PostgreSQL 14配置LDAP认证失败问题排查求助
PostgreSQL LDAP认证配置问题解决
1. 现有pg_hba.conf条目不完整,必须补充LDAP基础配置
你的pg_hba条目缺少关键的LDAP搜索/绑定参数,无法让PostgreSQL正确与AD服务器交互,必须添加对应你的DC=ad,DC=justcomp,DC=com基础DN配置,以下是两种适配你Node.js环境的正确配置:
适配纯用户名登录(推荐)
如果用sAMAccountName(如usersam)作为PostgreSQL登录名,配置如下:
host all all 0.0.0.0/0 ldap ldapserver=111.222.333.44 ldapport=389 ldaptls=1 ldapbasedn="DC=ad,DC=justcomp,DC=com" ldapsearchfilter="(sAMAccountName=%u)"
ldapbasedn:对应你Node.js中的baseDN,指定LDAP搜索的根路径ldapsearchfilter:用AD的sAMAccountName属性匹配登录用户名%u
适配UserPrincipalName登录
如果用usersam@justcomp.com格式登录,配置如下:
host all all 0.0.0.0/0 ldap ldapserver=111.222.333.44 ldapport=389 ldaptls=1 ldapbasedn="DC=ad,DC=justcomp,DC=com" ldapsearchfilter="(userPrincipalName=%u)"
适配域\用户名格式登录
如果要用justcomp\usersam格式登录,需给用户名加引号避免shell转义,pg_hba配置调整为:
host all all 0.0.0.0/0 ldap ldapserver=111.222.333.44 ldapport=389 ldaptls=1 ldapbasedn="DC=ad,DC=justcomp,DC=com" ldapsearchfilter="(sAMAccountName=%~u)"
%~u会自动提取justcomp\usersam中的usersam部分,匹配AD的sAMAccountName
2. 正确的连接命令
- 纯用户名模式:
psql -h 10.11.222.333 -U usersam -d postgres - UserPrincipalName模式:
psql -h 10.11.222.333 -U usersam@justcomp.com -d postgres - 域\用户名模式(注意引号):
psql -h 10.11.222.333 -U "justcomp\usersam" -d postgres
3. 是否需要创建对应数据库角色?
默认需要。LDAP仅负责验证密码合法性,用户必须在PostgreSQL中存在对应登录角色:
- 纯用户名模式:执行
create role usersam with login; - UserPrincipalName模式:执行
create role "usersam@justcomp.com" with login;
若不想逐个创建角色,可配置ldapmapusers参数批量映射,例如:
# 在pg_hba.conf中添加 ldapmapusers="*=ldap_authenticated"
需提前创建ldap_authenticated角色,所有LDAP验证通过的用户都会映射到该角色。
4. 当前认证失败的核心原因
- pg_hba.conf缺少
ldapbasedn和ldapsearchfilter,PostgreSQL无法构造正确的LDAP绑定请求 - 登录用户名格式与pg_hba配置不匹配,导致AD服务器无法识别用户身份
- 配置修改后未重启PostgreSQL服务(若你没执行此操作)
修复步骤
- 按上述需求修改pg_hba.conf配置
- 重启PostgreSQL服务使配置生效
- 创建对应格式的PostgreSQL登录角色
- 使用匹配格式的连接命令登录
内容的提问来源于stack exchange,提问作者usersam
相关产品推荐
相关产品推荐

