self_service_password
71
Originally developed by "LTB-Project"
A PHP-based web-application (running on an Apache Webserver) that allows users to change their password in an LDAP directory. The application is developed by the LTB-Project (see http://ltb-project.org/wiki/documentation/self-service-password).
Configuration is performed automatically during each start-up to link to the appropriate LDAP- and/or Mail-Containers.
NOTE: On purpose, there is no secured channel (TLS/SSL) to the OpenLDAP-Server, because its service will never be exposed to the world.
The service provides the following network ports and filesystems!.
80 : Web-Server (unsecure)None
The created container is configured automatically by the entrypoint-script during each run.
During this each run the following environment variables are evaluated:
General Variables:
SERVER_HOSTNAME (default: ${HOSTNAME})
LDAP Self-Service-Password (optional):
LSSP_ATTR_LOGIN (default: uid)
LSSP_ATTR_FN (default: cn)
LSSP_ATTR_MAIL (default: mail)
LSSP_DEFAULT_ACTION (default: change)
change, sendtoken or sendsms)LSSP_MAIL_FROM_LDAP (default: false)
LSSP_SHOW_MENU (default: true)
OpenLDAP-Server (required):
LDAP_BASE (default: empty)
.) notation (i.e. domain.com)LDAP_HOST (default: empty)
LDAP_STARTTLS (default: true)
LDAP_USER (default: cn=admin,${LDAP_BASE})
LDAP_PASS
LDAP_AD_MODE (default: false)
Mail-Server (optional):
If
SMTP_HOSTis not set, Password-Reset via Mail-Tokens will be disabled in the Web-Interface! If eitherSMTP_USERorSMTP_PASSare empty, SMTP connects without user credentials!
SMTP_HOST (default: empty)
SMTP_PORT (default: 25)
SMTP_USER (default: empty)
SMTP_PASS (default: empty)
SMTP_FROM (default: root(at)${SERVER_HOSTNAME})
SMTP_TLS (default: true)
reCAPTCHA (optional):
RECAPTCHA_USE (default: false)
RECAPTCHA_PUB_KEY (default: empty)
RECAPTCHA_PRV_KEY (default: empty)
RECAPTCHA_SSL (default: false)
RECAPTCHA_THEME (default: white)
If you have a running OpenLDAP container of the following types
you can link those containers directly using the link-alias ldap which will provide the following environment variables automatically
LDAP_HOST (by Docker Environment)LDAP_PORT (by Docker Environment)LDAP_USERLDAP_PASSLDAP_BASEIf you have running Mail-Server inside a container, you can link such a container directly using the link-alias mail.
This will provide the following environment variables:
SMTP_HOST (by Docker Environment)SMTP_PORT (by Docker Environment)If you want to override configuration you can mount volume for /usr/share/self-service-password/conf/conf.d and put your conf.php in it.
Password policy
Put this file in local lssp.d directory:
ppolicy.php
<?php
$pwd_min_length = 4;
$pwd_max_length = 24;
$pwd_min_lower = 3;
$pwd_min_upper = 1;
$pwd_min_digit = 1;
$pwd_min_special = 1;
$pwd_special_chars = "^a-zA-Z0-9";
$pwd_complexity = 4;
$pwd_no_reuse = true;
$pwd_show_policy = "always";
?>
Then run your container with --volume ./lssp.d:/usr/share/self-service-password/conf/conf.d.
You can run a container without linked containers:
docker run -d -p 8080:80
-e LDAP_HOST=<ldap-server-hostname>
-e LDAP_PORT=389
-e LDAP_BASE=example.com
-e LDAP_USER=<admin-username>
-e LDAP_PASS=<admin-password>
-e SMTP_HOST=<mailserver-hostname>
[-e SMTP_PORT=25]
[-e SMTP_USER=<smtp-username>]
[-e SMTP_PASS=<smtp-password>]
[-e SMTP_TLS=on]
[[-h <hostname>] | [-e SERVER_HOSTNAME=<hostname>]]
dtwardow/ldap-self-service-password:<tag>
Or with linked LDAP and Mail-Containers
docker run -d -p 8080:80
--link <ldap-server-container>:ldap
--link <mail-server-container>:mail
[-e SMTP_USER=<smtp-username>]
[-e SMTP_PASS=<smtp-password>]
[-e SMTP_TLS=on]
[[-h <hostname>] | [-e SERVER_HOSTNAME=<hostname>]]
dtwardow/ldap-self-service-password:<tag>
The examples above expose service on port 8080, so you can point your browser to http://hostname:8765/ in order to change or reset LDAP passwords.
TBD
Content type
Image
Digest
Size
142 MB
Last updated
about 6 years ago
docker pull onemancrew/self_service_password:1.3.2