Search the docs

LDAP/AD Identity Provider Connections

To secure the connection between Hammerspace and an Active Directory identity provider, set --connection-security TLS (ldaps, port 636) or --connection-security STARTTLS (port 389) on idp-add/idp-update, and enable server-certificate validation with --validate-server-certs-enable. Before enabling validation, add the AD server’s CA certificate under Administration  TLS  Trusted Certificates (or cert-add). After upgrading to 5.3, existing IdP entries default to connection security NONE with certificate validation unset — re-configure them explicitly.

Additional notes:

  • The value SSL is accepted as a synonym for TLS in --connection-security.

  • Certificate validation is disabled unless you enable it. To turn validation off on an existing IdP, use idp-update --validate-server-certs-disable; idp-add has no disable option.

  • Hammerspace does not monitor the AD server for later changes in its TLS capability; if the server’s TLS configuration changes, update the IdP configuration to match.