You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Symfony 6对接LDAP服务器登录报错:提供的密码无效

Symfony 6 LDAP身份验证报错:The presented password is invalid

问题概述

在Symfony 6项目中对接LDAP服务器完成身份验证时,已成功连接LDAP服务器并绑定LDAP用户提供者,但登录时出现错误:The presented password is invalid。

配置文件

services.yaml

Symfony\Component\Ldap\Ldap:
    arguments: ['@Symfony\Component\Ldap\Adapter\ExtLdap\Adapter']
    tags:
        - ldap
Symfony\Component\Ldap\Adapter\ExtLdap\Adapter:
    arguments:
        -   host: ldap.forumsys.com
            port: 389
            #encryption: tls
            options:
                protocol_version: 3
                referrals: false

security.yaml

providers:
    # used to reload user from session & other features (e.g. switch_user)
    my_ldap:
        ldap:
            service: Symfony\Component\Ldap\Ldap
            base_dn: DC=example,DC=com
            search_dn: "CN=read-only-admin,DC=example,DC=com"
            search_password: password
            default_roles: ROLE_USER
            uid_key: uid
    app_user_provider:
        id: App\Security\UserProvider
firewalls:
    dev:
        pattern: ^/(_(profiler|wdt)|css|images|js)/
        security: false
    main:
        lazy: true
        provider: my_ldap
        custom_authenticator: App\Security\LdapAuthenticator
        form_login_ldap:
            login_path: app_login
            check_path: app_login
            service: Symfony\Component\Ldap\Ldap
            dn_string: 'uid={user_identifier},dc=example,dc=com'
        entry_point: form_login_ldap
        logout:
            path: app_logout

日志信息

[2022-12-08T15:01:57.363017+01:00] request.INFO: Matched route "app_login". {"route":"app_login","route_parameters":{"_route":"app_login","_controller":"App\\Controller\\LdapController::login"},"request_uri":"https://127.0.0.1:8000/login","method":"POST"} []
[2022-12-08T15:01:57.373679+01:00] security.DEBUG: Checking for authenticator support. {"firewall_name":"main","authenticators":2} []
[2022-12-08T15:01:57.373737+01:00] security.DEBUG: Checking support on authenticator. {"firewall_name":"main","authenticator":"App\\Security\\LdapAuthenticator"} []
[2022-12-08T15:01:57.375104+01:00] security.DEBUG: Checking support on authenticator. {"firewall_name":"main","authenticator":"Symfony\\Component\\Ldap\\Security\\LdapAuthenticator"} []
[2022-12-08T15:01:57.993780+01:00] security.INFO: Authenticator failed. {"exception":"[object] (Symfony\\Component\\Security\\Core\\Exception\\BadCredentialsException(code: 0): The presented password is invalid 1. at C:\\xampp\\htdocs\\LdapFinal\\vendor\\symfony\\security-http\\EventListener\\CheckCredentialsListener.php:69)","authenticator":"App\\Security\\LdapAuthenticator"} []
[2022-12-08T15:01:58.002159+01:00] security.DEBUG: The "App\Security\LdapAuthenticator" authenticator set the failure response. {"authenticator":"App\\Security\\LdapAuthenticator"} []
[2022-12-08T15:01:58.010708+01:00] security.DEBUG: The "App\Security\LdapAuthenticator" authenticator set the response. Any later authenticator will not be called {"authenticator":"App\\Security\\LdapAuthenticator"} []
[2022-12-08T15:01:58.101859+01:00] request.INFO: Matched route "app_login". {"route":"app_login","route_parameters":{"_route":"app_login","_controller":"App\\Controller\\LdapController::login"},"request_uri":"https://127.0.0.1:8000/login","method":"GET"} []
[2022-12-08T15:01:58.108085+01:00] security.DEBUG: Checking for authenticator support. {"firewall_name":"main","authenticators":2} []
[2022-12-08T15:01:58.108178+01:00] security.DEBUG: Checking support on authenticator. {"firewall_name":"main","authenticator":"App\\Security\\LdapAuthenticator"} []
[2022-12-08T15:01:58.108209+01:00] security.DEBUG: Authenticator does not support the request. {"firewall_name":"main","authenticator":"App\\Security\\LdapAuthenticator"} []
[2022-12-08T15:01:58.108232+01:00] security.DEBUG: Checking support on authenticator. {"firewall_name":"main","authenticator":"Symfony\\Component\\Ldap\\Security\\LdapAuthenticator"} []
[2022-12-08T15:01:58.108260+01:00] security.DEBUG: Authenticator does not support the request. {"firewall_name":"main","authenticator":"Symfony\\Component\\Ldap\\Security\\LdapAuthenticator"} []
[2022-12-08T15:01:58.248350+01:00] request.INFO: Matched route "_wdt". {"route":"_wdt","route_parameters":{"_route":"_wdt","_controller":"web_profiler.controller.profiler::toolbarAction","token":"1fdb80"},"request_uri":"https://127.0.0.1:8000/_wdt/1fdb80","method":"GET"} []

排查与解决思路

  1. 优先级问题:自定义Authenticator拦截验证
    从日志可看到,App\Security\LdapAuthenticator先处理登录请求,验证失败后直接返回响应,导致Symfony自带的form_login_ldap验证逻辑未触发。

    • 若无需自定义验证逻辑,直接在security.yaml的main防火墙中移除custom_authenticator: App\Security\LdapAuthenticator配置,仅保留form_login_ldap即可。
    • 若需要自定义Authenticator,需检查内部验证逻辑:是否正确构建用户DN(如uid=用户名,dc=example,dc=com),是否调用LDAP的bind()方法验证密码,确保凭证传递无误。
  2. 验证测试用户信息
    使用对应测试LDAP服务器提供的合法用户信息,例如:

    • 用户名:einstein,密码:password
    • DN格式:uid=einstein,dc=example,dc=com
      确保登录时输入的用户名和密码完全匹配。
  3. 验证LDAP连接与查询
    可通过命令行工具测试LDAP连接和用户查询,确认用户存在且可被搜索到:

    ldapsearch -x -H ldap://ldap.forumsys.com:389 -D "CN=read-only-admin,DC=example,DC=com" -w password -b "dc=example,dc=com" "uid=einstein"
    

内容的提问来源于stack exchange,提问作者hamouche mohammed

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 09:25:26