LDAP/AD Identity Provider Connections
To secure the connection between Hammerspace and an Active Directory identity provider, set --connection-security TLS (ldaps, port 636) or --connection-security STARTTLS (port 389) on idp-add/idp-update, and enable server-certificate validation with --validate-server-certs-enable. Before enabling validation, add the AD server’s CA certificate under (or cert-add). After upgrading to 5.3, existing IdP entries default to connection security NONE with certificate validation unset — re-configure them explicitly.
Additional notes:
-
The value
SSLis accepted as a synonym forTLSin--connection-security. -
Certificate validation is disabled unless you enable it. To turn validation off on an existing IdP, use
idp-update --validate-server-certs-disable;idp-addhas no disable option. -
Hammerspace does not monitor the AD server for later changes in its TLS capability; if the server’s TLS configuration changes, update the IdP configuration to match.