Skip to content

With the LDAP/AD module, colleagues sign in to the appliance with their AD account. Their AD group decides their role.

When several people in the IT department use the appliance and access should be controlled in Active Directory. A colleague gets access by joining the AD group and loses it when their AD account is closed.

You need:

  • The Professional or Enterprise licence.
  • The LDAP/AD module downloaded, switched on and loaded under Modules.
  • A service account in AD that may read users and their group memberships.

The Owner role cannot be given through AD. Keep at least one Owner who signs in with sslbrain Cloud or a local password.

  1. Create the AD groups that should give Administrator and Operator, for example sslbrain-admins and sslbrain-operators. Add the users to them directly.

  2. Open System › Users and login › LDAP/AD on the appliance.

  3. Switch on LDAP Authentication and fill in the fields:

    FieldFill in with
    ServerThe domain controller’s hostname or IP address
    Port389
    Base DNWhere in AD users are searched from, for example DC=company,DC=local
    Bind user (DN)The service account’s DN, for example CN=svc-sslbrain,OU=Service,DC=company,DC=local
    Bind passwordThe service account’s password. It is stored encrypted
    Admin groupThe group’s CN, for example sslbrain-admins
    Operator groupThe group’s CN. Can be left empty
    DomainCan be left empty
  4. Click Test connection, and save.

The sign-in page now shows the Log in with AD button. Users type their sAMAccountName (for example jane) or userPrincipalName (for example jane@company.com) and their AD password.

Only administrators can save and test the page. If you switch LDAP authentication off, AD users cannot sign in.

The role is set at every sign-in, from the user’s groups in AD. Move a user to another group and the new role applies from their next sign-in.

The user is a direct member ofRole on the appliance
Admin groupAdministrator
Operator groupOperator
NeitherViewer

What each role may do is described under Users and sign-in.

AD users cannot confirm their sign-in again, so they cannot download private keys or backups. An Owner or a user with a local password does that.

  • Test connection fails: the appliance must reach the domain controller on port 389.
  • The user cannot sign in: the appliance only finds users under Base DN. After 5 failed attempts the form locks.
  • The user gets Viewer instead of their role: only direct membership counts, so a user in a nested group gets Viewer. The group name must match the group’s CN in AD exactly, including upper and lower case.