LDAP and Active Directory.
With LDAP sign-in, people use the username and password they already have in your directory. Farwing checks the password against the directory and takes their email, name and groups from it. It works with Microsoft Active Directory and with OpenLDAP.
Start from a ready-made set
Open Admin → Single sign-on and choose the directory option. Pick Active Directory or OpenLDAP to fill in the port, filters and attribute names for that kind of directory. You then add your own server address, accounts and search bases. These are the values each set fills in:
| Setting | Active Directory | OpenLDAP |
|---|---|---|
| Port and security | 636, LDAPS | 636, LDAPS |
| User filter | (&(objectClass=user)(sAMAccountName={username})) | (&(objectClass=inetOrgPerson)(uid={username})) |
| Username attribute | sAMAccountName | uid |
| Email attribute | mail | mail |
| Name attribute | displayName | cn |
| Group filter | (objectClass=group) | (objectClass=groupOfNames) |
| Member attribute | member | member |
| Nested groups | On | Off |
Connection settings
| Setting | What to enter |
|---|---|
| Server address | The host name of a domain controller or LDAP server, such as ldap.example.com. Enter the name only, with no ldaps:// and no path. |
| Port | Usually 636 for LDAPS and 389 for StartTLS. |
| Security | LDAPS or StartTLS. LDAPS is the default. See the warning below. |
| Sign-in button wording | What the sign-in page calls this method. It is company directory until you change it. It may be up to 40 characters. |
The service account
Farwing looks people up with a service account. Make a dedicated account that can only read the directory, and enter its full distinguished name and password:
CN=farwing-service,OU=Service Accounts,DC=example,DC=com
Farwing stores the password encrypted and never shows it again. The screen only tells you that one is saved. Some OpenLDAP servers allow searches without signing in. If yours does, leave the service account empty.
Where to find people and groups
| Setting | What it does |
|---|---|
| User search base | The part of the directory to search for people, such as OU=People,DC=example,DC=com. Required. |
| User filter | Finds one person. It must contain {username}, which Farwing replaces with the name typed at sign-in. |
| Group search base | The part of the directory to search for groups, such as OU=Groups,DC=example,DC=com. If you leave it empty, Farwing uses the user search base. |
| Group filter | Finds groups. If you leave it empty, Farwing does not look up groups. |
Attribute names
| Attribute | What Farwing reads it for |
|---|---|
| Username | The name people type at sign-in. Required. |
| The person's Farwing account. Required. | |
| Name | The name shown in the portal. Optional. |
| Member | The attribute on a group that lists its members. Needed when you look up groups. |
The ready-made sets above already hold the right names for Active Directory and OpenLDAP. Change them only if your directory uses different ones.
Groups
Group mapping turns directory groups into Farwing groups. Add one row for each. Give the directory group's name or its distinguished name on one side and the Farwing group on the other. Farwing creates a user the first time that person signs in, and updates their groups at every sign-in.
Nested groups in Active Directory
In Active Directory, groups can sit inside other groups. Turn on Nested groups and Farwing asks Active Directory for every group a person belongs to, including the groups that contain their groups. It uses Active Directory's built-in "member of, including nested groups" search. Only Active Directory understands it, so the OpenLDAP set leaves it off.
Test it
Two buttons check your settings before anyone relies on them.
| Button | What it proves |
|---|---|
| Test connection | Farwing can reach the directory, set up the encrypted connection, sign in with the service account and search. It does not involve any person's password. |
| Test a login | One real person can sign in. Enter that person's username and password. Farwing shows whether the sign-in worked, the email and name it found, and which groups were found, including which Farwing groups they map to. It proves the user filter, the attribute names and the group settings together. |
Run Test a login with an ordinary person and with someone who is in a group you map. If the groups come back wrong, check the group search base, the group filter and, in Active Directory, the nested groups switch.
The hourly sync
When the sync is on, Farwing checks the directory every hour. It disables Farwing users who were removed or disabled in the directory. A disabled user can no longer sign in.
Farwing never deletes these users. Their files and their history stay on the server, so you can still see who sent and received what.
If LDAP sign-in stops working
The local administrator must have a password and an authenticator app. Farwing shows a warning while it has no authenticator. Set one up before you turn LDAP sign-in on.
To get back in:
- Open your Farwing server's normal sign-in page.
- Type the local administrator's email and password into the form, and choose Sign in. Do not use the button for the directory.
- Enter the 6-digit code from the authenticator app. If you no longer have the app, choose Use a recovery code instead and enter a code you saved when you set it up. Or ask another administrator to reset your second factor.
- Open Admin → Single sign-on. Correct the setting, or turn the directory sign-in off, and save.
- Run Test a login before you close the administrator session.
Admin → Audit records every directory sign-in, every failure and every change to these settings.