30 lines
1.2 KiB
Plaintext
30 lines
1.2 KiB
Plaintext
# ============ LDAP connection ============
|
|
LDAP_URL=ldap://dc.school25.ru:389
|
|
LDAP_BASE_DN=DC=school25,DC=ru
|
|
# Domain used to build "user@domain" and "DOMAIN\user" bind names
|
|
LDAP_DOMAIN=school25.ru
|
|
|
|
# Optional OU filters for listing groups / OUs (empty = whole BaseDN subtree)
|
|
# LDAP_GROUP_OU=OU=Groups,DC=school25,DC=ru
|
|
|
|
# ============ Administrator account ============
|
|
# Account that has rights to create / modify / block users in AD.
|
|
# May be a sAMAccountName, a UPN (user@domain) or a full DN.
|
|
ADMIN_LOGIN=admin
|
|
# Passwords containing '#' (dotenv comment marker), spaces or other special chars
|
|
# must be wrapped in quotes, e.g. ADMIN_PASSWORD="my#pass"
|
|
ADMIN_PASSWORD=password
|
|
|
|
# ============ Server ============
|
|
PORT=8080
|
|
# Admin session lifetime in minutes
|
|
SESSION_TTL_MINUTES=120
|
|
|
|
# Use StartTLS on plain ldap:// connections (required by AD to set passwords).
|
|
# Set to false if the LDAP server refuses StartTLS (LDAP error 52) or LDAPS is unreachable.
|
|
ENCRYPT_TRAFFIC=false
|
|
|
|
# TLS settings for ldaps:// LDAP_URL connections (implicit TLS, no StartTLS needed).
|
|
# Leave reject-unauthorized=true in production if LDAP_CA_FILE points to your CA.
|
|
# LDAP_TLS_REJECT_UNAUTHORIZED=false
|
|
# LDAP_CA_FILE=./certs/dc-ca.crt |