diff --git a/doc/Extensions/Authentication.md b/doc/Extensions/Authentication.md index adafa6526..adb468a51 100644 --- a/doc/Extensions/Authentication.md +++ b/doc/Extensions/Authentication.md @@ -137,6 +137,7 @@ If you set ```$config['auth_ad_require_groupmembership']``` to 1, the authentica > Cleanup of old accounts is done using the authlog. You will need to set the cleanup date for when old accounts will be purged which will happen AUTOMATICALLY. > Please ensure that you set the $config['authlog_purge'] value to be greater than $config['active_directory]['users_purge'] otherwise old users won't be removed. + ##### Sample configuration ``` @@ -144,12 +145,14 @@ $config['auth_ad_url'] = "ldaps://your-domain.controll.er"; $config['auth_ad_check_certificates'] = 1; // or 0 $config['auth_ad_domain'] = "your-domain.com"; $config['auth_ad_base_dn'] = "dc=your-domain,dc=com"; -$config['auth_ad_groups']['admin']['level'] = 10; -$config['auth_ad_groups']['pfy']['level'] = 7; +$config['auth_ad_groups']['']['level'] = 10; +$config['auth_ad_groups']['']['level'] = 7; $config['auth_ad_require_groupmembership'] = 0; $config['active_directory']['users_purge'] = 14;//Purge users who haven't logged in for 14 days. ``` +Replace `` with your Active Directory admin-user group and `` with your standard user group. + #### Radius Authentication Please note that a mysql user is created for each user the logs in successfully. User level 1 is assigned to those accounts so you will then need to assign the relevant permissions unless you set `$config['radius']['userlevel']` to be something other than 1.