Skip to content

docs(auth): document LDAP OTP/MFA single-bind behavior and configuration - #231

Merged
TheWitness merged 2 commits into
developfrom
docs/ldap-otp-guidance-develop
Sep 30, 2026
Merged

TheWitness merged 2 commits into
developfrom
docs/ldap-otp-guidance-develop

Conversation

@TheWitness

Copy link
Copy Markdown
Member

Summary

Adds a One-Time Passwords (OTP / MFA) note to the LDAP Authentication page documenting how Cacti's LDAP flow behaves with single-use credentials.

Details

Cacti binds the user's password exactly once, during the final authentication step. The DN-resolution phase never uses the user's password:

  • No Searching — no bind during lookup (DN built from the template), then one bind as the user.
  • Anonymous Searching — anonymous bind to locate the DN, then one bind as the user.
  • Specific Searching — service-account bind to locate the DN, then one bind as the user.

Group membership checks reuse the already-bound connection and do not bind again.

The note recommends, for OTP/MFA:

  • Specific Searching with a dedicated service account (Anonymous where the directory permits) so the one-time code is preserved for the single authentication bind, and
  • a single LDAP server (e.g. a load balancer VIP), because multi-server failover re-attempts the bind with an already-consumed OTP.

Companion to the Cacti code PRs Cacti/cacti#8089 (1.2.x) and Cacti/cacti#8090 (develop), and to the 1.2.x docs PR #230.

Adds a One-Time Passwords (OTP / MFA) note to the LDAP authentication page
explaining that Cacti binds the user's password only once, that the DN
lookup never uses the user's password, and that OTP/MFA deployments should
use Specific Searching with a service account and a single server.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Clarify the No Searching recommendation and qualify the single-bind claim for failover.

Review effort: Lite
Findings: 1 Low severity

Open (1)
What changed in this PR

Documents LDAP OTP/MFA single-bind behavior and configuration guidance.

Changes:

  • Explains bind behavior across LDAP search modes.
  • Documents connection reuse for group checks.
  • Recommends service accounts and single-server configurations for OTP/MFA.
File Description
Settings-Auth-LDAP.md Adds LDAP OTP/MFA guidance.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread Settings-Auth-LDAP.md Outdated
…fy single-bind for failover; clarify No Searching
@TheWitness
TheWitness merged commit 5b2763b into develop Sep 30, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants