Ubuntu 20.04 NSS-LDAP客户端绑定LDAP服务器失败问题
Ubuntu 20.04 NSS-LDAP客户端连接报错但功能正常的排查与解决
问题现象
LDAP用户可正常登录客户端机器,ldapsearch测试连接也正常,但系统日志中持续出现以下错误:
systemd-logind: nss_ldap: failed to bind to LDAP server ldap://[IP address]: Can't contact LDAP server systemd-logind: nss_ldap: reconnecting to LDAP server... systemd-logind: nss_ldap: could not connect to any LDAP server as cn=admin,dc=example,dc=com - Can't contact LDAP server systemd-logind: nss_ldap: could not search LDAP server - Server is unavailable
当前配置文件
/etc/ldap.conf
注:nss_initgroups_ignoreusers为自动生成
# The distinguished name of the search base. base dc=example,dc=com # Another way to specify your LDAP server is to provide an uri ldap://[IP address] # The LDAP version to use (defaults to 3 # if supported by client library) ldap_version 3 # The distinguished name to bind to the server with # if the effective user ID is root. Password is # stored in /etc/ldap.secret (mode 600) rootbinddn cn=admin,dc=example,dc=com # Do not hash the password at all; presume # the directory server will do it, if # necessary. This is the default. pam_password md5 nss_initgroups_ignoreusers _apt,backup,bin,clamav,daemon,fwupd-refresh,games,gnats,irc,landscape,list,lp,lxd,mail,man,messagebus,mysql,news,pollinate,proxy,root,sshd,sync,sys,syslog,systemd-coredump,systemd-network,systemd-resolve,systemd-timesync,tcpdump,tss,uucp,uuidd,www-data
/etc/ldap.secret
已存储LDAP绑定账号cn=admin,dc=example,dc=com的密码,权限设置为600
/etc/nsswitch.conf
passwd: files ldap systemd group: files ldap systemd shadow: files ldap gshadow: files hosts: files dns networks: files protocols: db files services: db files ethers: db files rpc: db files netgroup: nis
/etc/pam.d/common-session
# here are the per-package modules (the "Primary" block) session [default=1] pam_permit.so # here's the fallback if no module succeeds session requisite pam_deny.so # prime the stack with a positive return value if there isn't one already; # this avoids us returning an error just because nothing sets a success code # since the modules above will each just jump around session required pam_permit.so # The pam_umask module will set the umask according to the system default in # /etc/login.defs and user settings, solving the problem of different # umask settings with different shells, display managers, remote sessions etc. # See "man pam_umask". session optional pam_umask.so # and here are more per-package modules (the "Additional" block) session required pam_unix.so session optional pam_ldap.so session optional pam_systemd.so session required pam_mkhomedir.so skel=/etc/skel umask=0022
/etc/security/access.conf
添加了以下规则:
-:ALL EXCEPT root khloud (ldap-group) (admin) ubuntu:ALL EXCEPT LOCAL
/etc/pam.d/sshd
取消了以下行的注释:
account required pam_access.so
已尝试的操作
- 使用
ldapsearch测试LDAP连接,结果正常 - 修改
nsswitch.conf配置 - 重装NSS-LDAP客户端
以上操作后错误日志仍存在,但LDAP用户登录等功能正常
排查与解决建议
1. 调整systemd-logind启动时机
systemd-logind在系统启动早期启动时,网络可能未完全就绪,导致nss_ldap初始化失败:
- 编辑
/lib/systemd/system/systemd-logind.service,添加网络依赖:[Unit] Description=User Login Management Documentation=man:systemd-logind.service(8) man:logind.conf(5) Documentation=https://www.freedesktop.org/wiki/Software/systemd/logind Documentation=https://www.freedesktop.org/wiki/Software/systemd/multiseat After=systemd-user-sessions.service systemd-userdb.service After=network-online.target Wants=network-online.target - 重新加载配置并重启服务:
sudo systemctl daemon-reload sudo systemctl restart systemd-logind
2. 优化nss_ldap连接参数
在/etc/ldap.conf中添加超时与重试配置,减少频繁报错:
# 连接超时(秒) bind_timelimit 30 # 搜索超时(秒) timelimit 30 # 启用故障自动重连 reconnect_on_failure yes # 重试间隔与上限 reconnect_sleeptime 1 reconnect_maxsleeptime 10 reconnect_maxretries 5
3. 调整nsswitch服务顺序
将systemd移至ldap前,优先查询本地用户数据库,减少不必要的LDAP连接尝试:
passwd: files systemd ldap group: files systemd ldap
4. 验证LDAP绑定账号权限
确认cn=admin,dc=example,dc=com账号权限与密码正确性:
ldapsearch -x -D cn=admin,dc=example,dc=com -W -b dc=example,dc=com '(objectClass=posixAccount)'
输入密码后若能返回LDAP用户列表,说明账号配置无误。
内容的提问来源于stack exchange,提问作者Khloud Mostafa
相关产品推荐
相关产品推荐

