LDAP Auth Backend: Redhat IPA Example (Freeipa)

Since the release 2013-05-10 “Weatherwax”
see AuthLDAP plugin Redhat IPA config page

For releases 2012-10-13 “Adora Belle” and older
see info below

Here is a configuration that worked with LDAP backend for Freeipa IDM / IPA IDM.

Without SSL (so far)

$conf['authtype']  = 'authldap';
$conf['auth']['ldap']['server']      = 'ldap://ipa.domain.tld:389';
$conf['auth']['ldap']['usertree']    = 'cn=users,cn=accounts,dc=domain,dc=tld';
$conf['auth']['ldap']['grouptree']   = 'cn=groups,cn=accounts,dc=domain,dc=tld';
$conf['plugin']['authldap']['userfilter'] = '(&(uid=%{user})(objectClass=posixAccount))';
$conf['plugin']['authldap']['groupfilter'] = '(&(member=%{dn})(objectClass=groupOfNames))';
//debug only
//$conf['auth']['ldap']['debug']      = 1;
