---
title: Set Up LDAP Using OpenLDAP Container
slug: litmusedge/set-up-ldap-using-openldap-container
docTags: 
createdAt: 2024-04-05T20:05:18.131Z
---

Litmus Edge allows companies to set up an LDAP server for managing user access to their devices, eliminating the need to define users locally on each Litmus Edge instance.

# Before You Begin

- Make sure you have access to Litmus Edge 3.11.1 and later.
- Basic knowledge of LDAP protocol.

# Step 1: Set Up the OpenLDAP Container

**To set up the OpenLDAP container and access the PHP LDAP Admin UI:**

1. From your Edge Device, navigate to **Applications&#x20;**> **Containers**.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/xlLsh-YiIcg7DfBJRZtbQ_image.png "Applications > Containers page")
2. Copy and paste the below commands and click the **Run** button.
   - Command to run the **OpenLDAP server:&#x20;**
     `docker run -dit -p 389:389 -p 636:636 --name my-openldap-container osixia/openldap:latest`
   - Command to run the **web UI** to configure users and groups:
     `docker run -dit --name phpldapadmin-service -p 9080:80 --env PHPLDAPADMIN_LDAP_HOSTS=<IP-OF-MY-OPENLDP-CONTAINER> -e PHPLDAPADMIN_HTTPS=false osixia/phpldapadmin:latest`
     Replace `<IP-OF-MY-OPENLDP-CONTAINER>` with the *IP address* of the openLDAP container.
     ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/MiT2g0uVtfuPvcEwjs6LZ_image.png "LDAP docker container images")
3. Once both containers are running, you can access *PHP LDAP Admin UI* by going to `<IP Address of LE>:9080` in your web browser.
   You should see this landing page:
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/MsQ7FWWNtxJmlIeUTwxIx_image.png "PHP LDAP Admin UI Landing Page")

# Step 2: Create Users and Groups

To configure the Litmus Edge LDAP container, we need to first create some users and groups on the LDAP server. We will create two users, namely `Alice Smith` and `Bob Jones`, and two groups named `litmus-admin` and `litmus-viewer`.

These LDAP groups will correspond to the *Administrator&#x20;*&#x61;nd *Viewer&#x20;*&#x67;roups in Litmus Edge, respectively.&#x20;

To proceed, we need to *log in* to the LDAP server using the default credentials from the container.

**Login DN:** `cn=admin,dc=example,dc=org`&#x20;

**Password:** `admin`&#x20;

**To log into the PHP LDAP Admin UI:**&#x20;

1. Click the **login&#x20;**&#x62;utton.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/Th_tLRLOD_Sngv-syRJ2b_image.png "PHP LDAP Admin UI Landing Page - Login")
2. Enter the default **Login DN** and **Password**.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/N7GnerPFnbgHXUUlnYOmz_image.png "PHP LDAP Admin UI - Login Dialog Box")
3. Upon successful login, you will see the landing page and an empty tree structure on the left side.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/tPLifSCvsVa4az6MbM0oZ_image.png "PHP LDAP Admin UI Landing Page ")

:::hint{type="info"}
**Note:** To keep this guide simple, we will add the groups and users under this root level. However, in an actual LDAP server, the structure is more complicated and contains many subfolders.
:::

## Step 2a: Add Users

**To add users to the LDAP server:**

1. Click the *globe* icon and then select **Create a child entry**. The *Create Object* page appears.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/lxnze7qWupISmDdsVr5ff_image.png "PHP LDAP Admin UI Create User Page")
2. Choose **Default** from Templates.
3. Select **inetOrgPerson&#x20;**&#x66;rom *ObjectClasses&#x20;*&#x6C;ist for the LDAP server container.
4. Click **Proceed >>**
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/JmwTeMya3JxD5EhKfzJ16_image.png "PHP LDAP Admin UI Create User Dialog Box")
5. Fill out the basic details for the users:
   - **cn:** asmith
   - **sn:** Smith
   - **givenName:** Alice
   - **employeeNumber:&#x20;**&#x31;2345
   - **Password:&#x20;**\<enter a password>
6. Click **Create Object** and then **Commit**.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/GPdt1M2U818xctwuXTD5F_image.png "PHP LDAP Admin UI Create LDAP Entry Page")
7. Repeat the above for Bob Jones (make sure you do this on the root of the LDAP by clicking on **dc=example, dc=org** and **Create a child entry**).
   Enter the following details:
   - **cn:** bjones&#x20;
   - **sn:** Jones&#x20;
   - **givenName:** Bob&#x20;
   - **employeeNumber:** 54321&#x20;
   - **Password:&#x20;**\<enter a password>
8. Click **Create Object** and then **Commit**.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/la3VVO6Lj-EdJLuxdmH_m_image.png "PHP LDAP Admin UI Create LDAP Entry Page")

You should see both *Alice* and *Bob* added to the LDAP server:&#x20;

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/g66K265aDwy6PgemOq9Pa_image.png" size="60" width="304" height="262" position="center" caption="PHP LDAP Admin UI Side Option" showCaption="true"}

## Step 2b: Add Groups

**To add groups to the LDAP server:**

1. Click the *globe* icon and then select **Create a child entry**. The *Create Object* page appears.
2. Choose **Default** from Templates.
3. Select **groupOfNames&#x20;**&#x66;rom *ObjectClasses&#x20;*&#x6C;ist for the LDAP server container.
4. Click **Proceed >>**
5. Fill out the basic details for the groups:
   - **cn:** litmus-admin
   - **member:&#x20;**&#x43;lick the *search icon&#x20;*&#x61;nd select **cn=asmith**
6. Click **Create Object**.
   ::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/6aGEnfp7425bBSXxyR3Ph_image.png" size="80" width="753" height="719" position="center" caption="PHP LDAP Admin UI - Create Groups" showCaption="true"}
7. Click **Commit.**
   ::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/eDBXaq_KMuX4WagSnBrio_image.png" size="70" width="513" height="275" position="center" caption="PHP LDAP Admin UI Create LDAP Entry Page" showCaption="true"}
8. Repeat the above for **Litmus-viewer** group (make sure you do this on the root of the LDAP by clicking on **dc=example, dc=org** and **Create a child entry**).
   Enter the following details:
   - **cn:** litmus-viewer&#x20;
   - **member:&#x20;**&#x43;lick the *search icon&#x20;*&#x61;nd select **cn=bjones**
9. Click **Create Object.**
   ::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/3laUsgiT9mPUmAtqi1aEC_image.png" size="70" width="581" height="712" position="center" caption="PHP LDAP Admin UI - Create Groups" showCaption="true"}
10. Click **Commit.**
    ::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/Fj8xMIhxpHn-K_nn9Wh4b_image.png" size="70" width="475" height="277" position="center" caption="PHP LDAP Admin UI Create LDAP Entry Page" showCaption="true"}

We should now have four entries under the root folder of the LDAP server. Next, we will configure Litmus Edge.

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/PLL_EIG6js49b0EQpT8Vu_image.png" size="60" width="346" height="370" position="center" caption="PHP LDAP Admin UI Side Option" showCaption="true"}

# Step 3: Litmus Edge LDAP Configuration&#x20;

**To define the LDAP server connection from your edge device:**

1. Navigate to *System&#x20;*>*&#x20;LDAP/AD Auth* and then click the **+** button to define a new LDAP Provider.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/dOZdmIjyTG4dTUlax9aEr_image.png "System > LDAP/AD Auth Page")
2. The *Add Provider* dialog box appears. Here, we have the option to start from a template or to define everything manually.
   Select **Advanced** to fill in all details and understand each parameter.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/ELAuTeeF9WEah3VGkcaQ1_image.png "Add Provider dialog box ")
3. On the *Generic&#x20;*&#x74;ab, give the provider a **name&#x20;**&#x61;nd click **Next**.
   The default selection for *Type&#x20;*&#x69;s **generic**.
   ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/tpFmkUQw2ZOsbksR9Vwdz_image.png "Add Provider dialog box - Generic tab")
4. On the *Connection* tab, enter the following:&#x20;
   - **Host:&#x20;**&#x45;nte&#x72;**&#x20;IP address&#x20;**&#x6F;f the LDAP container as the host.
   - **Port:&#x20;**&#x45;nter the **port number&#x20;**&#x75;sed to define the docker container for the LDAP server. For this guide, we used port **389&#x20;**&#x69;n *Step 1*.
   - **Bind DN and Bind DN Password:&#x20;**&#x45;nter the same **admin user credentials** to authenticate *PHP LDAP Admin UI*.
   - Click **Next**.
     ![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/m1N2ORWJjJ_fiFuSxw-4p_image.png "Add Provider dialog box - Connection tab")

# Step 4: Define User Search Details

In the *User&#x20;*&#x74;ab, we define the parameters for Litmus Edge to search and parse relevant information from the LDAP server, such as first name, last name, username, and UserID.

**The following information defines the User configuration:**

1. **User Search Base DN:&#x20;**&#x54;he DN (Distinguished Name) of the folder in the LDAP server is the starting point for searching users. As our LDAP server is simple, we'll start searching from the top-level folder, which is **dc=example, dc=org**.
2. **Search Scope:** Litmus Edge can use this setting to determine the level at which it should search for users.&#x20;
   There are *three&#x20;*&#x6F;ptions in the *dropdown&#x20;*&#x6D;enu to choose from:
   - **base:** Search at the base level of the User Search Base DN.
   - **one:** Search one level below the base level of the User Search Base DN.&#x20;
   - **sub:** Search all levels below the User Search Base DN.&#x20;
     For this guide, select **sub** to search everything under the top level folder.
3. **User Search Filter:** We require a filter to provide Litmus Edge with a list of users who should have access to it.&#x20;
   In a practical scenario, individuals may want to limit access to only specific employees, but for guide, we will match any entry that has an objectClass of *inetOrgPerson*: `(&(objectClass=inetOrgPerson))`&#x20;
   If you need more information on how to write LDAP filters, you can refer this [resource](https://confluence.atlassian.com/kb/how-to-write-ldap-search-filters-792496933.html).
4. **Attribute For Unique UserID:** This is the attribute that Litmus Edge will use as a unique identifier for each user. In this example, we will use **employeeNumber**.
5. **Attribute For Username:** This is the attribute that Litmus Edge will use for the username when logging in to LE. In this example, we will use **cn**.&#x20;
   So Alice's username will be *asmith* and Bob's username will be *bjones*.&#x20;
6. **First Name:** This is the attribute that Litmus Edge will use for the user's first name. This is the **givenName&#x20;**&#x61;ttribute that we filled out when creating Alice and Bob's user accounts in the LDAP server.&#x20;
7. **Last Name:** This is the attribute that Litmus Edge will use for the user's last name. For this example, we will use **sn** attribute.

After configuring your *User* tab, it will look like the screenshot below.&#x20;

![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/izu7xVn1qn0QnVggbTWpl_image.png "Add Provider dialog box - User tab")

# Step 5: Define Group Search Details&#x20;

The *Group&#x20;*&#x74;ab is same as the user section, but this time we are telling Litmus Edge how to search for the groups.

**The following information defines the Group configuration:**

1. **Group Search Base DN:&#x20;**&#x54;he DN (Distinguished Name) of the folder in the LDAP server will be our starting point for searching groups. As our LDAP server is simple, we'll start searching from the top-level folder, which is **dc=example, dc=org**.
2. **Search Scope:** Litmus Edge can use this setting to determine the level at which it should search for groups.&#x20;
   There are *three&#x20;*&#x6F;ptions in the *dropdown&#x20;*&#x6D;enu to choose from:
   - **base:** Search at the base level of the Group Search Base DN.
   - **one:** Search one level below the base level of the Group Search Base DN.&#x20;
   - **sub:** Search all levels below the Group Search Base DN.&#x20;
     For this guide, select **sub** to search everything under the top level folder.
3. **Group Search Filter:** We require a filter to provide Litmus Edge with a list of groups who should have access to it.&#x20;
   For this guide, we will match any entry that has an objectClass of *groupOfNames* and then we will add an additional filter to only include the *groupOfNames* that have a *cn* that starts with *Litmus*.&#x20;
   The filter looks like the following: `(&(objectClass=groupOfNames)(cn=litmus*))`
4. **Group Name Attribute:** This is the attribute Litmus Edge will use to display the group name.&#x20;
   In this example, we will use **cn**.
5. **Group Membership Attribute:** This attribute informs Litmus Edge which users belong to the group. This information is necessary for Litmus Edge to determine a user's permissions upon login.&#x20;
   In this example, we use **member&#x20;**&#x61;ttribute.
6. **Group Member Value Type:** This attribute tells Litmus Edge about the type of information stored in the list of members. When we added Bob and Alice to the group, their user account DN was inserted.
   In this example, Litmus Edge can use the attribute **DN** to identify members in the list.

After configuring your *Groups&#x20;*&#x74;ab, it will look like the screenshot below.&#x20;

![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/Rly3GFhXMnP5BYLi73F9j_image.png "Add Provider dialog box - Groups tab")

# Step 6: Test the Configuration

You will find a *Test&#x20;*&#x62;utton on this screen that will verify the input settings.

Click the **Test&#x20;**&#x62;utton. The *Update Provider* dialog box appears. It shows the expected results for two users and two groups.

![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/iMC3sBpc1smrCnv0-BEe-_image.png "Update Provider dialog box ")

# Step 7: Map LDAP Groups to Litmus Edge Groups

After a successful test of the connection, click **Create and Map Groups**. The *Map Groups* dialog box appears.

![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/Hf0XB5sGcp6IygnREtTsF_image.png "Map Groups dialog box")

Litmus Edge was able to connect to the LDAP server and find the list of groups that we created.

Next, we need to map these groups to the local groups we have on Litmus Edge. This mapping will let Litmus Edge know which permissions the user should be granted when they log in.

From the drop-down menu, map *litmus-admin* to **Administrators&#x20;**&#x61;nd *litmus-viewer* to **Viewers&#x20;**&#x61;nd click **Save**.

![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/tALNSIXeYAbZL-bcjtXgY_image.png "Map Groups dialog box - With Permissions")

# Step 8: Check User Access to Edge Device

Now, we will log in as Alice or Bob and verify that they each have the *Administrator&#x20;*&#x61;nd *Viewer&#x20;*&#x70;ermissions, respectively.

:::hint{type="info"}
**Note:** Please use the login credentials that were configured for Alice and Bob in *Step 2a*.
:::

Select **openldap&#x20;**&#x66;rom *Provider ID* drop-down to log in via LDAP.

::Image[]{src="https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/CmMddPBc-cQgmylXp2dQQ_image.png" size="70" width="504" height="440" position="center" caption="Litmus Edge Login Page" showCaption="true"}

If you select *Internal&#x20;*&#x70;rovider, Litmus Edge will look for a local user with the username of asmith, which does not exist. If your login was successful, you should see the EULA and need to accept it (this is only the case for the first login).

When you log in as Alice, you have complete access to Litmus Edge. To check, navigate to *System/Users/Groups&#x20;*&#x61;nd select **Administrators**. You will notice that Alice has been added to the Administrators group. This is expected because Alice is part of the litmus admin on the LDAP server.

![](https://api.archbee.com/api/optimize/SSUUxKZUk9bFTEPNn_6Zo/MioB7wEIZ-oGxWUe608PG_image.png "List of Members dialog box")

If you log in as Bob and try to access the same page as *System/Users/Groups*, you will find that you do not have the necessary access to view the page. This is because Bob has been assigned the Viewers group permissions and does not have the required privileges to view the page.
