基于cetic/helm部署的NiFi集群LDAP认证登录失败问题求助
基于cetic/helm部署的NiFi集群LDAP认证登录失败问题求助
我这边用cetic/helm部署了NiFi集群,配置了LDAP认证,但每次用个人账号登录NiFi UI时都会提示“无效用户凭证”,但同样的LDAP参数用ldapsearch却能正常查询到用户信息,实在搞不懂哪里出问题了,麻烦大家帮忙看看!
我的LDAP配置如下:
ldap: enabled: true host: "ldaps://ldaphost.net" searchBase: "ou=People,o=ABC" #CN=Users,DC=ldap,DC=example,DC=be admin: "cn=Keycloak_business_managed_Acc,ou=SystemUsers,ou=Accounts,o=ABC" pass: changeme searchFilter: (objectClass=abcEDPerson, inetorgperson, organizationalPerson, person, top, dspswuser, posixAccount, shadowAccount) userIdentityAttribute: uid authStrategy: SIMPLE # How the connection to the LDAP server is authenticated. Possible values are ANONYMOUS, SIMPLE, LDAPS, or START_TLS. identityStrategy: USE_USERNAME authExpiration: 12 hours userSearchScope: SUBTREE # Search scope for searching users (ONE_LEVEL, OBJECT, or SUBTREE). Required if searching users. groupSearchScope: SUBTREE # Search scope for searching groups (ONE_LEVEL, OBJECT, or SUBTREE). Required if searching groups.
测试情况:
用ldapsearch能正常查到用户:
root@bh-gsn-57-asca-dev-01:~# ldapsearch -h ldaphost.net -D "cn=Keycloak_business_managed_Acc,ou=SystemUsers,ou=Accounts,o=ABC" -w "changeme" -b "ou=people,o=abc" uid=myuserid # extended LDIF # # LDAPv3 # base <ou=people,o=abc> with scope subtree # filter: uid=myuserid # requesting: ALL # # 62XXXXXX, Internal, People, ABC dn: employeeNumber=62XXXXXX,ou=Internal,ou=People,o=ABC displayName: Prabir Choudhury (ABC-D)
我理解admin字段应该填绑定LDAP服务器的Manager DN,pass是对应的密码,所以我填的就是BIND DN和密码,理论上没问题啊...有没有朋友遇到过类似情况?求指点!
备注:内容来源于stack exchange,提问作者Pro
相关产品推荐
相关产品推荐

