Laravel 基于Ldaprecord连接本地OpenLDAP:连接测试成功但登录验证失败问题求助
It’s frustrating when your LDAP connection tests pass but login fails—let’s walk through the most common fixes for your setup:
1. Stop Using Anonymous Bind for Authentication
Your .env has LDAP_USERNAME and LDAP_PASSWORD set to null, which means Laravel is trying to bind anonymously. Most self-hosted OpenLDAP instances either block anonymous access entirely or restrict anonymous users from reading sensitive attributes like userPassword (required for authentication).
Fix:
- Create a dedicated service account in OpenLDAP (e.g.,
cn=ldap-service,dc=example,dc=com) with permissions to read user entries. - Update your
.envwith this account’s credentials:LDAP_USERNAME="cn=ldap-service,dc=example,dc=com" LDAP_PASSWORD="your-service-account-password"
2. Verify User DN Construction
Laravel LDAP needs to build the correct Distinguished Name (DN) for your user to authenticate them. If it’s using the wrong attribute to look up the user, the bind will fail even if the password is correct.
Check & Fix:
- Open
config/ldap.phpand navigate to theconnections.default.userssection. Ensure thekeymatches the unique attribute you’re using for login (e.g.,uidfor usernames,mailfor emails):'users' => [ 'object_classes' => ['inetOrgPerson', 'posixAccount'], 'key' => 'uid', // Match this to your user's login attribute ], - Test the user’s DN manually with the
ldapsearchcommand (replaceyour-usernamewith your actual user):
If this returns a valid DN (likeldapsearch -x -H ldap://127.0.0.1:10389 -b dc=example,dc=com "(uid=your-username)" dnuid=your-username,dc=example,dc=com), your lookup logic is correct.
3. Ensure User Passwords Are Stored in the Right Format
OpenLDAP won’t accept plaintext passwords for authentication—they need to be hashed in a supported format (like SSHA, MD5, or SHA-256). If you created your user with a plaintext password, that’s almost certainly the issue.
Fix:
- Generate a hashed password using
slappasswd(included with OpenLDAP):slappasswd # Enter your user's password when prompted, copy the output (e.g., {SSHA}abc123xyz...) - Update your user’s
userPasswordattribute in OpenLDAP to use this hashed value (via phpLDAPadmin, LDAP Admin, orldapmodify).
4. Debug with Detailed LDAP Logs
You already enabled LDAP_LOGGING=true, so use those logs to see exactly what’s happening during login.
How to Check:
- Open
storage/logs/laravel.logand search for entries starting withldap_record. Look for:Invalid credentials: Means the password/DN combination is wrong.Insufficient access rights: Your bind account doesn’t have permission to read the user’s password attribute.No such object: Laravel can’t find the user entry (double-check yourLDAP_BASE_DNand user lookup attribute).
5. Adjust OpenLDAP Access Control Lists (ACLs)
Even if your bind account works, restrictive ACLs might block access to user attributes needed for authentication.
Example ACL Configuration:
Edit your OpenLDAP database’s LDIF file (usually located at /etc/openldap/slapd.d/cn=config/olcDatabase={1}mdb.ldif or similar) to add these rules:
olcAccess: {0}to attrs=userPassword by self write by dn.base="cn=ldap-service,dc=example,dc=com" read by * auth olcAccess: {1}to dn.base="" by * read olcAccess: {2}to * by dn.base="cn=admin,dc=example,dc=com" write by dn.base="cn=ldap-service,dc=example,dc=com" read by * read
Then restart the OpenLDAP service:
systemctl restart slapd
内容的提问来源于stack exchange,提问作者Artūras Yapaz

