Ubuntu 18环境下LDAP客户端无法登录已创建的ldaptest用户的排查咨询及问题解决复盘
Ubuntu 18环境下LDAP客户端无法登录已创建的ldaptest用户的排查咨询及问题解决复盘
最近在学习LDAP,在Ubuntu 18环境下搭好了LDAP服务端,也成功创建了ldaptest用户,但安装客户端后尝试用su ldaptest登录时一直报错:No passwd entry for user 'ldaptest',折腾了一番终于解决,把整个过程记录下来给大家参考。
一、问题场景
我先确认了LDAP服务端的用户是正常创建的,执行ldapsearch -x -LLL -b "dc=myexample,dc=com"能看到ldaptest的完整条目:
dn: dc=myexample,dc=com objectClass: top objectClass: dcObject objectClass: organization o: myexample dc: myexample dn: cn=admin,dc=myexample,dc=com objectClass: simpleSecurityObject objectClass: organizationalRole cn: admin description: LDAP administrator dn: ou=people,dc=myexample,dc=com objectClass: organizationalUnit ou: people dn: ou=groups,dc=myexample,dc=com objectClass: organizationalUnit ou:: Z3JvdXBzIA== dn: uid=ldaptest,ou=people,dc=myexample,dc=com objectClass: inetOrgPerson objectClass: posixAccount objectClass: shadowAccount cn: ldaptest sn: ldaptest loginShell: /bin/bash uidNumber: 2000 gidNumber: 2000 homeDirectory: /home/ldaptest uid: ldaptest dn: cn=ldaptest,ou=groups,dc=myexample,dc=com objectClass: posixGroup cn: ldaptest gidNumber: 2000 memberUid: ldaptest
接着在同一台服务器上安装了LDAP客户端组件:
sudo apt -y install libnss-ldapd libpam-ldapd ldap-utils
但执行su ldaptest时始终报错No passwd entry for user 'ldaptest',怀疑是客户端配置或服务的问题。
二、已验证的配置与服务状态
1. nslcd配置文件(/etc/nslcd.conf)
配置看起来没问题,指定了本地LDAP服务和正确的搜索base:
# /etc/nslcd.conf # nslcd configuration file. See nslcd.conf(5) # for details. # The user and group nslcd should run as. uid nslcd gid nslcd # The location at which the LDAP server(s) should be reachable. uri ldap://localhost/ # The search base that will be used for all queries. base dc=myexample,dc=com # The LDAP protocol version to use. #ldap_version 3 # The DN to bind with for normal lookups. #binddn cn=annonymous,dc=example,dc=net #bindpw secret # The DN used for password modifications by root. #rootpwmoddn cn=admin,dc=example,dc=com # SSL options #ssl off #tls_reqcert never tls_cacertfile /etc/ssl/certs/ca-certificates.crt # The search scope. #scope sub
2. 服务状态检查
- nslcd服务是正常运行的:
systemctl status nslcd.service
输出:
● nslcd.service - LSB: LDAP connection daemon Loaded: loaded (/etc/init.d/nslcd; generated) Active: active (running) since Wed 2023-04-19 18:14:19 JST; 24s ago Docs: man:systemd-sysv-generator(8) Process: 22346 ExecStop=/etc/init.d/nslcd stop (code=exited, status=0/SUCCESS) Process: 22357 ExecStart=/etc/init.d/nslcd start (code=exited, status=0/SUCCESS) Tasks: 6 (limit: 4677) CGroup: /system.slice/nslcd.service └─22392 /usr/sbin/nslcd Apr 19 18:14:19 koala systemd[1]: Starting LSB: LDAP connection daemon... Apr 19 18:14:19 koala nslcd[22357]: * Starting LDAP connection daemon nslcd Apr 19 18:14:19 koala nslcd[22392]: version 0.9.9 starting Apr 19 18:14:19 koala nslcd[22392]: accepting connections Apr 19 18:14:19 koala nslcd[22357]: ...done. Apr 19 18:14:19 koala systemd[1]: Started LSB: LDAP connection daemon.
- slapd服务也正常运行:
systemctl status slapd.service
输出:
● slapd.service - LSB: OpenLDAP standalone server (Lightweight Directory Access Protocol) Loaded: loaded (/etc/init.d/slapd; generated) Drop-In: /lib/systemd/system/slapd.service.d └─slapd-remain-after-exit.conf Active: active (running) since Mon 2023-04-17 19:03:57 JST; 1 day 23h ago Docs: man:systemd-sysv-generator(8) Tasks: 4 (limit: 4677) CGroup: /system.slice/slapd.service └─4458 /usr/sbin/slapd -h ldap:/// ldapi:/// -g openldap -u openldap -F /etc/ldap/slapd.d Apr 17 19:03:57 koala systemd[1]: Starting LSB: OpenLDAP standalone server (Lightweight Directory Access Protocol)... Apr 17 19:03:57 koala slapd[4426]: * Starting OpenLDAP slapd Apr 17 19:03:57 koala slapd[4444]: @(#) $OpenLDAP: slapd (Ubuntu) (May 12 2022 13:52:38) $ Debian OpenLDAP Maintainers <pkg-openldap-devel@lists.alioth.debian.org> Apr 17 19:03:57 koala slapd[4458]: slapd starting Apr 17 19:03:57 koala slapd[4426]: ...done. Apr 17 19:03:57 koala systemd[1]: Started LSB: OpenLDAP standalone server (Lightweight Directory Access Protocol).
三、排查与解决过程
既然服务和配置都没问题,我尝试用getent passwd检查系统能识别的用户列表,发现ldaptest其实已经在列表里了:
ldaptest:x:2000:2000:ldaptest:/home/ldaptest:/bin/bash
这说明系统已经能从LDAP获取到用户信息,但可能是缓存的问题导致su命令没读到最新数据。于是我重启了nscd服务:
systemctl restart nscd.service
再次执行su ldaptest,成功登录,问题解决!
总结
这个问题大概率是nscd(名称服务缓存守护进程)的缓存没有更新,导致系统无法及时读取到LDAP中的用户信息,重启nscd刷新缓存后就能正常识别用户了。
备注:内容来源于stack exchange,提问作者whitebear
相关产品推荐
相关产品推荐

