You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Apache 2.4(RHEL9)LDAP表单认证失败,咨询do-login.html配置

Apache 2.4 LDAP自定义表单认证跳转异常解决

问题场景

在Red Hat 9.0上部署的Apache 2.4(httpd),原已实现LDAP基础认证,现改为自定义表单认证后,提交登录请求一直跳回login.html,需修正do-login.html相关配置。

现有配置

修改后的私有目录认证配置

<Directory /var/www/html/private>
    AuthType form
    AuthName "Login"
    AuthBasicAuthoritative off
    AuthBasicProvider ldap
    AuthLDAPURL "ldap://DC:389/OU=Users,dc=x,dc=com?sAMAccountName?sub?(objectClass=*)"
    Require valid-user
    AuthLDAPBindDN username
    AuthLDAPBindPassword pAsSwOrD
</Directory>

新增的登录处理配置

<Directory "/do-login.html">
    SetHandler form-login-handler
    AuthFormLoginRequiredLocation "login.html"
    AuthFormLoginSuccessLocation "/admin/index.html"
    AuthFormProvider ldap
    AuthUserFile  /dev/null
    AuthType form
    AuthName "Admin"
    Session On
    SessionCookieName session path=/
</Directory>

自定义登录表单

<form method="POST" action="/do-login.html">
  Username: <input type="text" name="httpd_username" value="" />
  Password: <input type="password" name="httpd_password" value="" />
  <input type="submit" name="login" value="Login" />
</form>

核心问题与修正方案

1. 修正登录处理路径的配置块类型

/do-login.html是单个请求路径而非目录,不能用<Directory>匹配,应改用<Location>:

<Location "/do-login.html">
    SetHandler form-login-handler
    AuthFormLoginRequiredLocation "/login.html"
    AuthFormLoginSuccessLocation "/admin/index.html"
    AuthFormProvider ldap
    AuthType form
    AuthName "Admin"
    # 必须添加LDAP连接配置,否则无法完成账号验证
    AuthLDAPURL "ldap://DC:389/OU=Users,dc=x,dc=com?sAMAccountName?sub?(objectClass=*)"
    AuthLDAPBindDN "username"
    AuthLDAPBindPassword "pAsSwOrD"
    Session On
    SessionCookieName session path=/ secure HttpOnly
</Location>

2. 统一私有目录的认证配置

私有目录配置需简化,移除冗余的基础认证参数,保持与表单认证的一致性:

<Directory /var/www/html/private>
    AuthType form
    AuthName "Admin" # 需与登录处理块的AuthName完全一致
    AuthFormAuthoritative on
    Require valid-user
</Directory>

3. 确保依赖模块已启用

Red Hat 9上需确认以下Apache模块已加载,可在/etc/httpd/conf.modules.d/目录下检查对应配置文件:

  • mod_session.so
  • mod_session_cookie.so
  • mod_authn_form.so
  • mod_auth_form.so
  • mod_ldap.so
  • mod_authnz_ldap.so

若未启用,可通过以下命令添加加载配置:

echo "LoadModule session_module modules/mod_session.so" >> /etc/httpd/conf.modules.d/00-session.conf
echo "LoadModule session_cookie_module modules/mod_session_cookie.so" >> /etc/httpd/conf.modules.d/00-session.conf
echo "LoadModule authn_form_module modules/mod_authn_form.so" >> /etc/httpd/conf.modules.d/00-auth.conf
echo "LoadModule auth_form_module modules/mod_auth_form.so" >> /etc/httpd/conf.modules.d/00-auth.conf

4. 无需创建物理的do-login.html文件

SetHandler form-login-handler会让Apache直接处理该路径的登录请求,无需在文件系统中创建do-login.html实体文件。

验证步骤

  1. 重启Apache服务:systemctl restart httpd
  2. 访问/private路径,应自动跳转到自定义登录表单
  3. 输入正确的LDAP账号密码,应成功跳转至/admin/index.html并正常访问私有目录内容

内容的提问来源于stack exchange,提问作者Roger McCarrick

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 21:47:34