https://github.com/pinepain/ldap-auth-proxy
A simple drop-in HTTP proxy for transparent LDAP authentication which is also a HTTP auth backend.
https://github.com/pinepain/ldap-auth-proxy
ingress-nginx ldap ldap-auth proxy
Last synced: over 1 year ago
JSON representation
A simple drop-in HTTP proxy for transparent LDAP authentication which is also a HTTP auth backend.
- Host: GitHub
- URL: https://github.com/pinepain/ldap-auth-proxy
- Owner: pinepain
- License: mit
- Created: 2018-03-29T21:49:39.000Z (over 8 years ago)
- Default Branch: master
- Last Pushed: 2020-07-29T12:25:13.000Z (almost 6 years ago)
- Last Synced: 2024-06-18T23:01:48.319Z (about 2 years ago)
- Topics: ingress-nginx, ldap, ldap-auth, proxy
- Language: Go
- Homepage:
- Size: 1.07 MB
- Stars: 74
- Watchers: 3
- Forks: 16
- Open Issues: 5
-
Metadata Files:
- Readme: README.md
- License: LICENSE
Awesome Lists containing this project
README
# LDAP Auth proxy
[](https://travis-ci.org/pinepain/ldap-auth-proxy)
[](https://goreportcard.com/report/github.com/pinepain/ldap-auth-proxy)
A simple drop-in HTTP proxy for transparent LDAP authorization which is also a HTTP auth backend.
## Usage
You can use `pinepain/ldap-auth-proxy` docker image (see available tags [here](https://hub.docker.com/r/pinepain/ldap-auth-proxy/tags/))
or build binary by yourself, `Dockerfile` and `.travis.yml` list all necessary steps to build it.
Usage examples could be found in [examples](./examples) folder.
## Architecture
LDAP auth proxy could be used in two modes: as an auth backend and as a proxy:
### Auth backend

Examples:
- Kubernetes `ingress-nginx` setup could be found in [examples/k8s-ingress-nginx](./examples/k8s-ingress-nginx).
- `docker-compose` setup could be found in [examples/auth_backend](./examples/auth_backend).
### Proxy

and it's variation, proxy behind nginx:

Example `docker-compose` setup could be found in [examples/proxy](./examples/proxy)
## Example settings for JumpCloud users:
export LDAP_SERVER='ldaps://ldap.jumpcloud.com'
export LDAP_BASE='o=,dc=jumpcloud,dc=com'
export LDAP_BIND_DN='uid=,ou=Users,o=,dc=jumpcloud,dc=com'
export LDAP_BIND_PASSWORD=''
export LDAP_USER_FILTER='(uid=%s)'
export LDAP_GROUP_FILTER='(&(objectClass=groupOfNames)(member=uid=%s,ou=Users,o=,dc=jumpcloud,dc=com))'
export GROUP_HEADER='X-Ldap-Group'
export HEADERS_MAP='X-LDAP-Mail:mail,X-LDAP-UID:uid,X-LDAP-CN:cn,X-LDAP-DN:dn'
where `` is your organisation id.
## Notes
A zero length password is always considered invalid since it is, according to the LDAP spec, a request for
"unauthenticated authentication." Unauthenticated authentication should not be used for LDAP based authentication.
See `section 5.1.2 of RFC-4513 `_ for a description of this behavior.
Neither zero length username supported. Anonymous authentication should also not be used for LDAP based authentication.
See `section 5.1.1 of RFC-4513 `_ for a description of that behavior.
## License
[ldap-auth-proxy](https://github.com/pinepain/ldap-auth-proxy) is licensed under the [MIT license](http://opensource.org/licenses/MIT).