Libris Translate 0.28.0 · User guide

Category: Manage Libris Translate

LDAP and Active Directory

Let people sign in with their directory account, while the directory stays the authority.

Steps

  1. Keep one local administrator who can sign in, then open Settings › Single sign-on and find the “LDAP / Active Directory directory” card.
  2. Choose the “Directory type”, OpenLDAP or Active Directory, and the “Directory address”: ldaps:// on port 636 by default, or ldap:// with “Encrypt with StartTLS (ldap:// only)”. Enter the “Service account DN”, its password and the “Search base”; change the “User filter” only if the default does not fit.
  3. Click “Test the directory” with a “Login to look up” before turning on “Turn on directory sign-in”. Fill in “Allowed groups” and “Administrator group” if the directory should decide who gets in and who administers.
  4. At first sign-in, Libris Translate finds the account by the directory’s stable identifier, never by a name or an address. To link an existing local account, use “Link to the directory” under Settings › Users.

What to know

Name, email and password come from the directory and are refreshed at each sign-in; Libris Translate keeps the role, the active state, the books and its own second factor, which a directory account still has to give. An empty password is refused before anything is sent. Certificate and host name verification can never be turned off, and plain ldap:// needs an explicit switch. Unknown login, ambiguous entry and wrong password all get the same answer. A directory cannot create more accounts than the licence allows, and account creation at first sign-in is off by default.

Fictional example

Test a fictional “jdoe” login and a read-only service account against a staging directory before ticking “Create accounts on first directory sign-in”.

Continue