2022-12-24 13:01:51 +01:00
---
gitea: none
include_toc: true
---
# lemonldap
2023-08-02 09:26:54 +02:00
## Synopsis
2022-12-24 13:01:51 +01:00
LemonLDAP, a Web Single Sign On and Access Management.
[For more informations ](https://lemonldap-ng.org/ )
2023-08-02 09:26:54 +02:00
## Basic variables
2023-08-01 15:13:17 +02:00
2023-08-02 09:26:54 +02:00
### Général
2023-08-01 15:13:17 +02:00
2023-08-02 09:26:54 +02:00
#### Reverse proxy
2023-08-01 15:13:17 +02:00
2023-08-02 09:26:54 +02:00
##### Point d'entrée des clients
This a family is a leadership.
| Description | Type | Example | Supplier |
|----------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------|---------------------|-----------------------|
| **Nom de domaine exterieur du serveur** (*[general.revprox.revprox_client.revprox_client_external_domainnames](dictionaries/21_revprox_client.xml)*) [+] | [domainname ](https://forge.cloud.silique.fr/risotto/rougail/src/branch/main/doc/variable/README.md#le-type-de-la-variable ) | service.example.net | ReverseProxy:external |
#### LemonLDAP
Configuration de la solution d'authentification unique LemonLDAP::NG.
| Description | Type | Example |
|-------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------|-------------------|
| **Courriel de l'administrateur** (*[general.lemonldap.lemon_mail_admin](dictionaries/70_lemonldap_ng.xml)*) | [mail ](https://forge.cloud.silique.fr/risotto/rougail/src/branch/main/doc/variable/README.md#le-type-de-la-variable ) | admin@example.net |
- [+]: variable is multiple
- **bold**: variable is mandatory
## Variables
### Général
#### Annuaire OpenLDAP
##### Client
| Description | Type | Values | Supplier |
|----------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------|----------|-------------|
| **Nom de la famille LDAP** (*[general.ldap.client.ldapclient_family](dictionaries/70_lemonldap_ng.xml)*) | [unix_user ](https://forge.cloud.silique.fr/risotto/rougail/src/branch/main/doc/variable/README.md#le-type-de-la-variable ) | all | LDAP:family |
#### Reverse proxy
##### Point d'entrée des clients
This a family is a leadership.
| Description | Type | Supplier |
|-------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------|-----------------------|
| **Nom de l'arborescence racine du site** (*[general.revprox.revprox_client.revprox_client_location](dictionaries/21_revprox_client.xml)*) | [filename ](https://forge.cloud.silique.fr/risotto/rougail/src/branch/main/doc/variable/README.md#le-type-de-la-variable ) | ReverseProxy:location |
#### LemonLDAP
Configuration de la solution d'authentification unique LemonLDAP::NG.
| Description | Type | Values |
|------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------|----------|
| **Nombre de processus dédié à LemonLdap (équivalent au nombre de processeurs)** (*[general.lemonldap.lemon_proc](dictionaries/70_lemonldap_ng.xml)*) | [number ](https://forge.cloud.silique.fr/risotto/rougail/src/branch/main/doc/variable/README.md#le-type-de-la-variable ) | 1 |
- [+]: variable is multiple
- **bold**: variable is mandatory
## Variables for expert
### Général
#### Annuaire OpenLDAP
2023-08-01 15:13:17 +02:00
2023-08-02 09:26:54 +02:00
##### Client
| Description | Values | Supplier |
|------------------------------------------------------------------------------------------------------------------------------------------------------|--------------|--------------|
| **Base DN de l'annuaire** (*[general.ldap.client.ldapclient_base_dn](dictionaries/21_ldap-client.xml)*) | < calculated > | LDAP:base_dn |
| **Base DN de l'annuaire des utilisateurs** (*[general.ldap.client.ldapclient_search_dn](dictionaries/21_ldap-client.xml)*) | < calculated > | |
| **Base DN de l'annuaire des groupes** (*[general.ldap.client.ldapclient_group_dn](dictionaries/21_ldap-client.xml)*) | < calculated > | |
| **Base DN de l'annuaire des utilisateurs n'appartenant à une famille** (*[general.ldap.client.ldapclient_user_dn](dictionaries/21_ldap-client.xml)*) | < calculated > | |
#### NGINX
Paramétrage global de NGINX.
| Description | Type | Values | Choices |
|---------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------|----------|---------------------|
| **Longueur maximum pour un nom de domaine** (*[general.nginx.nginx_hash_bucket_size](dictionaries/21_nginx.xml)*) | [choice ](https://forge.cloud.silique.fr/risotto/rougail/src/branch/main/doc/variable/README.md#le-type-de-la-variable ) | 128 | 128< br /> 64< br /> 32 |
| **Taille maximale des données reçues par la méthode POST (en Mo)** (*[general.nginx.nginx_post_max_size](dictionaries/21_nginx.xml)*) | [number ](https://forge.cloud.silique.fr/risotto/rougail/src/branch/main/doc/variable/README.md#le-type-de-la-variable ) | 32 | |
#### Reverse proxy
##### Point d'entrée des clients
This a family is a leadership.
| Description | Supplier |
|-------------------------------------------------------------------------------------------------------------------------------|----------------------------|
| Taille maximum du corps (*[general.revprox.revprox_client.revprox_client_max_body_size](dictionaries/21_revprox_client.xml)*) | ReverseProxy:max_body_size |
- [+]: variable is multiple
- **bold**: variable is mandatory
## Associated providers
- **LocalDNS**
- Journald
- **SMTP**
- **LDAP**
- **ReverseProxy**
**bold**: provider is mandatory
## Example
Zone names are provided as examples. Think about adapting with the value of provider_zone in configuration file.
2023-08-01 15:13:17 +02:00
```
lemonldap:
applicationservice: lemonldap
provider_zone: oauth2
zones_name:
- ldap
- localdns
- reverseproxy
- smtp
2023-08-02 09:26:54 +02:00
values:
general.revprox.revprox_client.revprox_client_external_domainnames:
- service.example.net
general.lemonldap.lemon_mail_admin: admin@example.net
2023-08-01 15:13:17 +02:00
```
2022-12-24 13:01:51 +01:00
## Dependances
2023-01-17 21:43:32 +01:00
- [ldap-client ](../ldap-client/README.md )
- [relay-mail-client ](../relay-mail-client/README.md )
2023-02-14 14:24:16 +01:00
- [nginx-https ](../nginx-https/README.md )
- [nginx-common ](../nginx-common/README.md )
- [reverse-proxy-client ](../reverse-proxy-client/README.md )
2022-12-24 13:01:51 +01:00
- [base-debian-bullseye ](../base-debian-bullseye/README.md )
- [base-debian ](../base-debian/README.md )
- [systemd ](../systemd/README.md )
- [base-machine ](../base-machine/README.md )
- [base ](../base/README.md )
- [dns-local ](../dns-local/README.md )
2023-02-14 14:24:16 +01:00
- [pki-tls ](../pki-tls/README.md )
2023-06-29 18:56:46 +02:00
- [journald ](../journald/README.md )
2023-07-31 18:41:59 +02:00
- [resolved ](../resolved/README.md )
2022-12-24 13:01:51 +01:00
2023-01-18 09:19:37 +01:00
## Supplier
2022-12-24 13:01:51 +01:00
2023-01-18 09:19:37 +01:00
[oauth2-client ](../oauth2-client/README.md )
2023-02-14 14:43:41 +01:00
[All applications services for this dataset. ](../README.md )