# Integrate an LDAP account database with Taiga

**URL:** <https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212>\
**Category:** Third party\
**Tags:** ldap\
**Created:** [September 15, 2022, 9:38pm UTC](https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212 "2022-09-15T21:38:33Z")\
**Posts on this page:** 20\
**Page:** 4

<div class="post-metadata">

**Author:** ![TuringTux](https://dub1.discourse-cdn.com/flex017/user_avatar/community.taiga.io/turingtux/32/309_2.png) [@TuringTux](https://community.taiga.io/u/TuringTux)\
**Post date:** [June 4, 2025, 3:22pm UTC](https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212/61 "2025-06-04T15:22:23Z")

</div>

Yes. Interesting, I do not think the error message is coming from the LDAP plugin (the error messages raised by the plugin should be coming from [this part of the source code](https://github.com/Monogramm/taiga-contrib-ldap-auth-ext/blob/master/taiga_contrib_ldap_auth_ext/connector.py), where I cannot find the “No active account” string).

As your frontend configuration looks intact (i.e., the request body should almost certainly be something like `{"username":"user","password":"pass","type":"ldap"}`, my suspicion is that it is a problem with the backend. To me it feels like the plugin code isn’t even run.

I suspect you included the [`taiga-back` configuration as specified](https://github.com/Monogramm/taiga-contrib-ldap-auth-ext?tab=readme-ov-file#taiga-back-configuration), esp. with a `INSTALLED_APPS += ["taiga_contrib_ldap_auth_ext"]` line?

---

<div class="post-metadata">

**Author:** ![Aukfood](https://dub1.discourse-cdn.com/flex017/user_avatar/community.taiga.io/aukfood/32/4643_2.png) [@Aukfood](https://community.taiga.io/u/Aukfood)\
**Post date:** [June 5, 2025, 8:16am UTC](https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212/62 "2025-06-05T08:16:04Z")

</div>

@TuringTux my config.append.py from custom-back directory

```auto
$ cat config.append.py 
INSTALLED_APPS += ["taiga_contrib_ldap_auth_ext"]

# Multiple LDAP servers are currently not supported, see
# https://github.com/Monogramm/taiga-contrib-ldap-auth-ext/issues/16
LDAP_SERVER = "ldap://url"
LDAP_PORT = 389

LDAP_BIND_DN = "CN= *******"
LDAP_BIND_PASSWORD = "pass"

LDAP_SEARCH_BASE = 'OU=Utilisateurs, ****'

LDAP_USERNAME_ATTRIBUTE = "cn"
LDAP_EMAIL_ATTRIBUTE = "mail"
LDAP_FULL_NAME_ATTRIBUTE = "givenName"

LDAP_SAVE_LOGIN_PASSWORD = False

LDAP_MAP_USERNAME_TO_UID = True

```

---

<div class="post-metadata">

**Author:** ![TuringTux](https://dub1.discourse-cdn.com/flex017/user_avatar/community.taiga.io/turingtux/32/309_2.png) [@TuringTux](https://community.taiga.io/u/TuringTux)\
**Post date:** [June 5, 2025, 9:07am UTC](https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212/63 "2025-06-05T09:07:28Z")

</div>

Oh, I think I have found the problem then:

**`LDAP_MAP_USERNAME_TO_UID = True` will never work. This property has to be set to a function or `None`**.

Try replacing the last line with:

```auto
LDAP_MAP_USERNAME_TO_UID = None

```

## Detailed explanation

See also: [README, section “Additional configuration options”](https://github.com/Monogramm/taiga-contrib-ldap-auth-ext?tab=readme-ov-file#additional-configuration-options)

This configuration option can be used to specify a custom [`SLUGIFY` function](https://github.com/Monogramm/taiga-contrib-ldap-auth-ext/blob/7806e5b623b050f77c66e4167dd7377c79433f30/taiga_contrib_ldap_auth_ext/services.py#L30). This is used [to determine the username the user should have in Taiga from the LDAP username](https://github.com/Monogramm/taiga-contrib-ldap-auth-ext/blob/7806e5b623b050f77c66e4167dd7377c79433f30/taiga_contrib_ldap_auth_ext/services.py#L99). Most setups don’t need to use a `SLUGIFY` function. For this, the `LDAP_MAP_USERNAME_TO_UID` attribute has to be present in the configuration, but set to something falsy (e.g. `None`)

---

<div class="post-metadata">

**Author:** ![Aukfood](https://dub1.discourse-cdn.com/flex017/user_avatar/community.taiga.io/aukfood/32/4643_2.png) [@Aukfood](https://community.taiga.io/u/Aukfood)\
**Post date:** [June 5, 2025, 9:19am UTC](https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212/64 "2025-06-05T09:19:38Z")

</div>

@TuringTux I change it yesterday but result is same

---

<div class="post-metadata">

**Author:** ![TuringTux](https://dub1.discourse-cdn.com/flex017/user_avatar/community.taiga.io/turingtux/32/309_2.png) [@TuringTux](https://community.taiga.io/u/TuringTux)\
**Post date:** [June 5, 2025, 9:20am UTC](https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212/65 "2025-06-05T09:20:48Z")

</div>

Oh, disappointing. Still, please leave it at `LDAP_MAP_USERNAME_TO_UID = None` for all further debugging, because with the other option, it will not work.

Was the server response you provided me with the parameter set to `None`, or to `True`?

And: Could you please also check that the contents from `config.append.py` have actually made it to the Docker container you are running, e.g., using this command?

```auto
docker exec -it taiga-taiga-back-1 cat /taiga-back/settings/config.py

```

---

<div class="post-metadata">

**Author:** ![Aukfood](https://dub1.discourse-cdn.com/flex017/user_avatar/community.taiga.io/aukfood/32/4643_2.png) [@Aukfood](https://community.taiga.io/u/Aukfood)\
**Post date:** [June 6, 2025, 5:02am UTC](https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212/66 "2025-06-06T05:02:51Z")

</div>

> [@TuringTux](#):
>
> `docker exec -it taiga-taiga-back-1 cat /taiga-back/settings/config.py`

The complete file config.py 🙂

> WARN[0000] /home/taiga/preprod/docker-compose.yml: the attribute `version` is obsolete, it will be ignored, please remove it to avoid potential confusion

# -_- coding: utf-8 -_-

# This Source Code Form is subject to the terms of the Mozilla Public

# License, v. 2.0. If a copy of the MPL was not distributed with this

# file, You can obtain one at [Mozilla Public License, version 2.0](http://mozilla.org/MPL/2.0/).

# 

# Copyright (c) 2021-present Kaleidos INC

from .common import \*  
import os

#########################################

## GENERIC

#########################################

DEBUG = os.getenv(‘DEBUG’, ‘False’) == ‘True’

DATABASES = {  
‘default’: {  
‘ENGINE’: ‘django.db.backends.postgresql’,  
‘NAME’: os.getenv(‘POSTGRES\_DB’),  
‘USER’: os.getenv(‘POSTGRES\_USER’),  
‘PASSWORD’: os.getenv(‘POSTGRES\_PASSWORD’),  
‘HOST’: os.getenv(‘POSTGRES\_HOST’),  
‘PORT’: os.getenv(‘POSTGRES\_PORT’,‘5432’),  
‘OPTIONS’: {‘sslmode’: os.getenv(‘POSTGRES\_SSLMODE’,‘disable’)},  
‘DISABLE\_SERVER\_SIDE\_CURSORS’: os.getenv(‘POSTGRES\_DISABLE\_SERVER\_SIDE\_CURSORS’, ‘False’) == ‘True’,  
}  
}  
SECRET\_KEY = os.getenv(‘TAIGA\_SECRET\_KEY’)

TAIGA\_SITES\_SCHEME = os.getenv(‘TAIGA\_SITES\_SCHEME’)  
TAIGA\_SITES\_DOMAIN = os.getenv(‘TAIGA\_SITES\_DOMAIN’)  
FORCE\_SCRIPT\_NAME = os.getenv(‘TAIGA\_SUBPATH’, ‘’)

TAIGA\_URL = f"{ TAIGA\_SITES\_SCHEME }://{ TAIGA\_SITES\_DOMAIN }{ FORCE\_SCRIPT\_NAME }"  
SITES = {  
“api”: { “name”: “api”, “scheme”: TAIGA\_SITES\_SCHEME, “domain”: TAIGA\_SITES\_DOMAIN },  
“front”: { “name”: “front”, “scheme”: TAIGA\_SITES\_SCHEME, “domain”: f"{ TAIGA\_SITES\_DOMAIN }{ FORCE\_SCRIPT\_NAME }" }  
}

LANGUAGE\_CODE = os.getenv(“LANGUAGE\_CODE”, “en-us”)

INSTANCE\_TYPE = “D”

WEBHOOKS\_ENABLED = os.getenv(‘WEBHOOKS\_ENABLED’, ‘True’) == ‘True’  
WEBHOOKS\_ALLOW\_PRIVATE\_ADDRESS = os.getenv(‘WEBHOOKS\_ALLOW\_PRIVATE\_ADDRESS’, ‘False’) == ‘True’  
WEBHOOKS\_ALLOW\_REDIRECTS = os.getenv(‘WEBHOOKS\_ALLOW\_REDIRECTS’, ‘False’) == ‘True’

# Setting DEFAULT\_PROJECT\_SLUG\_PREFIX to false

# removes the username from project slug

DEFAULT\_PROJECT\_SLUG\_PREFIX = os.getenv(‘DEFAULT\_PROJECT\_SLUG\_PREFIX’, ‘False’) == ‘True’

#########################################

## MEDIA

#########################################  
MEDIA\_URL = f"{ TAIGA\_URL }/media/"  
DEFAULT\_FILE\_STORAGE = “taiga\_contrib\_protected.storage.ProtectedFileSystemStorage”  
THUMBNAIL\_DEFAULT\_STORAGE = DEFAULT\_FILE\_STORAGE

STATIC\_URL = f"{ TAIGA\_URL }/static/"

#########################################

## EMAIL

#########################################

EMAIL\_BACKEND = os.getenv(‘EMAIL\_BACKEND’, ‘django.core.mail.backends.console.EmailBackend’)  
CHANGE\_NOTIFICATIONS\_MIN\_INTERVAL = 120 # seconds

DEFAULT\_FROM\_EMAIL = os.getenv(‘DEFAULT\_FROM\_EMAIL’, ‘system@taiga.io’)  
EMAIL\_USE\_TLS = os.getenv(‘EMAIL\_USE\_TLS’, ‘False’) == ‘True’  
EMAIL\_USE\_SSL = os.getenv(‘EMAIL\_USE\_SSL’, ‘False’) == ‘True’  
EMAIL\_HOST = os.getenv(‘EMAIL\_HOST’, ‘localhost’)  
EMAIL\_PORT = os.getenv(‘EMAIL\_PORT’, 587)  
EMAIL\_HOST\_USER = os.getenv(‘EMAIL\_HOST\_USER’, ‘user’)  
EMAIL\_HOST\_PASSWORD = os.getenv(‘EMAIL\_HOST\_PASSWORD’, ‘password’)

#########################################

## SESSION

#########################################  
SESSION\_COOKIE\_SECURE = os.getenv(‘SESSION\_COOKIE\_SECURE’, ‘True’) == ‘True’  
CSRF\_COOKIE\_SECURE = os.getenv(‘CSRF\_COOKIE\_SECURE’, ‘True’) == ‘True’

#########################################

## EVENTS

#########################################  
EVENTS\_PUSH\_BACKEND = “taiga.events.backends.rabbitmq.EventsPushBackend”

EVENTS\_PUSH\_BACKEND\_URL = os.getenv(‘EVENTS\_PUSH\_BACKEND\_URL’)  
if not EVENTS\_PUSH\_BACKEND\_URL:  
EVENTS\_PUSH\_BACKEND\_URL = f"amqp://{ os.getenv(‘RABBITMQ\_USER’) }:{ os.getenv(‘RABBITMQ\_PASS’) }@{ os.getenv(‘TAIGA\_EVENTS\_RABBITMQ\_HOST’, ‘taiga-events-rabbitmq’) }:5672/taiga"

EVENTS\_PUSH\_BACKEND\_OPTIONS = {  
“url”: EVENTS\_PUSH\_BACKEND\_URL  
}

#########################################

## TAIGA ASYNC

#########################################  
CELERY\_ENABLED = os.getenv(‘CELERY\_ENABLED’, ‘True’) == ‘True’  
from kombu import Queue # noqa

CELERY\_BROKER\_URL = os.getenv(‘CELERY\_BROKER\_URL’)  
if not CELERY\_BROKER\_URL:  
CELERY\_BROKER\_URL = f"amqp://{ os.getenv(‘RABBITMQ\_USER’) }:{ os.getenv(‘RABBITMQ\_PASS’) }@{ os.getenv(‘TAIGA\_ASYNC\_RABBITMQ\_HOST’, ‘taiga-async-rabbitmq’) }:5672/taiga"

CELERY\_RESULT\_BACKEND = None # for a general installation, we don’t need to store the results  
CELERY\_ACCEPT\_CONTENT = [‘pickle’,] # Values are ‘pickle’, ‘json’, ‘msgpack’ and ‘yaml’  
CELERY\_TASK\_SERIALIZER = “pickle”  
CELERY\_RESULT\_SERIALIZER = “pickle”  
CELERY\_TIMEZONE = os.getenv(‘CELERY\_TIMEZONE’, ‘Europe/Madrid’)  
CELERY\_TASK\_DEFAULT\_QUEUE = ‘tasks’  
CELERY\_QUEUES = (  
Queue(‘tasks’, routing\_key=‘task.#’),  
Queue(‘transient’, routing\_key=‘transient.#’, delivery\_mode=1)  
)  
CELERY\_TASK\_DEFAULT\_EXCHANGE = ‘tasks’  
CELERY\_TASK\_DEFAULT\_EXCHANGE\_TYPE = ‘topic’  
CELERY\_TASK\_DEFAULT\_ROUTING\_KEY = ‘task.default’

#########################################

## REGISTRATION

#########################################  
PUBLIC\_REGISTER\_ENABLED = os.getenv(‘PUBLIC\_REGISTER\_ENABLED’, ‘False’) == ‘True’

#########################################

## CONTRIBS

#########################################

# SLACK

ENABLE\_SLACK = os.getenv(‘ENABLE\_SLACK’, ‘False’) == ‘True’  
if ENABLE\_SLACK:  
INSTALLED\_APPS += [  
“taiga\_contrib\_slack”  
]

# GITHUB AUTH

# WARNING: If PUBLIC\_REGISTER\_ENABLED == False, currently Taiga by default prevents the OAuth

# buttons to appear for both login and register

ENABLE\_GITHUB\_AUTH = os.getenv(‘ENABLE\_GITHUB\_AUTH’, ‘False’) == ‘True’  
if PUBLIC\_REGISTER\_ENABLED and ENABLE\_GITHUB\_AUTH:  
INSTALLED\_APPS += [  
“taiga\_contrib\_github\_auth”  
]  
GITHUB\_API\_CLIENT\_ID = os.getenv(‘GITHUB\_API\_CLIENT\_ID’)  
GITHUB\_API\_CLIENT\_SECRET = os.getenv(‘GITHUB\_API\_CLIENT\_SECRET’)

# GITLAB AUTH

# WARNING: If PUBLIC\_REGISTER\_ENABLED == False, currently Taiga by default prevents the OAuth

# buttons to appear for both login and register

ENABLE\_GITLAB\_AUTH = os.getenv(‘ENABLE\_GITLAB\_AUTH’, ‘False’) == ‘True’  
if PUBLIC\_REGISTER\_ENABLED and ENABLE\_GITLAB\_AUTH:  
INSTALLED\_APPS += [  
“taiga\_contrib\_gitlab\_auth”  
]  
GITLAB\_API\_CLIENT\_ID = os.getenv(‘GITLAB\_API\_CLIENT\_ID’)  
GITLAB\_API\_CLIENT\_SECRET = os.getenv(‘GITLAB\_API\_CLIENT\_SECRET’)  
GITLAB\_URL = os.getenv(‘GITLAB\_URL’)

#########################################

## TELEMETRY

#########################################  
ENABLE\_TELEMETRY = os.getenv(‘ENABLE\_TELEMETRY’, ‘True’) == ‘True’

#########################################

## IMPORTERS

#########################################  
ENABLE\_GITHUB\_IMPORTER = os.getenv(‘ENABLE\_GITHUB\_IMPORTER’, ‘False’) == ‘True’  
if ENABLE\_GITHUB\_IMPORTER:  
IMPORTERS[“github”] = {  
“active”: True,  
“client\_id”: os.getenv(‘GITHUB\_IMPORTER\_CLIENT\_ID’),  
“client\_secret”: os.getenv(‘GITHUB\_IMPORTER\_CLIENT\_SECRET’)  
}

ENABLE\_JIRA\_IMPORTER = os.getenv(‘ENABLE\_JIRA\_IMPORTER’, ‘False’) == ‘True’  
if ENABLE\_JIRA\_IMPORTER:  
IMPORTERS[“jira”] = {  
“active”: True,  
“consumer\_key”: os.getenv(‘JIRA\_IMPORTER\_CONSUMER\_KEY’),  
“cert”: os.getenv(‘JIRA\_IMPORTER\_CERT’),  
“pub\_cert”: os.getenv(‘JIRA\_IMPORTER\_PUB\_CERT’)  
}

ENABLE\_TRELLO\_IMPORTER = os.getenv(‘ENABLE\_TRELLO\_IMPORTER’, ‘False’) == ‘True’  
if ENABLE\_TRELLO\_IMPORTER:  
IMPORTERS[“trello”] = {  
“active”: True,  
“api\_key”: os.getenv(‘TRELLO\_IMPORTER\_API\_KEY’),  
“secret\_key”: os.getenv(‘TRELLO\_IMPORTER\_SECRET\_KEY’)  
}  
INSTALLED\_APPS += [“taiga\_contrib\_ldap\_auth\_ext”]

# Multiple LDAP servers are currently not supported, see

LDAP\_SERVER = “ldap://URLDAP”  
LDAP\_PORT = 389

LDAP\_BIND\_DN = “mydn”  
LDAP\_BIND\_PASSWORD = “password”

LDAP\_SEARCH\_BASE = ‘OU=Utilisateurs,\*\*\*\*’

LDAP\_USERNAME\_ATTRIBUTE = “cn”  
LDAP\_EMAIL\_ATTRIBUTE = “mail”  
LDAP\_FULL\_NAME\_ATTRIBUTE = “givenName”

LDAP\_SAVE\_LOGIN\_PASSWORD = False

LDAP\_MAP\_USERNAME\_TO\_UID = None

---

<div class="post-metadata">

**Author:** ![Aukfood](https://dub1.discourse-cdn.com/flex017/user_avatar/community.taiga.io/aukfood/32/4643_2.png) [@Aukfood](https://community.taiga.io/u/Aukfood)\
**Post date:** [June 10, 2025, 9:16am UTC](https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212/67 "2025-06-10T09:16:48Z")

</div>

@TuringTux Could this be an ssl certificate problem between the gateway and the front end? This installation uses self-signed SSL certificates.  
I just did a test with the python script provided here “[https://community.taiga.io/t/taiga-6-ldap-accounts-are-not-created/3497”](https://community.taiga.io/t/taiga-6-ldap-accounts-are-not-created/3497%E2%80%9D) and here’s the error I got:

```auto
requests.exceptions.SSLError: HTTPSConnectionPool(host='myurl', port=443): Max retries exceeded with url: /api/v1/auth (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get local issuer certificate (_ssl.c:1000)'))))

```

Is this possible? How can I test by ignoring the ssl certificate (with the disable SSL verification script)?

Tr

---

<div class="post-metadata">

**Author:** ![TuringTux](https://dub1.discourse-cdn.com/flex017/user_avatar/community.taiga.io/turingtux/32/309_2.png) [@TuringTux](https://community.taiga.io/u/TuringTux)\
**Post date:** [June 10, 2025, 7:40pm UTC](https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212/68 "2025-06-10T19:40:14Z")

</div>

Not sure. If you can access the Taiga instance in the browser, and also see that you can send and receive to and from the API (which you proved by posting the network inspector screenshots), then the [script provided in my other answer](https://community.taiga.io/t/taiga-6-ldap-accounts-are-not-created/3497/2) should not give you any further information.

The next thing I would try is jumping into the backend container again and see if you can temporarily install `ldapsearch` there and execute a query against the LDAP server.

If it works, this means the problem must indeed be the LDAP plugin. If it does not work, likely something else is afoul with the communication.

# Test LDAP connection using base `ldap-utils`

1. Enter the container:

2. Install `ldap-utils`:

3. Start LDAP search:

4. Enter bind password:

5. Check exit status

The exit status should be `0` (success). If not, this means that not even Linux standard utilities can access the LDAP server from the backend container.

---

<div class="post-metadata">

**Author:** ![Aukfood](https://dub1.discourse-cdn.com/flex017/user_avatar/community.taiga.io/aukfood/32/4643_2.png) [@Aukfood](https://community.taiga.io/u/Aukfood)\
**Post date:** [June 11, 2025, 8:54am UTC](https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212/69 "2025-06-11T08:54:48Z")

</div>

@TuringTux I could request LDAP from backend container but result is not 0

> ldapsearch -H ldap://LDAPURL -x -b ‘Ou=Utilisateurs,DC=\*\*\*\*’ -W -D ‘CN=\*\*\*\*\*’
> 
> # numResponses: 3001
> 
> # numEntries: 3000
> 
> root@bd4a9c3359a8:/taiga-back# echo $?  
> 4

---

<div class="post-metadata">

**Author:** ![Aukfood](https://dub1.discourse-cdn.com/flex017/user_avatar/community.taiga.io/aukfood/32/4643_2.png) [@Aukfood](https://community.taiga.io/u/Aukfood)\
**Post date:** [June 17, 2025, 2:18pm UTC](https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212/70 "2025-06-17T14:18:07Z")

</div>

@TuringTux no other idea ?

---

<div class="post-metadata">

**Author:** ![TuringTux](https://dub1.discourse-cdn.com/flex017/user_avatar/community.taiga.io/turingtux/32/309_2.png) [@TuringTux](https://community.taiga.io/u/TuringTux)\
**Post date:** [June 18, 2025, 9:23am UTC](https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212/71 "2025-06-18T09:23:31Z")

</div>

I am afraid currently not. A result code of 4 for the LDAP command is okay, I believe, that is just “truncated output due to length”, so that would be fine.

If you can contact the LDAP server from within the backend container, I see no reason why the plugin should be unable to do the same, so I fear this problem is beyond my comprehension, sorry.

---

<div class="post-metadata">

**Author:** ![Aukfood](https://dub1.discourse-cdn.com/flex017/user_avatar/community.taiga.io/aukfood/32/4643_2.png) [@Aukfood](https://community.taiga.io/u/Aukfood)\
**Post date:** [June 18, 2025, 2:19pm UTC](https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212/72 "2025-06-18T14:19:49Z")

</div>

It is possible to create a traceback from the application which could trace actions from frontend to authentication ? A super debug mode ?

---

<div class="post-metadata">

**Author:** ![TuringTux](https://dub1.discourse-cdn.com/flex017/user_avatar/community.taiga.io/turingtux/32/309_2.png) [@TuringTux](https://community.taiga.io/u/TuringTux)\
**Post date:** [June 18, 2025, 7:10pm UTC](https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212/73 "2025-06-18T19:10:36Z")

</div>

Might be. I always want to add more logging and debugging capabilities to the plugin, but I never get around to it, I am afraid.

Maybe this will happen some time in the future, time permitting, but currently it looks rather bleak. I am really sorry, I wish I could be of more help here.

---

<div class="post-metadata">

**Author:** ![Aukfood](https://dub1.discourse-cdn.com/flex017/user_avatar/community.taiga.io/aukfood/32/4643_2.png) [@Aukfood](https://community.taiga.io/u/Aukfood)\
**Post date:** [June 27, 2025, 10:13am UTC](https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212/74 "2025-06-27T10:13:47Z")

</div>

Do you sync there is other solutions ?

- another ad/ldap plugin ?
- sync users from ldap to taiga ?

---

<div class="post-metadata">

**Author:** ![TuringTux](https://dub1.discourse-cdn.com/flex017/user_avatar/community.taiga.io/turingtux/32/309_2.png) [@TuringTux](https://community.taiga.io/u/TuringTux)\
**Post date:** [June 27, 2025, 12:29pm UTC](https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212/75 "2025-06-27T12:29:13Z")

</div>

I don’t think there currently is another implementation of this. Especially because the present plugin does seem to work in some contexts (e.g. for the installation I am administering).

Syncing users might work, although I also don’t know if there is any pre-existing solution for that.

---

<div class="post-metadata">

**Author:** ![TuringTux](https://dub1.discourse-cdn.com/flex017/user_avatar/community.taiga.io/turingtux/32/309_2.png) [@TuringTux](https://community.taiga.io/u/TuringTux)\
**Post date:** [October 25, 2025, 10:52am UTC](https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212/76 "2025-10-25T10:52:14Z")

</div>

🎉

**I am happy to announce that my fork of the LDAP auth plugin is now available on PyPI: [📦 `taiga-contrib-ldap-auth-enhanced`](https://pypi.org/project/taiga-contrib-ldap-auth-enhanced/)**

Compared to the Monogramm plugin, this plugin has the ability to use LDAP self-bind (i.e., you don’t need to use a dedicated bind user, but can use the credentials of the user who tries to log in to contact the database) and somewhat better error messages.

In the future, I also hope to provide faster updates and maybe more debug logging in this repo.

## Change to `taiga-contrib-ldap-auth-enhanced`

You can of course continue to use the Monogramm plugin, it is perfectly fine. However, if you want to use the self-bind feature (and maybe other, future updates), you can change your setup like this.

In `custom-back/Dockerfile`, replace:

```Dockerfile
RUN pip install taiga-contrib-ldap-auth-ext

```

with

```Dockerfile
RUN pip install taiga-contrib-ldap-auth-enhanced

```

In `custom-back/config.append.py`, replace:

```py
INSTALLED_APPS += ["taiga_contrib_ldap_auth_ext"]

```

with

```py
INSTALLED_APPS += ["taiga_contrib_ldap_auth_enhanced"]

```

The update instructions and links in the first post have been adjusted accordingly.

---

<div class="post-metadata">

**Author:** ![Zohaib09](https://avatars.discourse-cdn.com/v4/letter/z/b782af/32.png) [@Zohaib09](https://community.taiga.io/u/Zohaib09)\
**Post date:** [October 29, 2025, 9:46am UTC](https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212/77 "2025-10-29T09:46:33Z")

</div>

Sir i appreciate your efforts

---

<div class="post-metadata">

**Author:** ![Zohaib09](https://avatars.discourse-cdn.com/v4/letter/z/b782af/32.png) [@Zohaib09](https://community.taiga.io/u/Zohaib09)\
**Post date:** [April 30, 2026, 3:44pm UTC](https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212/78 "2026-04-30T15:44:37Z")

</div>

Sir I have setup again latest ldap and i am trying to integrate it with ldap. I have done it before, but this time it not logging any error. But also do not allow me to login

I have installed it with your latest instruction i am using it without docker

INSTALLED\_APPS += [“taiga\_contrib\_ldap\_auth\_enhanced”]  
LDAP\_SERVER = “ldap://sso.domain.com”  
LDAP\_PORT = 389  
LDAP\_START\_TLS = True  
LDAP\_BIND\_DN = “CN=admin,DC=domain,DC=com”  
LDAP\_BIND\_PASSWORD = “mypass”  
LDAP\_SEARCH\_BASE = ‘OU=people,DC=domain,DC=com’  
LDAP\_USERNAME\_ATTRIBUTE = “uid”  
LDAP\_EMAIL\_ATTRIBUTE = “mail”  
LDAP\_FULL\_NAME\_ATTRIBUTE = “cn”  
LDAP\_SAVE\_LOGIN\_PASSWORD = False  
LDAP\_MAP\_USERNAME\_TO\_UID = None

can you please advise? @TuringTux

---

<div class="post-metadata">

**Author:** ![TuringTux](https://dub1.discourse-cdn.com/flex017/user_avatar/community.taiga.io/turingtux/32/309_2.png) [@TuringTux](https://community.taiga.io/u/TuringTux)\
**Post date:** [April 30, 2026, 6:13pm UTC](https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212/79 "2026-04-30T18:13:29Z")

</div>

Hi @Zohaib09, nice hearing from you again!

What does the response say as recorded by your browsers networking tools (go to the login page, press Ctrl+Shift+I, switch to the “Network” tab, and then enter your credentials and press login)?

The response should be a JSON object with a more detailed error message, if you send me this, I might be able to help.

---

<div class="post-metadata">

**Author:** ![Zohaib09](https://avatars.discourse-cdn.com/v4/letter/z/b782af/32.png) [@Zohaib09](https://community.taiga.io/u/Zohaib09)\
**Post date:** [April 30, 2026, 7:14pm UTC](https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212/80 "2026-04-30T19:14:05Z")

</div>

Thanks a lot sir,

this is response when i entered credentials

 ![image](https://europe1.discourse-cdn.com/flex017/uploads/taiga/original/2X/9/94bded12b887804f351612cbd35c10cdae800555.png)

[Previous page](https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212.md?page=3)

[Next page](https://community.taiga.io/t/integrate-an-ldap-account-database-with-taiga/212.md?page=5)
