Warda-DNSDocs Warda: from ward — to protect, guardian
v0.6.9

Users of the directory

Business → Users of the directory (business.identity, Warda Business, beta; internal/directory, internal/admin/directory.go, go-ldap v3, MIT): the people of Active Directory or of an LDAP directory (OpenLDAP, Samba…) imported every hour as people of Warda.

  • The directory: Address ldaps://server (port 636) or ldap://server (port 389) with StartTLS — never in clear; the Certificate of the authority (PEM) when the directory has the company's own (the certificate of the server is always checked, one that cannot be checked is refused); the Account of reading (a DN or user@domain, read-only; empty: anonymous) and its password (kept with these settings in the meta table of the database of the box — not encrypted apart, only as the whole database is at rest —, never given back by the API nor put in the diagnostic, in the backups, which are encrypted, and sent to the secondary of a pair of high availability with the rest of the configuration: "Kept: leave empty to keep it"); Where the people are (base DN); the Attribute of the groups (memberOf); the Filter of the people (empty: the people of Active Directory, not its machines, and the inetOrgPerson of OpenLDAP). Each request waits 30 seconds at most.
  • Test the connection reads without importing ("The connection works: 12 people found, 1 disabled (…)"), with the groups seen.
  • Import now, and every hour while Import the people every hour is on (task Users of the directory, business.identity, 5 minutes after the start): a new entry becomes a person (an adult; its name, else its name and login when taken), a person known is renamed with the directory and keeps everything else; the accounts disabled in the directory are marked Disabled in the directory, those no longer found No longer found. Nothing is ever written to the directory, and nobody is removed by itself: Remove the people no longer found asks first (their devices stay, given to nobody).
  • Groups of the directory: give a group of the directory (up to 200) a group of devices; the devices of its people then follow the blocked services and the data loss prevention of that group (their own settings still first; the first group of a person that has one counts). Applied at once.
  • The administration log records directory.settings, directory.sync ("12 found, 2 new, 1 disabled, 0 no longer found") and the people created or renamed (person.create, person.update, "(directory)"). The settings (password included: the backup is encrypted) and the people imported go with the backups.

GET /api/v1/business/identity (accounts read) gives the settings (enabled, url, start_tls, ca, bind_dn, base_dn, filter, group_attribute, groups of dn and group_id; never the password: password_set), status (last, last_ok, error, found, added, disabled, missing), people, seen_groups and every_s; PUT saves them (password empty keeps the one saved); POST /api/v1/business/identity/test tests the settings given (found, disabled, sample, groups); POST /api/v1/business/identity/sync imports now and DELETE /api/v1/business/identity/missing removes the people no longer found (both also need household written). Later: signing in to Warda with the password of the directory, Entra ID and Google Workspace.