This is a simple HTTP server which allows you to authenticate against ldap with a HTTP GET request. This daemon is designed to run behind a reverse proxy (haproxy, nginx, apache2, ...).
To authenticate against this daemon you only need to fire a GET request with base64 encoded Authentication HTTP header.
$ curl -v --user 'username:password' localhost
version: "3.7"
services:
traefik:
image: traefik
network:
- internal
[...]
auth:
image: g0dscookie/ldapauthd
network:
- internal
[...]
backend:
image: mybackend
network:
- internal
deploy:
labels:
traefik.enable: "true"
traefik.frontend.auth.forward.address: "http://auth"
traefik.frontend.auth.forward.authResponseHeaders: "X-Forwarded-FullName,X-Forwarded-User,X-Forwarded-Email,X-Forwarded-Role"
git clone https://github.com/g0dsCookie/ldapauthd.git
cd ldapauthd
pip install -r requirements.txt
Now you may run with ./ldapauthd.py but I highly recommend reading Configuration.
Docker image g0dscookie/ldapauthd is available. See docker-compose.yml for configuration and usage of this container.
Configuration for this daemon is read from the current environment. Available configuration parameters are:
| Environment Variable | Description | Default |
|---|---|---|
| LDAPAUTHD_LOGLEVEL | Loglevel the daemon should run on. | INFO |
| LDAPAUTHD_USER | User the daemon should be run with. | nobody |
| LDAPAUTHD_UMASK | Umask the daemon should run with. | 755 |
| LDAPAUTHD_IP | IP address the daemon should listen on. | 0.0.0.0 |
| LDAPAUTHD_PORT | Port the daemon should listen on. | 80 |
| LDAPAUTHD_REALM | String to set in WWW-Authenticate | Authorization required |
| LDAP_LOGLEVEL | https://ldap3.readthedocs.io/logging.html#logging-detail-level | ERROR |
| LDAP_ATTRIBUTES | Attributes to get from ldap and report to client | {"cn": "X-Forwarded-FullName", "mail": "X-Forwarded-Email", "sAMAccountName": "X-Forwarded-User"} |
| LDAP_ALLOWEDUSERS | Allow specific users. Will be matched with given username | |
| LDAP_ALLOWEDGROUPS | Allow specific groups. Will be matched with full group dn | |
| LDAP_ROLEHEADER | The header name where the associated role should be stored | |
| LDAP_BASEDN | Base DN every search request will be based on. | |
| LDAP_BINDDN | Bind user to use for querying your ldap server. | |
| LDAP_BINDPW | Bind users password. | |
| LDAP_BACKENDS | Comma seperated list of ldap backend names. | |
| LDAP_<NAME>_HOST | Hostname of your domain controller. | |
| LDAP_<NAME>_PORT | Port on your domain controller to connect to. | 636 |
| LDAP_<NAME>_SSL | Use SSL for ldap connection. | True |
| LDAP_<NAME>_SSL_VALIDATE | Verify remote SSL certificate. | True |
Used to allow specific users and assign specific roles to them. Always overwrites LDAP_ALLOWEDGROUPS.
Users are matched case-insensitive.
LDAP_ALLOWEDUSERS={"username": "admin", "foobar": "nobody"}
Used to allow groups and assign appropriate role to the user. May be overwritten by LDAP_ALLOWEDUSERS.
First matched group will be used to allow access and assign the role.
Groups are matched case-insensitive.
LDAP_ALLOWEDGROUPS={"cn=admins,dc=example,dc=org": "admin", "cn=domain users,dc=example,dc=org": "users"}
This is based on sepich/nginx-ldap. I've used some code blocks of his script. Basically I've upgraded his script to python3 and changed the configuration process to use the environment instead of a plain text file.
Since version 0.2.0 most of the code base has changed due to the change of using ldap3 as ldap module.
Content type
Image
Digest
Size
33.6 MB
Last updated
over 6 years ago
docker pull g0dscookie/ldapauthd