Files
ldap-auth-service/.env.example
2026-08-20 12:33:17 +05:00

30 lines
1.2 KiB
Plaintext

# ============ LDAP connection ============
LDAP_URL=ldap://dc.school25.ru:389
LDAP_BASE_DN=DC=school25,DC=ru
# Domain used to build "user@domain" and "DOMAIN\user" bind names
LDAP_DOMAIN=school25.ru
# Optional OU filters for listing groups / OUs (empty = whole BaseDN subtree)
# LDAP_GROUP_OU=OU=Groups,DC=school25,DC=ru
# ============ Administrator account ============
# Account that has rights to create / modify / block users in AD.
# May be a sAMAccountName, a UPN (user@domain) or a full DN.
ADMIN_LOGIN=admin
# Passwords containing '#' (dotenv comment marker), spaces or other special chars
# must be wrapped in quotes, e.g. ADMIN_PASSWORD="my#pass"
ADMIN_PASSWORD=password
# ============ Server ============
PORT=8080
# Admin session lifetime in minutes
SESSION_TTL_MINUTES=120
# Use StartTLS on plain ldap:// connections (required by AD to set passwords).
# Set to false if the LDAP server refuses StartTLS (LDAP error 52) or LDAPS is unreachable.
ENCRYPT_TRAFFIC=false
# TLS settings for ldaps:// LDAP_URL connections (implicit TLS, no StartTLS needed).
# Leave reject-unauthorized=true in production if LDAP_CA_FILE points to your CA.
# LDAP_TLS_REJECT_UNAUTHORIZED=false
# LDAP_CA_FILE=./certs/dc-ca.crt