You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Laravel 基于Ldaprecord连接本地OpenLDAP:连接测试成功但登录验证失败问题求助

Troubleshooting Laravel + OpenLDAP Login Credential Errors

It’s frustrating when your LDAP connection tests pass but login fails—let’s walk through the most common fixes for your setup:

1. Stop Using Anonymous Bind for Authentication

Your .env has LDAP_USERNAME and LDAP_PASSWORD set to null, which means Laravel is trying to bind anonymously. Most self-hosted OpenLDAP instances either block anonymous access entirely or restrict anonymous users from reading sensitive attributes like userPassword (required for authentication).

Fix:

  • Create a dedicated service account in OpenLDAP (e.g., cn=ldap-service,dc=example,dc=com) with permissions to read user entries.
  • Update your .env with this account’s credentials:
    LDAP_USERNAME="cn=ldap-service,dc=example,dc=com"
    LDAP_PASSWORD="your-service-account-password"
    

2. Verify User DN Construction

Laravel LDAP needs to build the correct Distinguished Name (DN) for your user to authenticate them. If it’s using the wrong attribute to look up the user, the bind will fail even if the password is correct.

Check & Fix:

  • Open config/ldap.php and navigate to the connections.default.users section. Ensure the key matches the unique attribute you’re using for login (e.g., uid for usernames, mail for emails):
    'users' => [
        'object_classes' => ['inetOrgPerson', 'posixAccount'],
        'key' => 'uid', // Match this to your user's login attribute
    ],
    
  • Test the user’s DN manually with the ldapsearch command (replace your-username with your actual user):
    ldapsearch -x -H ldap://127.0.0.1:10389 -b dc=example,dc=com "(uid=your-username)" dn
    
    If this returns a valid DN (like uid=your-username,dc=example,dc=com), your lookup logic is correct.

3. Ensure User Passwords Are Stored in the Right Format

OpenLDAP won’t accept plaintext passwords for authentication—they need to be hashed in a supported format (like SSHA, MD5, or SHA-256). If you created your user with a plaintext password, that’s almost certainly the issue.

Fix:

  • Generate a hashed password using slappasswd (included with OpenLDAP):
    slappasswd
    # Enter your user's password when prompted, copy the output (e.g., {SSHA}abc123xyz...)
    
  • Update your user’s userPassword attribute in OpenLDAP to use this hashed value (via phpLDAPadmin, LDAP Admin, or ldapmodify).

4. Debug with Detailed LDAP Logs

You already enabled LDAP_LOGGING=true, so use those logs to see exactly what’s happening during login.

How to Check:

  • Open storage/logs/laravel.log and search for entries starting with ldap_record. Look for:
    • Invalid credentials: Means the password/DN combination is wrong.
    • Insufficient access rights: Your bind account doesn’t have permission to read the user’s password attribute.
    • No such object: Laravel can’t find the user entry (double-check your LDAP_BASE_DN and user lookup attribute).

5. Adjust OpenLDAP Access Control Lists (ACLs)

Even if your bind account works, restrictive ACLs might block access to user attributes needed for authentication.

Example ACL Configuration:
Edit your OpenLDAP database’s LDIF file (usually located at /etc/openldap/slapd.d/cn=config/olcDatabase={1}mdb.ldif or similar) to add these rules:

olcAccess: {0}to attrs=userPassword by self write by dn.base="cn=ldap-service,dc=example,dc=com" read by * auth
olcAccess: {1}to dn.base="" by * read
olcAccess: {2}to * by dn.base="cn=admin,dc=example,dc=com" write by dn.base="cn=ldap-service,dc=example,dc=com" read by * read

Then restart the OpenLDAP service:

systemctl restart slapd

内容的提问来源于stack exchange,提问作者Artūras Yapaz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 07:12:30