Sign-in with Active Directory
Copy link to the page “Sign-in with Active Directory”With the LDAP/AD module, colleagues sign in to the appliance with their AD account. Their AD group decides their role.
When you need this
Copy link to the section “When you need this”When several people in the IT department use the appliance and access should be controlled in Active Directory. A colleague gets access by joining the AD group and loses it when their AD account is closed.
You need:
- The Professional or Enterprise licence.
- The LDAP/AD module downloaded, switched on and loaded under Modules.
- A service account in AD that may read users and their group memberships.
The Owner role cannot be given through AD. Keep at least one Owner who signs in with sslbrain Cloud or a local password.
Set up the connection to AD
Copy link to the section “Set up the connection to AD”-
Create the AD groups that should give Administrator and Operator, for example
sslbrain-adminsandsslbrain-operators. Add the users to them directly. -
Open System › Users and login › LDAP/AD on the appliance.
-
Switch on LDAP Authentication and fill in the fields:
Field Fill in with Server The domain controller’s hostname or IP address Port 389 Base DN Where in AD users are searched from, for example DC=company,DC=localBind user (DN) The service account’s DN, for example CN=svc-sslbrain,OU=Service,DC=company,DC=localBind password The service account’s password. It is stored encrypted Admin group The group’s CN, for example sslbrain-adminsOperator group The group’s CN. Can be left empty Domain Can be left empty -
Click Test connection, and save.
The sign-in page now shows the Log in with AD button. Users type their sAMAccountName (for example jane) or userPrincipalName (for example jane@company.com) and their AD password.
Only administrators can save and test the page. If you switch LDAP authentication off, AD users cannot sign in.
Roles from AD groups
Copy link to the section “Roles from AD groups”The role is set at every sign-in, from the user’s groups in AD. Move a user to another group and the new role applies from their next sign-in.
| The user is a direct member of | Role on the appliance |
|---|---|
| Admin group | Administrator |
| Operator group | Operator |
| Neither | Viewer |
What each role may do is described under Users and sign-in.
AD users cannot confirm their sign-in again, so they cannot download private keys or backups. An Owner or a user with a local password does that.
If it fails
Copy link to the section “If it fails”- Test connection fails: the appliance must reach the domain controller on port 389.
- The user cannot sign in: the appliance only finds users under Base DN. After 5 failed attempts the form locks.
- The user gets Viewer instead of their role: only direct membership counts, so a user in a nested group gets Viewer. The group name must match the group’s CN in AD exactly, including upper and lower case.