Use STARTTLS on a plain LDAP connection usually on port 389.
Verify the TLS certificate of the server.
This setting activates a LDAP server pool that is persisted between requests.
The user data in this database can be modified from within privacyIDEA.
Enter the base DN for the user groups. Leave this field empty if the groups are located in the same base DN as defined for the users above.
Filter to get the groups of a single user. Possible tags: {base_dn} (from the users), {username}, and all attribute mapping keys.
{base_dn}
{username}
The group attribute defining the group's name, which should be stored in the user info.
The key to store the groups in the user info (attribute mapping key).