Rundeck Active Directory认证配置:如何用Windows命令获取对象名?
Rundeck Active Directory认证配置所需的Windows验证命令
我在配置Rundeck的Active Directory认证时遇到问题,正在编辑/rundeck/server/config/jaas-loginmodule.conf文件,当前配置内容如下:
RDpropertyfilelogin { com.dtolabs.rundeck.jetty.jaas.JettyCachingLdapLoginModule sufficient debug="true" contextFactory="com.sun.jndi.ldap.LdapCtxFactory" providerUrl="ldap://hpwidc00011.corporate.local:389" bindDn="cn=svc_rundeck,dc=corporate,dc=local" bindPassword="X" authenticationMethod="simple" forceBindingLogin="false" userBaseDn="ou=Users,dc=Corporate,dc=corporate,dc=local" userRdnAttribute="sAMAccountName" userIdAttribute="sAMAccountName" userPasswordAttribute="userPassword" userObjectClass="user" userLastNameAttribute="sn" userFirstNameAttribute="givenName" userEmailAttribute="mail" roleBaseDn="ou=Users,dc=corporate,dc=local" roleNameAttribute="cn" roleUsernameMemberAttribute="memberUid" roleMemberAttribute="member" roleObjectClass="group" cacheDurationMillis="300000" reportStatistics="true" timeoutRead="10000" timeoutConnect="20000" nestedGroups="true"; org.eclipse.jetty.jaas.spi.PropertyFileLoginModule required debug="true" file="/securepay/app/rundeck/server/config/realm.properties"; };
需要通过Windows命令获取并验证配置中所需的对象信息,确保配置生效。
一、验证Bind DN(服务账号)信息
确认bindDn的正确性,在域控制器或已加域的机器上执行:
dsquery user -samid svc_rundeck
命令会返回服务账号的完整DN(如CN=svc_rundeck,OU=Service Accounts,DC=corporate,DC=local),与配置中的bindDn比对,确保完全一致。
二、修正用户搜索路径(userBaseDn)
当前配置中userBaseDn存在重复域名段(dc=Corporate,dc=corporate,dc=local),执行以下命令获取正确的用户OU路径:
dsquery ou -name Users
返回结果类似OU=Users,DC=corporate,DC=local,用此结果替换配置中的错误userBaseDn。
三、验证用户属性配置
确认AD用户属性与配置字段匹配,查询指定用户的详细属性:
dsget user "CN=Test User,OU=Users,DC=corporate,DC=local" -samid -sn -givenname -mail
替换命令中的用户DN为实际测试用户的DN,检查返回的属性值是否正常,确保配置的属性名称(如sAMAccountName、sn)与AD实际属性一致。
四、验证组(角色)相关配置
- 确认组搜索路径:如果Rundeck权限组不在
ou=Users下,执行以下命令查找组所在OU:
dsquery group -name "Rundeck*" # 替换为你的Rundeck相关组名前缀
从返回的组完整DN中提取正确的roleBaseDn。
- 修正组成员属性:AD组的成员属性为
member,memberUid是OpenLDAP专用字段,需删除配置中的roleUsernameMemberAttribute。可通过以下命令查看组成员验证:
dsget group "CN=Rundeck Admins,OU=Groups,DC=corporate,DC=local" -members
确认返回的成员DN格式符合配置预期。
五、测试LDAP连接(可选)
在Windows上使用ldp.exe工具(需安装RSAT组件),输入配置中的providerUrl地址和端口,用bindDn和bindPassword绑定,测试连接是否正常,排查认证或网络问题。
内容的提问来源于stack exchange,提问作者Amanda N
相关产品推荐
相关产品推荐

