Libris Translate 0.28.0 · User guide
Category: Manage Libris Translate
LDAP and Active Directory
Let people sign in with their directory account, while the directory stays the authority.
Steps
- Keep one local administrator who can sign in, then open Settings › Single sign-on and find the “LDAP / Active Directory directory” card.
- Choose the “Directory type”, OpenLDAP or Active Directory, and the “Directory address”: ldaps:// on port 636 by default, or ldap:// with “Encrypt with StartTLS (ldap:// only)”. Enter the “Service account DN”, its password and the “Search base”; change the “User filter” only if the default does not fit.
- Click “Test the directory” with a “Login to look up” before turning on “Turn on directory sign-in”. Fill in “Allowed groups” and “Administrator group” if the directory should decide who gets in and who administers.
- At first sign-in, Libris Translate finds the account by the directory’s stable identifier, never by a name or an address. To link an existing local account, use “Link to the directory” under Settings › Users.
What to know
Name, email and password come from the directory and are refreshed at each sign-in; Libris Translate keeps the role, the active state, the books and its own second factor, which a directory account still has to give. An empty password is refused before anything is sent. Certificate and host name verification can never be turned off, and plain ldap:// needs an explicit switch. Unknown login, ambiguous entry and wrong password all get the same answer. A directory cannot create more accounts than the licence allows, and account creation at first sign-in is off by default.
Fictional example
Test a fictional “jdoe” login and a read-only service account against a staging directory before ticking “Create accounts on first directory sign-in”.