Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Discuss
  3. Cloudron LDAP access for external apps?

Cloudron LDAP access for external apps?

Scheduled Pinned Locked Moved Solved Discuss
11 Posts 6 Posters 2.0k Views 7 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • ? Offline
    ? Offline
    A Former User
    wrote on last edited by
    #1

    Is it possible to make the LDAP service in Cloudron accessible to external applications? I know external access is disabled by default, but it would be great if it were open for any external apps I have. Thanks

    1 Reply Last reply
    1
    • jdaviescoatesJ Offline
      jdaviescoatesJ Offline
      jdaviescoates
      wrote on last edited by jdaviescoates
      #2

      No, not yet but hopefully soon πŸ™‚

      I use Cloudron with Gandi & Hetzner

      1 Reply Last reply
      0
      • ? Offline
        ? Offline
        A Former User
        wrote on last edited by
        #3

        Damn, I forgot to verify this before I installed to experiment.

        jdaviescoatesJ 1 Reply Last reply
        0
        • ? A Former User

          Damn, I forgot to verify this before I installed to experiment.

          jdaviescoatesJ Offline
          jdaviescoatesJ Offline
          jdaviescoates
          wrote on last edited by
          #4

          @YurkshireLad personally I don't need it yet, but it'd be nice to have.

          I've only been playing around with/ using Cloudron since January but I totally love it so far, and I've been really impressed with how responsive the developers are; they respond promptly, fix bugs quickly and add new features at an amazing rate.

          I use Cloudron with Gandi & Hetzner

          1 Reply Last reply
          2
          • nebulonN Offline
            nebulonN Offline
            nebulon
            Staff
            wrote on last edited by
            #5

            Technically this seems to be possible quite easily by providing a TLS certificate to the ldap server instance and expose it on a public port. It however raises a few issues like rate-limiting and how to configure which users and groups are exposed there. Also ldap binds for user searches have to be maintained somehow (I think similar to app passwords)
            So far there was no focus on that feature, as we don't know how useful it really is for which use-cases and which organizations really require this. Afterall just adding also adds an ongoing burden on testing and maintaining such a feature.

            imc67I 1 Reply Last reply
            1
            • nebulonN nebulon

              Technically this seems to be possible quite easily by providing a TLS certificate to the ldap server instance and expose it on a public port. It however raises a few issues like rate-limiting and how to configure which users and groups are exposed there. Also ldap binds for user searches have to be maintained somehow (I think similar to app passwords)
              So far there was no focus on that feature, as we don't know how useful it really is for which use-cases and which organizations really require this. Afterall just adding also adds an ongoing burden on testing and maintaining such a feature.

              imc67I Offline
              imc67I Offline
              imc67
              translator
              wrote on last edited by
              #6

              @nebulon the LDAP/SSO discussions are alas a β€˜little bit’ scattered around the forum, this is from another thread:

              @imc67 said in LDAP/AD Server:

              It would be extremely convenient to have Cloudron as a LDAP server (app) and contains "the one and only truth" about usermanagement (all users/groups etc) so external systems (like local NAS) can make use of it.

              Is that feasible, easy to do, safe ...?

              1 Reply Last reply
              1
              • nebulonN Offline
                nebulonN Offline
                nebulon
                Staff
                wrote on last edited by
                #7

                Agree, let me lock this thread in favor of the other one.

                1 Reply Last reply
                1
                • A Offline
                  A Offline
                  augusto
                  wrote on last edited by
                  #8

                  Just here to vote for a implementation for this feature.

                  In our organization, we have different internal apps that are scattered here and there because of historical reasons. We use cloudron now for some apps and would like to manage users from a single source, but at the moment the only way we could do that is configuring an ldap server which is something that's out of our knowledge base.

                  Would be great to have something like a simple app we could install on or cloudron and we can cosult via rest API where we can get the active users and groups/roles, something super simple but that's synced with the cloudron user directory. Is this feasible?

                  fbartelsF 1 Reply Last reply
                  2
                  • A augusto

                    Just here to vote for a implementation for this feature.

                    In our organization, we have different internal apps that are scattered here and there because of historical reasons. We use cloudron now for some apps and would like to manage users from a single source, but at the moment the only way we could do that is configuring an ldap server which is something that's out of our knowledge base.

                    Would be great to have something like a simple app we could install on or cloudron and we can cosult via rest API where we can get the active users and groups/roles, something super simple but that's synced with the cloudron user directory. Is this feasible?

                    fbartelsF Offline
                    fbartelsF Offline
                    fbartels
                    App Dev
                    wrote on last edited by
                    #9

                    @augusto I've got good news for you: https://forum.cloudron.io/post/41167

                    jdaviescoatesJ 1 Reply Last reply
                    3
                    • fbartelsF fbartels

                      @augusto I've got good news for you: https://forum.cloudron.io/post/41167

                      jdaviescoatesJ Offline
                      jdaviescoatesJ Offline
                      jdaviescoates
                      wrote on last edited by
                      #10

                      @nebulon said in Cloudron LDAP access for external apps?:

                      Agree, let me lock this thread in favor of the other one.

                      Doesn't look like you did ever lock it πŸ™‚

                      But perhaps now turn this into a question and mark it as solved πŸ™‚

                      I use Cloudron with Gandi & Hetzner

                      nebulonN 1 Reply Last reply
                      0
                      • nebulonN nebulon marked this topic as a question on
                      • nebulonN nebulon has marked this topic as solved on
                      • jdaviescoatesJ jdaviescoates

                        @nebulon said in Cloudron LDAP access for external apps?:

                        Agree, let me lock this thread in favor of the other one.

                        Doesn't look like you did ever lock it πŸ™‚

                        But perhaps now turn this into a question and mark it as solved πŸ™‚

                        nebulonN Offline
                        nebulonN Offline
                        nebulon
                        Staff
                        wrote on last edited by
                        #11

                        @jdaviescoates thanks for the hint πŸ™‚

                        1 Reply Last reply
                        1
                        Reply
                        • Reply as topic
                        Log in to reply
                        • Oldest to Newest
                        • Newest to Oldest
                        • Most Votes


                        • Login

                        • Don't have an account? Register

                        • Login or register to search.
                        • First post
                          Last post
                        0
                        • Categories
                        • Recent
                        • Tags
                        • Popular
                        • Bookmarks
                        • Search