Active Directory and LDAP
One connector covers LDAP directories. Under “Variant”, administrators define how the directory is structured:
| Property | Generic LDAP (ApacheDS) | OpenLDAP | Active Directory |
|---|---|---|---|
| Groups | groupOfNames, member | posixGroup, memberUid | group, member |
| Account ID | uid | uid | sAMAccountName |
| Unique ID | entryUUID | entryUUID | objectGUID |
| Lock | pwdAccountLockedTime | pwdAccountLockedTime | userAccountControl |
| Last logon | not preset | authTimestamp | lastLogonTimestamp, lastLogon |
Connection
The fields: “Host”, “Port”, “Base DN”, and “Bind DN” and “Bind password” of the service account. Under “Advanced” are “User Search Base” and “Group Search Base” – if left empty, the base DN applies – and “Use SSL (LDAPS)”. For Active Directory, further fields are added, including “AD domain” and “Initial Account State”. “Check status” signs in to the directory with the service account.
Accounts
Nova creates new accounts directly below the “User Search Base”: for Generic LDAP and OpenLDAP as uid=<account ID>, for Active Directory as cn=<name>. In Active Directory, Nova sets sAMAccountName to the account ID and userPrincipalName according to the “UPN rule”, or to account ID@AD domain if there is no rule. The “Mail rule” fills the mail attribute for all variants. If “Initial Account State” is set to “Disabled”, a new AD account is created locked and stays locked until it is explicitly enabled. Nova writes further attributes according to the “Mapping”.
Nova finds accounts by uid or mail, in Active Directory by sAMAccountName, userPrincipalName or mail.
Groups
Nova takes over groups as entitlements with a job of type “Import LDAP Groups”. Nova recognises a group by its unique ID, provided the directory supplies one. If the group is renamed or moved within the “Group Search Base”, Nova finds it again through this ID and updates the stored DN. Once the ID is known, Nova accepts only exactly this object: a newly created group with the old name or DN does not count as the same group.
Nova changes memberships one at a time; the other members of a group remain untouched. Generic LDAP does not maintain memberOf itself. There, Nova writes it in addition, provided the directory schema knows the attribute.
Nested groups
Nova reads the group structure. The “Add group” dialog on an account shows the subgroups and parent groups of each group. Nova does not derive assignments from nesting. For Generic LDAP and Active Directory, administrators can nest groups in this dialog (“Add subgroup”) and remove nesting again. OpenLDAP groups (posixGroup) do not allow nesting.
Cycle protection: before Nova enters a group as a subgroup, it checks whether that group already contains the parent group, directly or across further levels. If it does, Nova does not make the change. The same applies if the check cannot be completed – for example because an object cannot be read or the limit of 64 levels, 512 reads or 5 seconds is reached. If the directory already contains a cycle, Nova shows a notice and does not run through the cycle repeatedly. The display reads at most 5,000 groups and 64 levels; if it is incomplete, Nova says so.
Passwords
- Active Directory: Nova writes
unicodePwd. The directory only accepts passwords over an encrypted connection; without “Use SSL (LDAPS)”, Nova refuses to set the password. - Generic LDAP and OpenLDAP: Nova uses the password modify operation according to RFC 3062 and, if the server does not support it, the
userPasswordattribute.
Locking
- Active Directory: Nova sets or clears the
ACCOUNTDISABLEbit inuserAccountControl; the other bits remain unchanged. - Generic LDAP and OpenLDAP: Nova locks permanently through the password policy attribute
pwdAccountLockedTimeand removes it to unlock. The password is kept; Nova reads the result back. This requires an active password policy – for OpenLDAP the ppolicy overlay – and the right to write this attribute.
Last logon
In Active Directory, Nova reads lastLogonTimestamp, otherwise lastLogon; for OpenLDAP authTimestamp, provided the directory maintains it. For Generic LDAP no attribute is preset; one can be specified in the configuration key last_logon_attrs.
Directory permissions required
The service account (“Bind DN”) needs:
- Read: accounts below the “User Search Base”; groups with their member attribute and unique ID below the “Group Search Base”; for Generic LDAP also the schema, to check
memberOf; for the last logon, the attributes named above. - Groups: write the member attribute (
memberormemberUid) on the groups Nova manages; for Generic LDAP alsomemberOfon the accounts. - Accounts: create, modify and delete below the “User Search Base”.
- Passwords: reset them – in Active Directory via
unicodePwd. - Locking: write
userAccountControlorpwdAccountLockedTime. - Nesting: write
memberon parent groups and read the subgroups involved.
Nova should connect via LDAPS (“Use SSL (LDAPS)”); Active Directory requires this for password operations.