---
title: Charmhub | Deploy Keystone LDAP integration using Charmhub - The Open Operator
  Collection
description: Deploy the latest version of Keystone LDAP integration on any cloud.
url: https://charmhub.io/keystone-ldap-k8s/configurations
---

# Keystone LDAP integration

[OpenStack Charmers](https://charmhub.io/publisher/openstack-charmers "View all packages from OpenStack Charmers")

* [OpenStack Charmers](https://charmhub.io/publisher/openstack-charmers "View all packages from OpenStack Charmers")

Platform:

24.04

22.04

edge 3

```
juju deploy keystone-ldap-k8s --channel edge
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [domain-name](https://charmhub.io/keystone-ldap-k8s/configurations#domain-name)
* [ldap-config-flags](https://charmhub.io/keystone-ldap-k8s/configurations#ldap-config-flags)
* [tls-ca-ldap](https://charmhub.io/keystone-ldap-k8s/configurations#tls-ca-ldap)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* domain-name | string

  Name of the keystone domain to configure; defaults to the deployed
  application name.
* ldap-config-flags | string

  The are ~50 LDAP configuration options supported by keystone.
  Use a json like string with double quotes
  and braces around all the options and single quotes around complex values.
  "{user\_tree\_dn: 'DC=dc1,DC=ad,DC=example,DC=com',
  user\_allow\_create: False,
  user\_allow\_delete: False}"
  See the README for more details.
* tls-ca-ldap | string

  This option controls which certificate (or a chain) will be used to connect
  to an ldap server(s) over TLS. Certificate contents should be either used
  directly or included via include-file://
  An LDAP url should also be considered as ldaps and StartTLS are both valid
  methods of using TLS (see RFC 4513) with StartTLS using a non-ldaps url which,
  of course, still requires a CA certificate.
