mirror of
https://github.com/honeymoose/OpenSearch.git
synced 2025-02-24 05:44:59 +00:00
[DOCS] [Security] Templates do not use bind_dn (elastic/x-pack-elasticsearch#1979)
Document that user_dn_template mode for LDAP authentication does not support bind_dn Original commit: elastic/x-pack-elasticsearch@eef72615a8
This commit is contained in:
parent
84ee21ed26
commit
a36121a725
@ -85,7 +85,7 @@ users, you can use User DN templates to configure the realm. The advantage of
|
|||||||
this method is that a search does not have to be performed to find the user DN.
|
this method is that a search does not have to be performed to find the user DN.
|
||||||
However, multiple bind operations might be needed to find the correct user DN.
|
However, multiple bind operations might be needed to find the correct user DN.
|
||||||
|
|
||||||
To configure an `ldap` Realm with User Search:
|
To configure an `ldap` Realm with User DN templates:
|
||||||
|
|
||||||
. Add a realm configuration of type `ldap` to `elasticsearch.yml` in the
|
. Add a realm configuration of type `ldap` to `elasticsearch.yml` in the
|
||||||
`xpack.security.authc.realms` namespace. At a minimum, you must set the realm `type` to
|
`xpack.security.authc.realms` namespace. At a minimum, you must set the realm `type` to
|
||||||
@ -119,6 +119,9 @@ xpack:
|
|||||||
|
|
||||||
. Restart Elasticsearch
|
. Restart Elasticsearch
|
||||||
|
|
||||||
|
IMPORTANT: The `bind_dn` setting is not used in template mode.
|
||||||
|
All LDAP operations will execute as the authenticating user.
|
||||||
|
|
||||||
|
|
||||||
[[ldap-load-balancing]]
|
[[ldap-load-balancing]]
|
||||||
===== Load Balancing and Failover
|
===== Load Balancing and Failover
|
||||||
|
@ -155,6 +155,7 @@ to `1h`.
|
|||||||
|
|
||||||
`bind_dn`::
|
`bind_dn`::
|
||||||
The DN of the user that will be used to bind to the LDAP and perform searches.
|
The DN of the user that will be used to bind to the LDAP and perform searches.
|
||||||
|
Only applicable in {xpack-ref}/ldap-realm.html#ldap-user-search[user search mode].
|
||||||
If this is not specified, an anonymous bind will be attempted.
|
If this is not specified, an anonymous bind will be attempted.
|
||||||
Defaults to Empty.
|
Defaults to Empty.
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user