LDAP Operations Performed During Sync

The following LDAP operations are performed during user and group synchronization from any LDAP directory.

  • Bind operation to authenticate clients (and the applications or users behind them) to the LDAP directory server. The LDAP tool supports simple bind authentication, in which the client either binds by providing a Distinguished Name (DN) and a password or anonymously (with an empty bind DN and an empty password). Unauthenticated binds, wherein a DN is provided with an empty password, are also allowed. Simple Authentication and Secure Layer (SASL) bind authentication is not supported.

  • Search operation to retrieve LDAP directory user and group information that matches the provided search criteria. The LDAP tool will perform an LDAP search for each URI specified. The search can be customized using query filters, user and group attributes, and the search base itself.

Last modified: January 21, 2022

Was this article helpful?

Verification instructions

Note: You must install cosign to verify the authenticity of the SingleStore file.

Use the following steps to verify the authenticity of singlestoredb-server, singlestoredb-toolbox, singlestoredb-studio, and singlestore-client SingleStore files that have been downloaded.

You may perform the following steps on any computer that can run cosign, such as the main deployment host of the cluster.

  1. (Optional) Run the following command to view the associated signature files.

    curl undefined
  2. Download the signature file from the SingleStore release server.

    • Option 1: Click the Download Signature button next to the SingleStore file.

    • Option 2: Copy and paste the following URL into the address bar of your browser and save the signature file.

    • Option 3: Run the following command to download the signature file.

      curl -O undefined
  3. After the signature file has been downloaded, run the following command to verify the authenticity of the SingleStore file.

    echo -n undefined |
    cosign verify-blob --certificate-oidc-issuer https://oidc.eks.us-east-1.amazonaws.com/id/CCDCDBA1379A5596AB5B2E46DCA385BC \
    --certificate-identity https://kubernetes.io/namespaces/freya-production/serviceaccounts/job-worker \
    --bundle undefined \
    --new-bundle-format -
    Verified OK