Confluent Control Center 7.2.2 Jetty LDAP登录模块绑定认证疑问
问题:Confluent Control Center 7.2.2 配置Jetty LdapLoginModule时移除bindDn/bindPassword失败
我正在用Jetty的LdapLoginModule保护Confluent Control Center 7.2.2,当前有一套可正常运行的JAAS配置:
c3 { org.eclipse.jetty.jaas.spi.LdapLoginModule required useLdaps="true" contextFactory="com.sun.jndi.ldap.LdapCtxFactory" hostname="ldaps.xxxx.xxxxx" port="xxx" bindDn=<user principal name> bindPassword=<user password> authenticationMethod="simple" forceBindingLogin="true" userBaseDn="DC=xxxx,DC=xxxx,DC=xxx,DC=xx" userRdnAttribute="userPrincipalName" userIdAttribute="userPrincipalName" userObjectClass="user" roleBaseDn="OU=xxxxxx,OU=xxx,OU=xxxxx,DC=xxxx,DC=xxxx,DC=xxx,DC=xx" roleNameAttribute="cn" roleMemberAttribute="member" roleObjectClass="group"; };
我原本期望移除bindDn和bindPassword,通过设置forceBindingLogin="true"让系统使用当前认证用户的凭据直接绑定LDAP,但移除这两个配置后出现错误:
LDAP: error code 1 - 000004DC: LdapErr: DSID-0C090A71, comment: In order to perform this operation a successful bind must be completed on the connection., data 0, v3839
看起来即便开启了forceBindingLogin,系统仍要求提供bindDn。我注意到Confluent文档显示,bindDn配置在6.1.9到6.2.0版本间从可选变为必填,同时Jetty升级到了9.4.39,但文档没有说明变更原因。
内容的提问来源于stack exchange,提问作者Alex
相关产品推荐
相关产品推荐

