summaryrefslogtreecommitdiff
path: root/docs/configuration/cheatsheet.md
diff options
context:
space:
mode:
authorfeld <feld@feld.me>2024-09-16 15:50:58 +0000
committerfeld <feld@feld.me>2024-09-16 15:50:58 +0000
commit3a0d4e98374d77fd6721034362677984b97d2cab (patch)
tree8d7c8721b6718185d8feff1fda1240f1001358e0 /docs/configuration/cheatsheet.md
parent8250a9764ea07a69a701401fd00f6d55e0ef2003 (diff)
parent91d1d7260b7084f59ae42e7c4b46c7fb963fda96 (diff)
downloadpleroma-3a0d4e98374d77fd6721034362677984b97d2cab.tar.gz
pleroma-3a0d4e98374d77fd6721034362677984b97d2cab.zip
Merge branch 'ldap-tls' into 'develop'
LDAP: permit overriding the CA root, improve SSL/TLS See merge request pleroma/pleroma!4265
Diffstat (limited to 'docs/configuration/cheatsheet.md')
-rw-r--r--docs/configuration/cheatsheet.md5
1 files changed, 3 insertions, 2 deletions
diff --git a/docs/configuration/cheatsheet.md b/docs/configuration/cheatsheet.md
index 0b4e53b6f..6a535e054 100644
--- a/docs/configuration/cheatsheet.md
+++ b/docs/configuration/cheatsheet.md
@@ -968,12 +968,13 @@ Pleroma account will be created with the same name as the LDAP user name.
* `enabled`: enables LDAP authentication
* `host`: LDAP server hostname
* `port`: LDAP port, e.g. 389 or 636
-* `ssl`: true to use SSL, usually implies the port 636
+* `ssl`: true to use implicit SSL/TLS, usually port 636
* `sslopts`: additional SSL options
-* `tls`: true to start TLS, usually implies the port 389
+* `tls`: true to use explicit TLS (STARTTLS), usually port 389
* `tlsopts`: additional TLS options
* `base`: LDAP base, e.g. "dc=example,dc=com"
* `uid`: LDAP attribute name to authenticate the user, e.g. when "cn", the filter will be "cn=username,base"
+* `cacertfile`: Path to alternate CA root certificates file
Note, if your LDAP server is an Active Directory server the correct value is commonly `uid: "cn"`, but if you use an
OpenLDAP server the value may be `uid: "uid"`.