You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Shibboleth 5 IdP配置:SP重定向时显示LDAP登录页面的方法

Shibboleth 5 IdP 配置LDAP认证及登录页面显示

Shibboleth 5 放弃了旧版本的JSP登录页面,改用Spring Web Flow + Thymeleaf模板处理认证流程,以下是配置LDAP认证并显示登录页面的具体步骤:

1. 配置LDAP数据源

编辑conf/ldap.properties文件,填入你的OpenLDAP连接信息:

# LDAP服务器地址
idp.authn.LDAP.ldapURL = ldap://localhost:389
# 用户搜索根DN
idp.authn.LDAP.baseDN = dc=your-domain,dc=com
# 用户名匹配过滤规则({user}会被替换为用户输入的账号)
idp.authn.LDAP.userFilter = (uid={user})
# LDAP绑定账号(用于搜索用户)
idp.authn.LDAP.bindDN = cn=admin,dc=your-domain,dc=com
# 绑定账号密码
idp.authn.LDAP.bindDNCredential = your-ldap-admin-password

2. 启用LDAP认证流

编辑conf/authn/general-authn.xml文件:

  • 在<util:list id="shibboleth.AvailableAuthenticationFlows">列表中添加LDAP认证流的配置:
    <bean id="authn/LDAP" parent="shibboleth.AuthenticationFlow"
          p:passiveAuthenticationSupported="true"
          p:forcedAuthenticationSupported="true"
          p:nonBrowserSupported="true"/>
    
  • 修改默认认证流为LDAP,找到<bean id="shibboleth.DefaultAuthenticationFlow"节点,将value值改为authn/LDAP:
    <bean id="shibboleth.DefaultAuthenticationFlow" class="java.lang.String" value="authn/LDAP"/>
    

3. 配置登录视图模板

Shibboleth 5的登录页面模板位于views/login/login.html,无需手动创建JSP:

  • 确认模板中的表单提交路径为${flowExecutionUrl}(Spring Web Flow自动处理认证请求的路径),默认模板已包含该配置:
    <form method="post" action="${flowExecutionUrl}">
        <label for="username">用户名</label>
        <input type="text" id="username" name="j_username" required>
        <label for="password">密码</label>
        <input type="password" id="password" name="j_password" required>
        <button type="submit">登录</button>
    </form>
    
  • 若需自定义页面样式或提示文字,直接修改login.html即可。

4. 启用LDAP认证处理器

编辑conf/authn/ldap-authn-config.xml,确保LDAP认证处理器的bean处于启用状态(默认已配置,可检查是否存在以下内容):

<bean id="authn/LDAP" class="net.shibboleth.idp.authn.impl.LDAPAuthentication"
      p:dataSource-ref="shibboleth.authn.LDAP.dataSource"
      p:principalNameFormatter-ref="shibboleth.authn.LDAP.principalNameFormatter"
      p:errorHandler-ref="shibboleth.authn.LDAP.errorHandler"/>

5. 重启Jetty服务

配置修改完成后,重启Jetty使配置生效:

systemctl restart jetty

验证与排错

  • 访问SP的受保护资源,应被重定向至IdP的login.html页面,输入LDAP合法账号密码后,即可完成认证并跳转回SP获取授权。
  • 若认证失败,查看IdP日志logs/idp-process.log排查问题,常见原因包括:LDAP连接失败、用户条目无uid或userPassword属性、密码加密格式不兼容(需确保userPassword为SSHA/MD5等Shibboleth支持的格式)。

内容的提问来源于stack exchange,提问作者Christopher Biessener

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 16:57:03