Sign inSign up

g0dscookie/ldapauthd

By g0dscookie

•Updated over 6 years ago

Simple HTTP ldap auth daemon

Image
0

2.4K

g0dscookie/ldapauthd repository overview

⁠ldapauthd

This is a simple HTTP server which allows you to authenticate against ldap with a HTTP GET request. This daemon is designed to run behind a reverse proxy (haproxy, nginx, apache2, ...).

⁠Usage

To authenticate against this daemon you only need to fire a GET request with base64 encoded Authentication HTTP header.

⁠Examples

⁠Curl

$ curl -v --user 'username:password' localhost

⁠Traefik
version: "3.7"
services:
  traefik:
    image: traefik
    network:
      - internal
    [...]
  auth:
    image: g0dscookie/ldapauthd
    network:
      - internal
    [...]
  backend:
    image: mybackend
    network:
      - internal
    deploy:
      labels:
        traefik.enable: "true"
        traefik.frontend.auth.forward.address: "http://auth"
        traefik.frontend.auth.forward.authResponseHeaders: "X-Forwarded-FullName,X-Forwarded-User,X-Forwarded-Email,X-Forwarded-Role"

⁠Installation

⁠Local

git clone https://github.com/g0dsCookie/ldapauthd.git
cd ldapauthd
pip install -r requirements.txt

Now you may run with ./ldapauthd.py but I highly recommend reading Configuration⁠.

⁠Docker

Docker image g0dscookie/ldapauthd is available. See docker-compose.yml for configuration and usage of this container.

⁠Configuration

Configuration for this daemon is read from the current environment. Available configuration parameters are:

Environment VariableDescriptionDefault
LDAPAUTHD_LOGLEVELLoglevel the daemon should run on.INFO
LDAPAUTHD_USERUser the daemon should be run with.nobody
LDAPAUTHD_UMASKUmask the daemon should run with.755
LDAPAUTHD_IPIP address the daemon should listen on.0.0.0.0
LDAPAUTHD_PORTPort the daemon should listen on.80
LDAPAUTHD_REALMString to set in WWW-AuthenticateAuthorization required
LDAP_LOGLEVELhttps://ldap3.readthedocs.io/logging.html#logging-detail-level⁠ERROR
LDAP_ATTRIBUTESAttributes to get from ldap and report to client{"cn": "X-Forwarded-FullName", "mail": "X-Forwarded-Email", "sAMAccountName": "X-Forwarded-User"}
LDAP_ALLOWEDUSERSAllow specific users. Will be matched with given username
LDAP_ALLOWEDGROUPSAllow specific groups. Will be matched with full group dn
LDAP_ROLEHEADERThe header name where the associated role should be stored
LDAP_BASEDNBase DN every search request will be based on.
LDAP_BINDDNBind user to use for querying your ldap server.
LDAP_BINDPWBind users password.
LDAP_BACKENDSComma seperated list of ldap backend names.
LDAP_<NAME>_HOSTHostname of your domain controller.
LDAP_<NAME>_PORTPort on your domain controller to connect to.636
LDAP_<NAME>_SSLUse SSL for ldap connection.True
LDAP_<NAME>_SSL_VALIDATEVerify remote SSL certificate.True

⁠Examples

⁠LDAP_ALLOWEDUSERS

Used to allow specific users and assign specific roles to them. Always overwrites LDAP_ALLOWEDGROUPS.

Users are matched case-insensitive.

LDAP_ALLOWEDUSERS={"username": "admin", "foobar": "nobody"}

⁠LDAP_ALLOWEDGROUPS

Used to allow groups and assign appropriate role to the user. May be overwritten by LDAP_ALLOWEDUSERS.

First matched group will be used to allow access and assign the role.

Groups are matched case-insensitive.

LDAP_ALLOWEDGROUPS={"cn=admins,dc=example,dc=org": "admin", "cn=domain users,dc=example,dc=org": "users"}

⁠Special Thanks

This is based on sepich/nginx-ldap⁠. I've used some code blocks of his script. Basically I've upgraded his script to python3 and changed the configuration process to use the environment instead of a plain text file.

Since version 0.2.0 most of the code base has changed due to the change of using ldap3 as ldap module.

Tag summary

Content type

Image

Digest

Size

33.6 MB

Last updated

over 6 years ago

docker pull g0dscookie/ldapauthd