Symfony 6对接LDAP服务器登录报错:提供的密码无效
Symfony 6 LDAP身份验证报错:The presented password is invalid
问题概述
在Symfony 6项目中对接LDAP服务器完成身份验证时,已成功连接LDAP服务器并绑定LDAP用户提供者,但登录时出现错误:The presented password is invalid。
配置文件
services.yaml
Symfony\Component\Ldap\Ldap: arguments: ['@Symfony\Component\Ldap\Adapter\ExtLdap\Adapter'] tags: - ldap Symfony\Component\Ldap\Adapter\ExtLdap\Adapter: arguments: - host: ldap.forumsys.com port: 389 #encryption: tls options: protocol_version: 3 referrals: false
security.yaml
providers: # used to reload user from session & other features (e.g. switch_user) my_ldap: ldap: service: Symfony\Component\Ldap\Ldap base_dn: DC=example,DC=com search_dn: "CN=read-only-admin,DC=example,DC=com" search_password: password default_roles: ROLE_USER uid_key: uid app_user_provider: id: App\Security\UserProvider firewalls: dev: pattern: ^/(_(profiler|wdt)|css|images|js)/ security: false main: lazy: true provider: my_ldap custom_authenticator: App\Security\LdapAuthenticator form_login_ldap: login_path: app_login check_path: app_login service: Symfony\Component\Ldap\Ldap dn_string: 'uid={user_identifier},dc=example,dc=com' entry_point: form_login_ldap logout: path: app_logout
日志信息
[2022-12-08T15:01:57.363017+01:00] request.INFO: Matched route "app_login". {"route":"app_login","route_parameters":{"_route":"app_login","_controller":"App\\Controller\\LdapController::login"},"request_uri":"https://127.0.0.1:8000/login","method":"POST"} [] [2022-12-08T15:01:57.373679+01:00] security.DEBUG: Checking for authenticator support. {"firewall_name":"main","authenticators":2} [] [2022-12-08T15:01:57.373737+01:00] security.DEBUG: Checking support on authenticator. {"firewall_name":"main","authenticator":"App\\Security\\LdapAuthenticator"} [] [2022-12-08T15:01:57.375104+01:00] security.DEBUG: Checking support on authenticator. {"firewall_name":"main","authenticator":"Symfony\\Component\\Ldap\\Security\\LdapAuthenticator"} [] [2022-12-08T15:01:57.993780+01:00] security.INFO: Authenticator failed. {"exception":"[object] (Symfony\\Component\\Security\\Core\\Exception\\BadCredentialsException(code: 0): The presented password is invalid 1. at C:\\xampp\\htdocs\\LdapFinal\\vendor\\symfony\\security-http\\EventListener\\CheckCredentialsListener.php:69)","authenticator":"App\\Security\\LdapAuthenticator"} [] [2022-12-08T15:01:58.002159+01:00] security.DEBUG: The "App\Security\LdapAuthenticator" authenticator set the failure response. {"authenticator":"App\\Security\\LdapAuthenticator"} [] [2022-12-08T15:01:58.010708+01:00] security.DEBUG: The "App\Security\LdapAuthenticator" authenticator set the response. Any later authenticator will not be called {"authenticator":"App\\Security\\LdapAuthenticator"} [] [2022-12-08T15:01:58.101859+01:00] request.INFO: Matched route "app_login". {"route":"app_login","route_parameters":{"_route":"app_login","_controller":"App\\Controller\\LdapController::login"},"request_uri":"https://127.0.0.1:8000/login","method":"GET"} [] [2022-12-08T15:01:58.108085+01:00] security.DEBUG: Checking for authenticator support. {"firewall_name":"main","authenticators":2} [] [2022-12-08T15:01:58.108178+01:00] security.DEBUG: Checking support on authenticator. {"firewall_name":"main","authenticator":"App\\Security\\LdapAuthenticator"} [] [2022-12-08T15:01:58.108209+01:00] security.DEBUG: Authenticator does not support the request. {"firewall_name":"main","authenticator":"App\\Security\\LdapAuthenticator"} [] [2022-12-08T15:01:58.108232+01:00] security.DEBUG: Checking support on authenticator. {"firewall_name":"main","authenticator":"Symfony\\Component\\Ldap\\Security\\LdapAuthenticator"} [] [2022-12-08T15:01:58.108260+01:00] security.DEBUG: Authenticator does not support the request. {"firewall_name":"main","authenticator":"Symfony\\Component\\Ldap\\Security\\LdapAuthenticator"} [] [2022-12-08T15:01:58.248350+01:00] request.INFO: Matched route "_wdt". {"route":"_wdt","route_parameters":{"_route":"_wdt","_controller":"web_profiler.controller.profiler::toolbarAction","token":"1fdb80"},"request_uri":"https://127.0.0.1:8000/_wdt/1fdb80","method":"GET"} []
排查与解决思路
优先级问题:自定义Authenticator拦截验证
从日志可看到,App\Security\LdapAuthenticator先处理登录请求,验证失败后直接返回响应,导致Symfony自带的form_login_ldap验证逻辑未触发。- 若无需自定义验证逻辑,直接在
security.yaml的main防火墙中移除custom_authenticator: App\Security\LdapAuthenticator配置,仅保留form_login_ldap即可。 - 若需要自定义Authenticator,需检查内部验证逻辑:是否正确构建用户DN(如
uid=用户名,dc=example,dc=com),是否调用LDAP的bind()方法验证密码,确保凭证传递无误。
- 若无需自定义验证逻辑,直接在
验证测试用户信息
使用对应测试LDAP服务器提供的合法用户信息,例如:- 用户名:
einstein,密码:password - DN格式:
uid=einstein,dc=example,dc=com
确保登录时输入的用户名和密码完全匹配。
- 用户名:
验证LDAP连接与查询
可通过命令行工具测试LDAP连接和用户查询,确认用户存在且可被搜索到:ldapsearch -x -H ldap://ldap.forumsys.com:389 -D "CN=read-only-admin,DC=example,DC=com" -w password -b "dc=example,dc=com" "uid=einstein"
内容的提问来源于stack exchange,提问作者hamouche mohammed
相关产品推荐
相关产品推荐

