Prerequisites
You will need the following information to establish an LDAP connection:- LDAP URL - The LDAP/LDAPS URL to connect to (e.g., ldap://domain-or-ip:389 or ldaps://domain-or-ip:636)
- Binding DN/UPN - The Distinguished Name (DN), or User Principal Name (UPN) if supported, of the principal to bind with (e.g., ‘CN=John,CN=Users,DC=example,DC=com’)
- Binding Password - The password to bind with for authentication
- CA Certificate - The SSL certificate (PEM format) to use for secure connection when using ldaps:// with a self-signed certificate
- Secret Rotation
For Password Rotation, the following requirements must additionally be met:
- You must use an LDAPS connection
- The binding user must either have:
- Permission to change other users passwords if rotating directory users’ passwords
- Permission to update their own password if rotating their personal password
Setup LDAP Connection in Infisical
- Infisical UI
- API
-
Navigate to the Integrations tab in the desired project, then select App Connections.
-
Select the LDAP Connection option.
-
Select the Simple Bind method option and provide the details obtained from the previous section and press Connect to Provider.
-
Your LDAP Connection is now available for use.
Automatic Credential Rotation
Infisical can automatically rotate the binding password of your LDAP connection on a recurring schedule. This is a single-phase rotation, meaning only one password exists at any given time. When a rotation occurs, the old password is replaced immediately. When creating or editing your LDAP connection, toggle on the Automatic Credential Rotation switch and configure the rotation schedule.
- Rotation Interval - How many days between each rotation.
- Rotate At - The local time of day at which the rotation will be triggered.