Sovite.SASL.Backend.LDAP (sovite v0.2.0)

Copy Markdown View Source

A Sovite.SASL.Backend that checks passwords by binding to an LDAP directory as the user.

The user's entry is found with a search (as a service account, or anonymously), then the server is asked to bind as that entry with the given password. Alternatively :dn_template builds the DN directly and skips the search.

Only PLAIN and LOGIN work: the password must be sent to the directory, so SCRAM-SHA-256 is not possible.

An empty password is always refused: LDAP treats a bind with one as an anonymous bind, which would succeed (RFC 4513 §5.1.2).

Options

The connection options of Sovite.LDAP.connect/1 (:servers, :port, :security, :tls_options), and:

  • :base - search base DN. Required unless :dn_template is given.
  • :filter - an RFC 4515 filter (Sovite.LDAP.Filter) with placeholders: %u the whole user name, %n the part before the last @, %d the part after it. Defaults to "(mail=%u)".
  • :dn_template - a DN with the same placeholders, such as "uid=%n,ou=people,dc=example,dc=com". Values are escaped (RFC 4514).
  • :bind_dn / :bind_password - service account for the search. Anonymous if not given.
  • :timeout - milliseconds for the whole check. Defaults to 10 seconds.