# Authelia Active Directory / ADUC migration worksheet # Fill this out locally, then we can use it to update Authelia from LLDAP to AD LDAP. # Do NOT commit this file after adding real passwords or secrets. # Current deployment context AUTHELIA_URL=https://auth.wheelz.lab AUTHELIA_BACKEND_URL=http://192.168.20.5:9091 AUTHELIA_CONFIG_DIR=/mnt/HomeStorage02/Docker/Authelia/config # Active Directory domain AD_DOMAIN_FQDN=local.wheelz.com AD_NETBIOS_DOMAIN=WHEELZ AD_BASE_DN=DC=local,DC=wheelz,DC=com AD_DC_HOSTNAME=WheelzDC01.local.wheelz.com AD_DC_IP=192.168.30.15 # LDAP connection # Start with ldap:// for testing, then move to ldaps:// once CA trust is handled. AD_LDAP_URL=ldap://192.168.30.15:389 # AD_LDAPS_URL=ldaps://WheelzDC01.local.wheelz.com:636 AD_START_TLS=false AD_TLS_SKIP_VERIFY=false # If using LDAPS, provide/export the AD CA root cert path later. AD_CA_CERT_PATH=/config/certs/ad-ca-root.crt # Bind/service account for Authelia LDAP searches # Recommended: create a normal AD user with read/search access only. AD_BIND_USERNAME=svc-authelia@local.wheelz.com AD_BIND_PASSWORD= # Optional DN form if UPN bind does not work: # AD_BIND_DN=CN=svc_authelia_ldap,OU=Service Accounts,DC=local,DC=wheelz,DC=com # User search scope # Broad is easiest. Narrow to an OU later if desired. AD_USERS_BASE_DN=DC=local,DC=wheelz,DC=com # Example narrower value: # AD_USERS_BASE_DN=OU=Users,DC=local,DC=wheelz,DC=com AD_USERS_FILTER=(&({username_attribute}={input})(objectClass=user)(!(userAccountControl:1.2.840.113556.1.4.803:=2))) AD_USERNAME_ATTRIBUTE=sAMAccountName AD_DISPLAY_NAME_ATTRIBUTE=displayName AD_MAIL_ATTRIBUTE=mail # Group search scope AD_GROUPS_BASE_DN=DC=local,DC=wheelz,DC=com # Example narrower value: # AD_GROUPS_BASE_DN=OU=Groups,DC=local,DC=wheelz,DC=com AD_GROUPS_FILTER=(member={dn}) AD_GROUP_NAME_ATTRIBUTE=cn # Authelia AD security groups AD_GROUP_AUTHELIA_ADMINS=Authelia-Admin AD_GROUP_AUTHELIA_FAMILY=Authelia-Family AD_GROUP_AUTHELIA_FRIENDS=Authelia-Friends AD_GROUP_AUTHELIA_GUESTS=Authelia-Guest # First admin user to verify after switching AD_FIRST_ADMIN_USERNAME=wheelz AD_FIRST_ADMIN_UPN=wheelz@local.wheelz.com AD_FIRST_ADMIN_MUST_BE_MEMBER_OF=Authelia-Admin # Network checks needed before changing Authelia # TrueNAS/Authelia container must reach the DC on one of these: # - TCP 389 for LDAP # - TCP 636 for LDAPS LDAP_PORT_TO_TEST=389 # Notes for Wheelz: # 1. Create svc_authelia_ldap in ADUC. # 2. Create security groups: Authelia-Admin, Authelia-Family, Authelia-Guest. # 3. Add your real AD user to Authelia-Admin. # 4. Fill in exact DC hostname, any real OU paths, and the service account password. # 5. Do not paste the real password into Obsidian or commit it to Gitea.