Shibboleth 5 IdP配置:SP重定向时显示LDAP登录页面的方法
Shibboleth 5 IdP 配置LDAP认证及登录页面显示
Shibboleth 5 放弃了旧版本的JSP登录页面,改用Spring Web Flow + Thymeleaf模板处理认证流程,以下是配置LDAP认证并显示登录页面的具体步骤:
1. 配置LDAP数据源
编辑conf/ldap.properties文件,填入你的OpenLDAP连接信息:
# LDAP服务器地址 idp.authn.LDAP.ldapURL = ldap://localhost:389 # 用户搜索根DN idp.authn.LDAP.baseDN = dc=your-domain,dc=com # 用户名匹配过滤规则({user}会被替换为用户输入的账号) idp.authn.LDAP.userFilter = (uid={user}) # LDAP绑定账号(用于搜索用户) idp.authn.LDAP.bindDN = cn=admin,dc=your-domain,dc=com # 绑定账号密码 idp.authn.LDAP.bindDNCredential = your-ldap-admin-password
2. 启用LDAP认证流
编辑conf/authn/general-authn.xml文件:
- 在
<util:list id="shibboleth.AvailableAuthenticationFlows">列表中添加LDAP认证流的配置:<bean id="authn/LDAP" parent="shibboleth.AuthenticationFlow" p:passiveAuthenticationSupported="true" p:forcedAuthenticationSupported="true" p:nonBrowserSupported="true"/> - 修改默认认证流为LDAP,找到
<bean id="shibboleth.DefaultAuthenticationFlow"节点,将value值改为authn/LDAP:<bean id="shibboleth.DefaultAuthenticationFlow" class="java.lang.String" value="authn/LDAP"/>
3. 配置登录视图模板
Shibboleth 5的登录页面模板位于views/login/login.html,无需手动创建JSP:
- 确认模板中的表单提交路径为
${flowExecutionUrl}(Spring Web Flow自动处理认证请求的路径),默认模板已包含该配置:<form method="post" action="${flowExecutionUrl}"> <label for="username">用户名</label> <input type="text" id="username" name="j_username" required> <label for="password">密码</label> <input type="password" id="password" name="j_password" required> <button type="submit">登录</button> </form> - 若需自定义页面样式或提示文字,直接修改
login.html即可。
4. 启用LDAP认证处理器
编辑conf/authn/ldap-authn-config.xml,确保LDAP认证处理器的bean处于启用状态(默认已配置,可检查是否存在以下内容):
<bean id="authn/LDAP" class="net.shibboleth.idp.authn.impl.LDAPAuthentication" p:dataSource-ref="shibboleth.authn.LDAP.dataSource" p:principalNameFormatter-ref="shibboleth.authn.LDAP.principalNameFormatter" p:errorHandler-ref="shibboleth.authn.LDAP.errorHandler"/>
5. 重启Jetty服务
配置修改完成后,重启Jetty使配置生效:
systemctl restart jetty
验证与排错
- 访问SP的受保护资源,应被重定向至IdP的
login.html页面,输入LDAP合法账号密码后,即可完成认证并跳转回SP获取授权。 - 若认证失败,查看IdP日志
logs/idp-process.log排查问题,常见原因包括:LDAP连接失败、用户条目无uid或userPassword属性、密码加密格式不兼容(需确保userPassword为SSHA/MD5等Shibboleth支持的格式)。
内容的提问来源于stack exchange,提问作者Christopher Biessener
相关产品推荐
相关产品推荐

