You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu 18环境下LDAP客户端无法登录已创建的ldaptest用户的排查咨询及问题解决复盘

Ubuntu 18环境下LDAP客户端无法登录已创建的ldaptest用户的排查咨询及问题解决复盘

最近在学习LDAP,在Ubuntu 18环境下搭好了LDAP服务端,也成功创建了ldaptest用户,但安装客户端后尝试用su ldaptest登录时一直报错:No passwd entry for user 'ldaptest',折腾了一番终于解决,把整个过程记录下来给大家参考。

一、问题场景

我先确认了LDAP服务端的用户是正常创建的,执行ldapsearch -x -LLL -b "dc=myexample,dc=com"能看到ldaptest的完整条目:

dn: dc=myexample,dc=com
objectClass: top
objectClass: dcObject
objectClass: organization
o: myexample
dc: myexample

dn: cn=admin,dc=myexample,dc=com
objectClass: simpleSecurityObject
objectClass: organizationalRole
cn: admin
description: LDAP administrator

dn: ou=people,dc=myexample,dc=com
objectClass: organizationalUnit
ou: people

dn: ou=groups,dc=myexample,dc=com
objectClass: organizationalUnit
ou:: Z3JvdXBzIA==

dn: uid=ldaptest,ou=people,dc=myexample,dc=com
objectClass: inetOrgPerson
objectClass: posixAccount
objectClass: shadowAccount
cn: ldaptest
sn: ldaptest
loginShell: /bin/bash
uidNumber: 2000
gidNumber: 2000
homeDirectory: /home/ldaptest
uid: ldaptest

dn: cn=ldaptest,ou=groups,dc=myexample,dc=com
objectClass: posixGroup
cn: ldaptest
gidNumber: 2000
memberUid: ldaptest

接着在同一台服务器上安装了LDAP客户端组件:

sudo apt -y install libnss-ldapd libpam-ldapd ldap-utils

但执行su ldaptest时始终报错No passwd entry for user 'ldaptest',怀疑是客户端配置或服务的问题。

二、已验证的配置与服务状态

1. nslcd配置文件(/etc/nslcd.conf)

配置看起来没问题,指定了本地LDAP服务和正确的搜索base:

# /etc/nslcd.conf
# nslcd configuration file. See nslcd.conf(5)
# for details.

# The user and group nslcd should run as.
uid nslcd
gid nslcd

# The location at which the LDAP server(s) should be reachable.
uri ldap://localhost/

# The search base that will be used for all queries.
base dc=myexample,dc=com

# The LDAP protocol version to use.
#ldap_version 3

# The DN to bind with for normal lookups.
#binddn cn=annonymous,dc=example,dc=net
#bindpw secret

# The DN used for password modifications by root.
#rootpwmoddn cn=admin,dc=example,dc=com

# SSL options
#ssl off
#tls_reqcert never
tls_cacertfile /etc/ssl/certs/ca-certificates.crt

# The search scope.
#scope sub

2. 服务状态检查

  • nslcd服务是正常运行的:
systemctl status nslcd.service

输出:

● nslcd.service - LSB: LDAP connection daemon
Loaded: loaded (/etc/init.d/nslcd; generated)
Active: active (running) since Wed 2023-04-19 18:14:19 JST; 24s ago
Docs: man:systemd-sysv-generator(8)
Process: 22346 ExecStop=/etc/init.d/nslcd stop (code=exited, status=0/SUCCESS)
Process: 22357 ExecStart=/etc/init.d/nslcd start (code=exited, status=0/SUCCESS)
Tasks: 6 (limit: 4677)
CGroup: /system.slice/nslcd.service
└─22392 /usr/sbin/nslcd

Apr 19 18:14:19 koala systemd[1]: Starting LSB: LDAP connection daemon...
Apr 19 18:14:19 koala nslcd[22357]:  * Starting LDAP connection daemon nslcd
Apr 19 18:14:19 koala nslcd[22392]: version 0.9.9 starting
Apr 19 18:14:19 koala nslcd[22392]: accepting connections
Apr 19 18:14:19 koala nslcd[22357]:    ...done.
Apr 19 18:14:19 koala systemd[1]: Started LSB: LDAP connection daemon.
  • slapd服务也正常运行:
systemctl status slapd.service

输出:

● slapd.service - LSB: OpenLDAP standalone server (Lightweight Directory Access Protocol)
Loaded: loaded (/etc/init.d/slapd; generated)
Drop-In: /lib/systemd/system/slapd.service.d
└─slapd-remain-after-exit.conf
Active: active (running) since Mon 2023-04-17 19:03:57 JST; 1 day 23h ago
Docs: man:systemd-sysv-generator(8)
Tasks: 4 (limit: 4677)
CGroup: /system.slice/slapd.service
└─4458 /usr/sbin/slapd -h ldap:/// ldapi:/// -g openldap -u openldap -F /etc/ldap/slapd.d

Apr 17 19:03:57 koala systemd[1]: Starting LSB: OpenLDAP standalone server (Lightweight Directory Access Protocol)...
Apr 17 19:03:57 koala slapd[4426]:  * Starting OpenLDAP slapd
Apr 17 19:03:57 koala slapd[4444]: @(#) $OpenLDAP: slapd  (Ubuntu) (May 12 2022 13:52:38) $
Debian OpenLDAP Maintainers <pkg-openldap-devel@lists.alioth.debian.org>
Apr 17 19:03:57 koala slapd[4458]: slapd starting
Apr 17 19:03:57 koala slapd[4426]:    ...done.
Apr 17 19:03:57 koala systemd[1]: Started LSB: OpenLDAP standalone server (Lightweight Directory Access Protocol).

三、排查与解决过程

既然服务和配置都没问题,我尝试用getent passwd检查系统能识别的用户列表,发现ldaptest其实已经在列表里了:

ldaptest:x:2000:2000:ldaptest:/home/ldaptest:/bin/bash

这说明系统已经能从LDAP获取到用户信息,但可能是缓存的问题导致su命令没读到最新数据。于是我重启了nscd服务:

systemctl restart nscd.service

再次执行su ldaptest,成功登录,问题解决!

总结

这个问题大概率是nscd(名称服务缓存守护进程)的缓存没有更新,导致系统无法及时读取到LDAP中的用户信息,重启nscd刷新缓存后就能正常识别用户了。

备注:内容来源于stack exchange,提问作者whitebear

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.22 15:28:11