Symas employee?Sign in

← Knowledge Base

Reference

Using OpenLDAP with Authentik

Authentik is an open-source, self-hosted Identity Provider (IdP) and Single Sign-On (SSO) platform designed to secure, manage, and authenticate users across applications. It functions as a flexible alternative to solutions like Okta or Azure AD, supporting protocols such as OAuth2, SAML, LDAP, and SCIM. Key features include multi-factor authentication (MFA), user lifecycle management, and a proxy for securing non-native apps. 

Use the following configuration settings. Make sure you replace “dc=example,dc=com” with the root DN for your OpenLDAP service.

Additional information for setting up Authentik with OpenLDAP may be found here:

https://docs.goauthentik.io/add-secure-apps/providers/ldap

Name

ldap

Slug

ldap
  • Enabled
  • Sync Users
  • User password writeback
  • Sync groups

Connection settings

Server URI

ldap://:389
  • Enable StartTLS

TLS Verification Certificate

---------

Bind CN

The Bind CN item is the distinguished name (DN) of the administrative user you will use to login (authenticate) to the OpenLDAP server for Authentik to do its work. 

uid=admin,ou=people,dc=example,dc=com

Bind Password

The Bind Password is the password for the admin account.

ADMIN_PASSWORD

Base DN

Remember, this must be the base DN for the OpenLDAP directory. It should look something like:

dc=example,dc=com

LDAP Attribute mapping

User Property Mappings

  • authentik default LDAP Mapping: mail
  • authentik default LDAP Mapping: Name
  • authentik default Active Directory Mapping: givenName
  • authentik default Active Directory Mapping: sAMAccountName
  • authentik default Active Directory Mapping: sn
  • authentik default Active Directory Mapping: userPrincipalName
  • authentik default OpenLDAP Mapping: cn
  • authentik default OpenLDAP Mapping: uid

Group Property Mappings

  • authentik default LDAP Mapping: mail
  • authentik default LDAP Mapping: Name
  • authentik default Active Directory Mapping: givenName
  • authentik default Active Directory Mapping: sAMAccountName
  • authentik default Active Directory Mapping: sn
  • authentik default Active Directory Mapping: userPrincipalName
  • authentik default OpenLDAP Mapping: cn
  • authentik default OpenLDAP Mapping: uid

Additional settings

Group

---------

User path

LDAP/users

Addition User DN

ou=people

Addition Group DN

ou=groups

User object filter

(objectClass=person)

Group object filter

(objectClass=groupOfUniqueNames)

Group membership field

member

Object uniqueness field

uid