Server admin

LDAP and Active Directory.

With LDAP sign-in, people use the username and password they already have in your directory. Farwing checks the password against the directory and takes their email, name and groups from it. It works with Microsoft Active Directory and with OpenLDAP.

Plan: LDAP and Active Directory sign-in need a Business license or higher. It sits next to the OpenID Connect sign-in and SAML, and the sign-in page shows a button for each method you turn on. If a server drops to Free mode, sign-ins that already work keep working. They count toward the 5 active users that Free mode allows.

Start from a ready-made set

Open Admin → Single sign-on and choose the directory option. Pick Active Directory or OpenLDAP to fill in the port, filters and attribute names for that kind of directory. You then add your own server address, accounts and search bases. These are the values each set fills in:

SettingActive DirectoryOpenLDAP
Port and security636, LDAPS636, LDAPS
User filter(&(objectClass=user)(sAMAccountName={username}))(&(objectClass=inetOrgPerson)(uid={username}))
Username attributesAMAccountNameuid
Email attributemailmail
Name attributedisplayNamecn
Group filter(objectClass=group)(objectClass=groupOfNames)
Member attributemembermember
Nested groupsOnOff

Connection settings

SettingWhat to enter
Server addressThe host name of a domain controller or LDAP server, such as ldap.example.com. Enter the name only, with no ldaps:// and no path.
PortUsually 636 for LDAPS and 389 for StartTLS.
SecurityLDAPS or StartTLS. LDAPS is the default. See the warning below.
Sign-in button wordingWhat the sign-in page calls this method. It is company directory until you change it. It may be up to 40 characters.
Warning: plain LDAP is not safe. LDAPS or StartTLS is required by default. Plain LDAP sends the service account's password and every person's password across the network where anyone who can see the traffic can read them. Farwing refuses it unless you do two things: choose the unencrypted option and turn on the insecure switch. A warning stays on the screen for as long as it is on. Use LDAPS or StartTLS instead.

The service account

Farwing looks people up with a service account. Make a dedicated account that can only read the directory, and enter its full distinguished name and password:

CN=farwing-service,OU=Service Accounts,DC=example,DC=com

Farwing stores the password encrypted and never shows it again. The screen only tells you that one is saved. Some OpenLDAP servers allow searches without signing in. If yours does, leave the service account empty.

SettingWhat it does
User search baseThe part of the directory to search for people, such as OU=People,DC=example,DC=com. Required.
User filterFinds one person. It must contain {username}, which Farwing replaces with the name typed at sign-in.
Group search baseThe part of the directory to search for groups, such as OU=Groups,DC=example,DC=com. If you leave it empty, Farwing uses the user search base.
Group filterFinds groups. If you leave it empty, Farwing does not look up groups.

Attribute names

AttributeWhat Farwing reads it for
UsernameThe name people type at sign-in. Required.
EmailThe person's Farwing account. Required.
NameThe name shown in the portal. Optional.
MemberThe attribute on a group that lists its members. Needed when you look up groups.

The ready-made sets above already hold the right names for Active Directory and OpenLDAP. Change them only if your directory uses different ones.

Groups

Group mapping turns directory groups into Farwing groups. Add one row for each. Give the directory group's name or its distinguished name on one side and the Farwing group on the other. Farwing creates a user the first time that person signs in, and updates their groups at every sign-in.

Nested groups in Active Directory

In Active Directory, groups can sit inside other groups. Turn on Nested groups and Farwing asks Active Directory for every group a person belongs to, including the groups that contain their groups. It uses Active Directory's built-in "member of, including nested groups" search. Only Active Directory understands it, so the OpenLDAP set leaves it off.

Test it

Two buttons check your settings before anyone relies on them.

ButtonWhat it proves
Test connectionFarwing can reach the directory, set up the encrypted connection, sign in with the service account and search. It does not involve any person's password.
Test a loginOne real person can sign in. Enter that person's username and password. Farwing shows whether the sign-in worked, the email and name it found, and which groups were found, including which Farwing groups they map to. It proves the user filter, the attribute names and the group settings together.

Run Test a login with an ordinary person and with someone who is in a group you map. If the groups come back wrong, check the group search base, the group filter and, in Active Directory, the nested groups switch.

The hourly sync

When the sync is on, Farwing checks the directory every hour. It disables Farwing users who were removed or disabled in the directory. A disabled user can no longer sign in.

Farwing never deletes these users. Their files and their history stay on the server, so you can still see who sent and received what.

If LDAP sign-in stops working

The local administrator account always works. If the directory is down, a password was changed or a certificate expired, an administrator can still sign in with a password.

The local administrator must have a password and an authenticator app. Farwing shows a warning while it has no authenticator. Set one up before you turn LDAP sign-in on.

To get back in:

  1. Open your Farwing server's normal sign-in page.
  2. Type the local administrator's email and password into the form, and choose Sign in. Do not use the button for the directory.
  3. Enter the 6-digit code from the authenticator app. If you no longer have the app, choose Use a recovery code instead and enter a code you saved when you set it up. Or ask another administrator to reset your second factor.
  4. Open Admin → Single sign-on. Correct the setting, or turn the directory sign-in off, and save.
  5. Run Test a login before you close the administrator session.

Admin → Audit records every directory sign-in, every failure and every change to these settings.