You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu 20.04 NSS-LDAP客户端绑定LDAP服务器失败问题

Ubuntu 20.04 NSS-LDAP客户端连接报错但功能正常的排查与解决

问题现象

LDAP用户可正常登录客户端机器,ldapsearch测试连接也正常,但系统日志中持续出现以下错误:

systemd-logind: nss_ldap: failed to bind to LDAP server ldap://[IP address]: Can't contact LDAP server
systemd-logind: nss_ldap: reconnecting to LDAP server...
systemd-logind: nss_ldap: could not connect to any LDAP server as cn=admin,dc=example,dc=com - Can't contact LDAP server
systemd-logind: nss_ldap: could not search LDAP server - Server is unavailable

当前配置文件

/etc/ldap.conf

注:nss_initgroups_ignoreusers为自动生成

# The distinguished name of the search base.
base dc=example,dc=com

# Another way to specify your LDAP server is to provide an
uri ldap://[IP address]

# The LDAP version to use (defaults to 3
# if supported by client library)
ldap_version 3

# The distinguished name to bind to the server with
# if the effective user ID is root. Password is
# stored in /etc/ldap.secret (mode 600)
rootbinddn cn=admin,dc=example,dc=com

# Do not hash the password at all; presume
# the directory server will do it, if
# necessary. This is the default.
pam_password md5

nss_initgroups_ignoreusers _apt,backup,bin,clamav,daemon,fwupd-refresh,games,gnats,irc,landscape,list,lp,lxd,mail,man,messagebus,mysql,news,pollinate,proxy,root,sshd,sync,sys,syslog,systemd-coredump,systemd-network,systemd-resolve,systemd-timesync,tcpdump,tss,uucp,uuidd,www-data

/etc/ldap.secret

已存储LDAP绑定账号cn=admin,dc=example,dc=com的密码,权限设置为600

/etc/nsswitch.conf

passwd:         files ldap systemd
group:          files ldap systemd
shadow:         files ldap
gshadow:        files

hosts:          files dns
networks:       files

protocols:      db files
services:       db files
ethers:         db files
rpc:            db files

netgroup:       nis

/etc/pam.d/common-session

# here are the per-package modules (the "Primary" block)
session [default=1]                     pam_permit.so
# here's the fallback if no module succeeds
session requisite                       pam_deny.so
# prime the stack with a positive return value if there isn't one already;
# this avoids us returning an error just because nothing sets a success code
# since the modules above will each just jump around
session required                        pam_permit.so
# The pam_umask module will set the umask according to the system default in
# /etc/login.defs and user settings, solving the problem of different
# umask settings with different shells, display managers, remote sessions etc.
# See "man pam_umask".
session optional                        pam_umask.so
# and here are more per-package modules (the "Additional" block)
session required        pam_unix.so
session optional                        pam_ldap.so
session optional        pam_systemd.so
session required    pam_mkhomedir.so skel=/etc/skel umask=0022

/etc/security/access.conf

添加了以下规则:

-:ALL EXCEPT root khloud (ldap-group) (admin) ubuntu:ALL EXCEPT LOCAL

/etc/pam.d/sshd

取消了以下行的注释:

account  required     pam_access.so

已尝试的操作

  • 使用ldapsearch测试LDAP连接,结果正常
  • 修改nsswitch.conf配置
  • 重装NSS-LDAP客户端
    以上操作后错误日志仍存在,但LDAP用户登录等功能正常

排查与解决建议

1. 调整systemd-logind启动时机

systemd-logind在系统启动早期启动时,网络可能未完全就绪,导致nss_ldap初始化失败:

  • 编辑/lib/systemd/system/systemd-logind.service,添加网络依赖:
    [Unit]
    Description=User Login Management
    Documentation=man:systemd-logind.service(8) man:logind.conf(5)
    Documentation=https://www.freedesktop.org/wiki/Software/systemd/logind
    Documentation=https://www.freedesktop.org/wiki/Software/systemd/multiseat
    After=systemd-user-sessions.service systemd-userdb.service
    After=network-online.target
    Wants=network-online.target
    
  • 重新加载配置并重启服务:
    sudo systemctl daemon-reload
    sudo systemctl restart systemd-logind
    

2. 优化nss_ldap连接参数

在/etc/ldap.conf中添加超时与重试配置,减少频繁报错:

# 连接超时(秒)
bind_timelimit 30
# 搜索超时(秒)
timelimit 30
# 启用故障自动重连
reconnect_on_failure yes
# 重试间隔与上限
reconnect_sleeptime 1
reconnect_maxsleeptime 10
reconnect_maxretries 5

3. 调整nsswitch服务顺序

将systemd移至ldap前,优先查询本地用户数据库,减少不必要的LDAP连接尝试:

passwd:         files systemd ldap
group:          files systemd ldap

4. 验证LDAP绑定账号权限

确认cn=admin,dc=example,dc=com账号权限与密码正确性:

ldapsearch -x -D cn=admin,dc=example,dc=com -W -b dc=example,dc=com '(objectClass=posixAccount)'

输入密码后若能返回LDAP用户列表,说明账号配置无误。

内容的提问来源于stack exchange,提问作者Khloud Mostafa

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 21:21:02