
|
|
LDAP_DOMAIN=school25.ru
|
|
|
|
# Optional OU filters for listing groups / OUs (empty = whole BaseDN subtree)
|
|
# LDAP_GROUP_OU=OU=Groups,DC=school25,DC=ru
|
|
|
|
# ============ Administrator account ============
|
|
# Account that has rights to create / modify / block users in AD.
|
|
# May be a sAMAccountName, a UPN (user@domain) or a full DN.
|
|
# NOTE: with LDAP_PASSWORD_METHOD=kerberos the account must be a
|
|
# sAMAccountName or UPN (a DN cannot be used as a Kerberos principal).
|
|
ADMIN_LOGIN=admin
|
|
# Passwords containing '#' (dotenv comment marker), spaces or other special chars
|
|
# must be wrapped in quotes, e.g. ADMIN_PASSWORD="my#pass"
|
|
ADMIN_PASSWORD=password
|
|
|
|
# ============ Server ============
|
|
PORT=8080
|
|
# Admin session lifetime in minutes
|
|
SESSION_TTL_MINUTES=120
|
|
|
|
# Use StartTLS on plain ldap:// connections (required by AD to set passwords).
|
|
# Set to false if the LDAP server refuses StartTLS (LDAP error 52) or LDAPS is unreachable.
|
|
ENCRYPT_TRAFFIC=false
|
|
|
|
# TLS settings for ldaps:// LDAP_URL connections (implicit TLS, no StartTLS needed).
|
|
# Leave reject-unauthorized=true in production if LDAP_CA_FILE points to your CA.
|
|
# LDAP_TLS_REJECT_UNAUTHORIZED=false
|
|
# LDAP_CA_FILE=./certs/dc-ca.crt
|
|
|
|
# ============ Password setting ============
|
|
# AD only allows setting unicodePwd over a protected channel (LDAPS / StartTLS /
|
|
# Kerberos signed+sealed connection). Without TLS the plain LDAP modify returns
|
|
# LDAP error 53.
|
|
#
|
|
# Password method (LDAP_PASSWORD_METHOD):
|
|
# kerberos - (default on Linux) kinit + ldapmodify -Y GSSAPI using the admin
|
|
# account; requires krb5/openldap-clients/cyrus-sasl-gssapiv2
|
|
# packages and /etc/krb5.conf. No TLS needed.
|
|
# powershell - (default on Windows) PowerShell/ADSI IADsUser.SetPassword on a
|
|
# domain-joined machine (Kerberos protected channel).
|
|
# ldap - plain unicodePwd LDAP modify; works only over LDAPS/StartTLS.
|
|
# LDAP_PASSWORD_METHOD=kerberos
|
|
# Kerberos realm (default: LDAP_DOMAIN in uppercase, e.g. SCHOOL25.RU)
|
|
# LDAP_REALM=SCHOOL25.RU
|
|
# Legacy switch kept for compatibility (implies LDAP_PASSWORD_METHOD=powershell):
|
|
# LDAP_USE_POWERSHELL_PASSWORD=true
|
|
# LDAP_POWERSHELL_EXE=powershell.exe
|
|
|
|
# ============ Kerberos (password setting) ============
|
|
# Additional domain controllers for the generated /etc/krb5.conf
|
|
# (comma-separated). Default: only the host from LDAP_URL is used,
|
|
# the rest is discovered via DNS SRV (_kerberos._tcp.<domain>).
|
|
LDAP_KDC_SERVERS=dc.school25.ru,dc3.school25.ru,srv.school25.ru
|
|
# Transient GSSAPI/KDC errors (e.g. "Server (ldap/...@REALM) unknown") are
|
|
# retried automatically. Number of attempts (default 3) and pause between them
|
|
# in milliseconds (default 1000). Applies to the kerberos password method.
|
|
# LDAP_PASSWORD_RETRIES=3
|
|
# LDAP_PASSWORD_RETRY_DELAY_MS=1000
|
|
|
|
# ============ Email (registration) ============
|
|
# SMTP server used to send verification codes and registration result letters.
|
|
# If EMAIL_HOST is empty the registration endpoints return 503.
|
|
# EMAIL_HOST=smtp.example.ru
|
|
# EMAIL_PORT=587
|
|
# EMAIL_SECURE=false
|
|
# EMAIL_LOGIN=mail@example.ru
|
|
# EMAIL_PASSWORD=password
|
|
# Optional "From" address, defaults to EMAIL_LOGIN
|
|
# MAIL_FROM=mail@example.ru |