Skip to content

Unit 4: Active Directory and LDAP integration #44

@TeoSlayer

Description

@TeoSlayer

Scope

On-premise AD/LDAP integration for enterprises that haven't migrated to cloud identity.

Deliverables

  • AD group membership → Pilot network mapping
  • Kerberos-to-token bridge: service that validates Kerberos tickets and issues short-lived Pilot join tokens
  • LDAP bind verification: simpler alternative for LDAP-only environments
  • AD CS certificate templates: "Pilot Agent" template with Extended Key Usage and SAN fields
  • Bridge service binary: standalone component that connects to AD and issues tokens
  • Setup guide: AD configuration, group policy, certificate template creation

Files

  • cmd/pilot-ad-bridge/ — Kerberos/LDAP bridge service
  • pkg/adbridge/ — AD/LDAP client, token issuance

Priority: MEDIUM

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions