You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ActiveMQ Artemis 2.26.0如何同时基于用户名和AD组授权?

问题解答

1. 配置login.config实现用户同时拥有用户名和所属组角色权限

可以通过两种方式配置,让用户同时获得用户名和AD组作为角色:

方式一:单LDAP登录模块(推荐)

通过设置userRoleName为逗号分隔的多个属性,同时提取用户名(sAMAccountName)和所属组(memberOf)作为角色,并使用搜索过滤器限制仅允许指定OU的用户认证:

LDAPLogin {
   org.apache.activemq.artemis.spi.core.security.jaas.LDAPLoginModule required
     debug=true
     initialContextFactory="com.sun.jndi.ldap.LdapCtxFactory"
     ignorePartialResultException=true
     connectionURL="ldaps://domain-controller1:636 ldaps://domain-controller2:636"
     connectionUsername="bind_username"
     connectionPassword="bind_password"
     connectionProtocol="s"
     connectionTimeout="5000"
     readTimeout="5000"
     authentication=simple
     userBase="DC=company,DC=tld"
     userSearchMatching="(& (sAMAccountName={0}) (| (distinguishedName=*,OU=OU_for_application_users,DC=company,DC=tld) (distinguishedName=*,OU=OU_for_team_users,DC=company,DC=tld)))"
     userSearchSubtree=true
     userRoleName="sAMAccountName,memberOf"
     roleName="CN"
     ;
};
  • userRoleName="sAMAccountName,memberOf":同时从用户条目提取用户名和所属组DN作为角色来源
  • roleName="CN":从memberOf的DN中提取组名称(CN属性)作为角色名
  • 搜索过滤器确保仅OU_for_application_users和OU_for_team_users下的用户能通过认证

方式二:多LDAP登录模块组合

如果需要保留原有的OU分离逻辑,可以使用两个登录模块分别处理用户名和组角色,配合JAAS模块标志实现:

LDAPLogin {
   // 认证用户并添加用户名角色(覆盖两个OU)
   org.apache.activemq.artemis.spi.core.security.jaas.LDAPLoginModule required
     debug=true
     initialContextFactory="com.sun.jndi.ldap.LdapCtxFactory"
     ignorePartialResultException=true
     connectionURL="ldaps://domain-controller1:636 ldaps://domain-controller2:636"
     connectionUsername="bind_username"
     connectionPassword="bind_password"
     connectionProtocol="s"
     connectionTimeout="5000"
     readTimeout="5000"
     authentication=simple
     userBase="DC=company,DC=tld"
     userSearchMatching="(& (sAMAccountName={0}) (| (distinguishedName=*,OU=OU_for_application_users,DC=company,DC=tld) (distinguishedName=*,OU=OU_for_team_users,DC=company,DC=tld)))"
     userSearchSubtree=true
     userRoleName="sAMAccountName"
     ;
   // 添加用户所属组角色(无需重复认证)
   org.apache.activemq.artemis.spi.core.security.jaas.LDAPLoginModule optional
     debug=true
     initialContextFactory="com.sun.jndi.ldap.LdapCtxFactory"
     ignorePartialResultException=true
     connectionURL="ldaps://domain-controller1:636 ldaps://domain-controller2:636"
     connectionUsername="bind_username"
     connectionPassword="bind_password"
     connectionProtocol="s"
     connectionTimeout="5000"
     readTimeout="5000"
     authentication=none
     userBase="DC=company,DC=tld"
     userSearchMatching="(sAMAccountName={0})"
     userSearchSubtree=true
     userRoleName="memberOf"
     roleName="CN"
     ;
};
  • 第一个required模块负责用户认证并添加用户名角色
  • 第二个optional模块仅提取组角色,不重复认证(authentication=none)

2. ActiveMQ Artemis混合授权的合理性

ActiveMQ Artemis采用统一的角色-based访问控制(RBAC)模型,不区分用户身份和组身份,所有权限都绑定到角色上。这种设计与IBM MQ的用户/组分离授权模式不同,但混合使用用户名和组作为角色是完全合理的,原因如下:

  • 灵活性:既可以通过组角色批量管理多数用户的权限,也可以通过用户名角色为特定用户分配个性化权限(如管理员账号)
  • 简洁性:统一的角色模型简化了权限配置,无需维护用户和组两套授权规则
  • 适配性:符合LDAP/AD的常见使用场景——用户既属于组,也可能需要单独的权限例外

注意事项

  • 可维护性:避免过度使用用户名角色,尽量通过组角色管理批量权限,减少配置复杂度
  • 安全性:用户名角色应仅分配给需要特殊权限的用户,避免滥用
  • 性能:同时提取用户名和组角色会增加LDAP查询开销,建议配置LDAP缓存优化性能

内容的提问来源于stack exchange,提问作者Aleksandr Milovidov

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.10 06:46:06