I'm building a simple LDAP flask integrated api, and typically I've seen the pattern of:
# Base
app.config["LDAP_HOST"] = os.getenv("LDAP_HOST")
app.config["LDAP_DOMAIN_NAME"] = os.getenv("LDAP_DOMAIN_NAME")
app.config["LDAP_USERNAME"] = os.getenv("LDAP_USERNAME")
app.config["LDAP_PASSWORD"] = os.getenv("LDAP_PASSWORD")
@auth.verify_password
def verify_password(username, password):
if session.get('username'):
return True
if not username and not password:
return False
try:
# Simple LDAP wrapper
sad = Simple_AD(
server_name = app.config["LDAP_HOST"] ,
# Option 1 - With dedicated service account
username = app.config["LDAP_USERNAME"],
password = app.config["LDAP_PASSWORD"],
# Option 2 - Binding with the user's actual creds provided in the basic auth request itself
username = username
password = password
)
ldap_user = sad.get_aduser(samaccountname=username)
if ldap_user:
session['username'] = username
return True
except:
return False
My question is why do some applications use a dedicated service account when doing the LDAP bind, when I can easily bind with the actual user's provided credentials?
I can understand some edge case limitations like:
- User doesn't have full access to the directory
- AD/LDAP audit logs will show user instead of service account
Besides these minor things, is there a reason to maintain a dedicated username/password JUST for ldap binding itself?
Not having to maintain ANOTHER service account is generally what I'd be after here.
Thanks!