SimpleSAMLphp配置LDAP认证报错:值192.168.1.2不匹配预期模式
解决SimpleSAMLphp LDAP认证的AssertionFailedException错误
错误详情
SimpleSAML\Error\Error: UNHANDLEDEXCEPTION Backtrace: 2 public/_include.php:28 (SimpleSAML_exception_handler) 1 vendor/symfony/error-handler/ErrorHandler.php:541 (Symfony\Component\ErrorHandler\ErrorHandler::handleException) 0 [builtin] (N/A) Caused by: SimpleSAML\Assert\AssertionFailedException: The value "192.168.1.2" does not match the expected pattern. Backtrace: 13 vendor/simplesamlphp/assert/src/Assert.php:364 (SimpleSAML\Assert\Assert::__callStatic) 12 modules/ldap/src/Connector/Ldap.php:58 (SimpleSAML\Module\ldap\Connector\Ldap::__construct) 11 modules/ldap/src/ConnectorFactory.php:49 (SimpleSAML\Module\ldap\ConnectorFactory::fromAuthSource) 10 modules/ldap/src/Auth/Source/Ldap.php:66 (SimpleSAML\Module\ldap\Auth\Source\Ldap::__construct) 9 src/SimpleSAML/Auth/Source.php:326 (SimpleSAML\Auth\Source::parseAuthSource) 8 src/SimpleSAML/Auth/Source.php:368 (SimpleSAML\Auth\Source::getById) 7 src/SimpleSAML/Auth/Simple.php:72 (SimpleSAML\Auth\Simple::getAuthSource) 6 src/SimpleSAML/Auth/Simple.php:159 (SimpleSAML\Auth\Simple::login) 5 modules/admin/src/Controller/Test.php:142 (SimpleSAML\Module\admin\Controller\Test::main) 4 vendor/symfony/http-kernel/HttpKernel.php:163 (Symfony\Component\HttpKernel\HttpKernel::handleRaw) 3 vendor/symfony/http-kernel/HttpKernel.php:75 (Symfony\Component\HttpKernel\HttpKernel::handle) 2 vendor/symfony/http-kernel/Kernel.php:202 (Symfony\Component\HttpKernel\Kernel::handle) 1 src/SimpleSAML/Module.php:228 (SimpleSAML\Module::process) 0 public/module.php:14 (N/A)
部署环境
- Debian 12 + nginx/1.22.1 + PHP 8.2(已安装LDAP扩展)+ SimpleSAMLphp 2.0.4
- Debian 11 + nginx/1.18.0 + PHP 7.4(已安装LDAP扩展)+ SimpleSAMLphp 2.0.4
当前配置
LDAP模块安装与启用
通过Composer安装LDAP模块:
php composer.phar require simplesamlphp/simplesamlphp-module-ldap
在config.php中启用模块:
'module.enable' => [ 'exampleauth' => false, 'core' => true, 'admin' => true, 'ldap' => true, 'saml' => true ],
authsources.php配置
// Example of a LDAP authentication source. 'Test' => [ 'ldap:Ldap', // The connection string for the LDAP-server. // You can add multiple by separating them with a space. 'connection_string' => '192.168.1.2', // Whether SSL/TLS should be used when contacting the LDAP server. // Possible values are 'ssl', 'tls' or 'none' 'encryption' => 'ssl', // The LDAP version to use when interfacing the LDAP-server. // Defaults to 3 'version' => 3, // Set to TRUE to enable LDAP debug level. Passed to the LDAP connector class. // // Default: FALSE // Required: No 'ldap.debug' => true, 'ldap.port' => 389, // The LDAP-options to pass when setting up a connection 'options' => [ // Set whether to follow referrals. // AD Controllers may require 0x00 to function. // Possible values are 0x00 (NEVER), 0x01 (SEARCHING), // 0x02 (FINDING) or 0x03 (ALWAYS). 'referrals' => 0x00, 'network_timeout' => 3, ], // The connector to use. // Defaults to '\SimpleSAML\Module\ldap\Connector\Ldap', but can be set // to '\SimpleSAML\Module\ldap\Connector\ActiveDirectory' when // authenticating against Microsoft Active Directory. This will // provide you with more specific error messages. 'connector' => '\SimpleSAML\Module\ldap\Connector\Ldap', // Which attributes should be retrieved from the LDAP server. // This can be an array of attribute names, or NULL, in which case // all attributes are fetched. 'attributes' => null, // Which attributes should be base64 encoded after retrieval from // the LDAP server. 'attributes.binary' => [ 'jpegPhoto', 'objectGUID', 'objectSid', 'mS-DS-ConsistencyGuid' ], // The pattern which should be used to create the user's DN given // the username. %username% in this pattern will be replaced with // the user's username. // // This option is not used if the search.enable option is set to TRUE. 'dnpattern' => 'cn=%username%,ou=Klxx,ou=xxxx,ou=Benutzer,ou=xxx,ou=Sxx,o=mxx', // As an alternative to specifying a pattern for the users DN, it is // possible to search for the username in a set of attributes. This is // enabled by this option. 'search.enable' => true, // An array on DNs which will be used as a base for the search. In // case of multiple strings, they will be searched in the order given. 'search.base' => [ 'ou=xxx,ou=xxxx,ou=Bxxxxx,ou=xxxxxx,ou=xxxxxx,o=xxxxxxx', ], // The scope of the search. Valid values are 'sub' and 'one' and // 'base', first one being the default if no value is set. 'search.scope' => 'sub', // The attribute(s) the username should match against. // // This is an array with one or more attribute names. Any of the // attributes in the array may match the value the username. 'search.attributes' => ['uid', 'mail','cn','sn'], // Additional filters that must match for the entire LDAP search to // be true. // // This should be a single string conforming to RFC 1960 and RFC 2544. // The string is appended to the search attributes 'search.filter' => '(objectclass=*)', // The username & password where SimpleSAMLphp should bind to before // searching. If this is left NULL, no bind will be performed before // searching. 'search.username' => 'cn=xxxxxxxx,ou=sxxxxxx,ou=xxxxxxxx,o=mxxxxxx', 'search.password' => 'xxxxxxxxxxxxxxxxxxxx', ],
解决方案
错误原因是SimpleSAMLphp的LDAP模块对connection_string的格式有严格校验,必须使用带协议前缀的URI格式(如ldap://或ldaps://),直接填写IP地址不符合规则,因此抛出断言失败异常。
步骤1:修正connection_string格式
修改authsources.php中的connection_string,添加对应协议前缀:
- 如果使用
ssl加密(默认对应636端口),修改为:
'connection_string' => 'ldaps://192.168.1.2',
- 如果使用
tls加密(对应389端口),修改为:
'connection_string' => 'ldap://192.168.1.2',
步骤2:匹配加密方式与端口
注意加密方式和端口的对应关系:
ssl加密通常使用636端口,若LDAP服务器用389端口提供加密,建议将encryption改为'tls'- 修改后确保
ldap.port与服务器实际监听端口一致
步骤3:重新测试
保存配置后,重新测试LDAP认证功能即可解决该错误。
内容的提问来源于stack exchange,提问作者max Hhhh
相关产品推荐
相关产品推荐

