Linux通过SSSD和PAM对接Google LDAP登录过慢及组权限配置问题
问题描述
环境信息
- GCP托管域名+LDAP服务,OU结构:
Organizational Units: - Technical School - Technical School - Students - Technical School - Internals - Technical School - Teachers - Technical School - Projects - Technical School - Technicians
- 用户规模:1000+
- 组类型:以动态组为主,例如Students组规则:
(user.org_unit_id==orgUnitId('sanitized_info')) && user.suspended == false - 系统:Ubuntu 20.04.6 LTS,已配置
/etc/sssd/sssd.conf(配置内容如下)
当前SSSD配置:
[sssd] services = nss,pam,sudo domains = ourdomain.org [domain/ourdomain.org] ldap_tls_cert = /var/lib/ldap/domain.crt ldap_tls_key = /var/lib/ldap/domain.key ldap_uri = ldaps://ldap.google.com ldap_search_base = dc=ourdomain,dc=org id_provider = ldap auth_provider = ldap ldap_schema = rfc2307bis ldap_user_uuid = entryUUID ldap_groups_use_matching_rule_in_chain = true ldap_initgroups_use_matching_rule_in_chain = true ldap_tls_cipher_suite = NORMAL:!VERS-TLS1.3 ldap_referrals = False ldap_group_nesting_level = 0 fallback_homedir = /home/%u@%d use_fully_qualified_names = True create_homedir = True auto_private_groups = true #override_homedir = /home/%u@%d override_shell = /bin/bash [pam] offline_credentials_expiration = 2 offline_failed_login_attempts = 3 offline_failed_login_delay = 5
核心问题
- 登录耗时长达10分钟:调试确认每次登录会全量下载1000+用户的所有信息
- 动态组权限映射失效:无法将对应"Technical School - Technicians" OU的动态组Tech关联到Linux组以分配sudo权限,调整
ldap_referrals=false、ldap_group_nesting_level=0、auto_private_groups=true后无改善
解决方案
一、优化登录速度(终止全量用户同步)
1. 缩小用户搜索范围
在[domain/ourdomain.org]段添加用户搜索的OU限制,避免遍历整个域:
# 仅搜索Technical School下的用户,可根据需求进一步细化到具体OU ldap_user_search_base = ou=Technical School,dc=ourdomain,dc=org # 示例:如果只允许技术人员登录,可改为 # ldap_user_search_base = ou=Technical School - Technicians,ou=Technical School,dc=ourdomain,dc=org
2. 添加用户过滤规则+启用缓存
过滤掉已暂停的用户,同时开启SSSD缓存减少重复查询:
# 只同步未被暂停的用户,匹配GCP LDAP的suspended属性 ldap_user_filter = (&(objectClass=user)(user.suspended=false)) # 启用凭证缓存,设置缓存有效期(单位:秒) cache_credentials = True entry_cache_timeout = 3600 # 1小时 entry_cache_nowait_timeout = 300 # 5分钟(缓存过期后不等待新数据直接返回旧数据)
3. 关闭冗余的组递归查询
保持ldap_group_nesting_level=0,同时添加以下配置禁用不必要的组解析:
ldap_initgroups_extra_attrs =
修改完成后重启SSSD并清空旧缓存:
sudo systemctl restart sssd sudo sss_cache -E
二、动态组映射与sudo权限配置
GCP LDAP动态组需要特殊配置才能被SSSD识别,按以下步骤操作:
1. 配置SSSD识别动态组
在[domain/ourdomain.org]段添加:
# 指定GCP动态组的对象类 ldap_group_object_class = googleDynamicGroup # 动态组成员关联属性 ldap_group_member = memberOf # 开启动态组支持 ldap_enable_dynamic_groups = True
2. 映射动态组到本地Linux组
创建本地sudo组tech_sudo,并通过SSSD关联到LDAP动态组Tech:
# 在[domain/ourdomain.org]段添加组映射规则 ldap_group_map = tech_sudo;cn=Tech,ou=Technical School,dc=ourdomain,dc=org
或者用命令行快速映射:
sudo sss_groupadd -M "cn=Tech,ou=Technical School,dc=ourdomain,dc=org" tech_sudo
3. 配置sudo权限
新建sudo规则文件:
sudo nano /etc/sudoers.d/tech_sudo
写入内容:
%tech_sudo ALL=(ALL) NOPASSWD:ALL
保存后设置正确权限:
sudo chmod 440 /etc/sudoers.d/tech_sudo
4. 验证配置
重启SSSD后,用Tech组内用户登录,执行以下命令验证:
id # 检查用户是否已加入tech_sudo组 sudo -l # 确认sudo权限生效
内容的提问来源于stack exchange,提问作者elmaia
相关产品推荐
相关产品推荐

