Skip to content

Commit

Permalink
Merge pull request #240 from GitHubUser4234/master
Browse files Browse the repository at this point in the history
Documentation for enabling changing passwords in user_ldap
  • Loading branch information
MorrisJobke committed Dec 9, 2016
2 parents 9c25089 + 08dd8d9 commit 2fe8fd8
Show file tree
Hide file tree
Showing 2 changed files with 17 additions and 0 deletions.
17 changes: 17 additions & 0 deletions admin_manual/configuration_user/user_auth_ldap.rst
Original file line number Diff line number Diff line change
Expand Up @@ -375,6 +375,23 @@ Group Member association:
have a very valid reason and know what you are doing.

* Example: *uniquemember*

Enable LDAP password changes per user:
Allow LDAP users to change their password and allow Super Administrators and Group Administrators to change the password of their LDAP users.

To enable this feature, the following requirements have to be met:

* General requirements:

* Access control policies must be configured on the LDAP server to grant permissions for password changes.
* Passwords are sent in plaintext to the LDAP server. Therefore, transport encryption must be used for the communication between Nextcloud and the LDAP server, e.g. employ LDAPS.
* Enabling password hashing on the LDAP server is highly recommended. While Active Directory stores passwords in a one-way format by default, OpenLDAP users could configure the ``ppolicy_hash_cleartext`` directive of the ppolicy overlay that ships with OpenLDAP.

* Additional requirements for Active Directory:

* At least a 128-bit transport encryption must be used for the communication between Nextcloud and the LDAP server
* Make sure that the ``fUserPwdSupport`` char of the dSHeuristics is configured to employ the ``userPassword`` attribute as ``unicodePwd`` alias. While this is set accordingly on AD LDS by default, this is not the case on AD DS.


Special Attributes
^^^^^^^^^^^^^^^^^^
Expand Down
Binary file modified admin_manual/images/ldap-advanced-2-directory.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.

0 comments on commit 2fe8fd8

Please sign in to comment.