You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于cetic/helm部署的NiFi集群LDAP认证登录失败问题求助

基于cetic/helm部署的NiFi集群LDAP认证登录失败问题求助

我这边用cetic/helm部署了NiFi集群,配置了LDAP认证,但每次用个人账号登录NiFi UI时都会提示“无效用户凭证”,但同样的LDAP参数用ldapsearch却能正常查询到用户信息,实在搞不懂哪里出问题了,麻烦大家帮忙看看!

我的LDAP配置如下:

ldap:
  enabled: true
  host: "ldaps://ldaphost.net"
  searchBase: "ou=People,o=ABC" #CN=Users,DC=ldap,DC=example,DC=be
  admin: "cn=Keycloak_business_managed_Acc,ou=SystemUsers,ou=Accounts,o=ABC"
  pass: changeme
  searchFilter: (objectClass=abcEDPerson, inetorgperson, organizationalPerson, person, top, dspswuser, posixAccount, shadowAccount)
  userIdentityAttribute: uid
  authStrategy: SIMPLE # How the connection to the LDAP server is authenticated. Possible values are ANONYMOUS, SIMPLE, LDAPS, or START_TLS.
  identityStrategy: USE_USERNAME
  authExpiration: 12 hours
  userSearchScope: SUBTREE # Search scope for searching users (ONE_LEVEL, OBJECT, or SUBTREE). Required if searching users.
  groupSearchScope: SUBTREE # Search scope for searching groups (ONE_LEVEL, OBJECT, or SUBTREE). Required if searching groups.

测试情况:

用ldapsearch能正常查到用户:

root@bh-gsn-57-asca-dev-01:~# ldapsearch -h ldaphost.net -D "cn=Keycloak_business_managed_Acc,ou=SystemUsers,ou=Accounts,o=ABC" -w "changeme" -b "ou=people,o=abc" uid=myuserid
# extended LDIF
#
# LDAPv3
# base <ou=people,o=abc> with scope subtree
# filter: uid=myuserid
# requesting: ALL
#
# 62XXXXXX, Internal, People, ABC
dn: employeeNumber=62XXXXXX,ou=Internal,ou=People,o=ABC
displayName: Prabir Choudhury (ABC-D)

我理解admin字段应该填绑定LDAP服务器的Manager DN,pass是对应的密码,所以我填的就是BIND DN和密码,理论上没问题啊...有没有朋友遇到过类似情况?求指点!

备注:内容来源于stack exchange,提问作者Pro

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.23 15:27:47