You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows Server Docker容器无法连接LDAP服务器问题求助

Windows容器中LDAP查询AD报错"The server is not operational."的排查与解决

我编写了一段通过LDAP地址从AD查询用户及其所属组的代码,本地运行正常,但部署到使用Windows Server Core镜像的Docker容器后,出现错误提示:"The server is not operational.",已确认容器可访问DC服务器。

代码片段

using var ldapContext = new DirectoryEntry(_configuration["ActiveDirectory:Path"], username, password);
using var searcher = new DirectorySearcher(ldapContext);
searcher.Filter = $"(&(objectCategory=person)(objectClass=user)(sAMAccountName={username}))";
searcher.PropertiesToLoad.Add("memberOf");
try
{
    List<string> groups = new();
    foreach (SearchResult entry in searcher.FindAll())
        if (entry.Properties.Contains("memberOf"))
            // 后续处理逻辑
            ...
}
catch (Exception ex)
{
    // 异常捕获
}

使用的Dockerfile

FROM mcr.microsoft.com/dotnet/aspnet:6.0.9-windowsservercore-ltsc2022 AS base
EXPOSE 80
WORKDIR /app

FROM mcr.microsoft.com/dotnet/sdk:6.0.401-windowsservercore-ltsc2022 AS build
WORKDIR /src
COPY ["src/services/identity/Identity.Api.Service/Identity.Api.Service.csproj", "src/services/identity/Identity.Api.Service/"]
RUN dotnet restore "src/services/identity/Identity.Api.Service/Identity.Api.Service.csproj"
COPY . .
WORKDIR "/src/src/services/identity/Identity.Api.Service"
RUN dotnet build "Identity.Api.Service.csproj" -c Release -o /app/build

FROM build AS publish
RUN dotnet publish "Identity.Api.Service.csproj" -c Release -o /app/publish /p:UseAppHost=false
FROM base AS final
WORKDIR /app
COPY --from=publish /app/publish .
ENTRYPOINT ["dotnet", "Identity.Api.Service.dll"]

完整堆栈跟踪

at System.DirectoryServices.DirectoryEntry.Bind(Boolean throwIfFail) 
in /_/src/libraries/System.DirectoryServices/src/System/DirectoryServices/DirectoryEntry.cs:line 561

at System.DirectoryServices.DirectorySearcher.FindAll(Boolean findMoreThanOne) 
in /_/src/libraries/System.DirectoryServices/src/System/DirectoryServices/DirectorySearcher.cs:line 623

at Identity.Api.Service.Controllers.IdentityController.LoginViaActiveDirectory(String username, String password)

排查与解决思路

不需要更换镜像,重点检查容器环境的网络配置、LDAP参数设置:

  • 验证LDAP路径的正确性
    确保ActiveDirectory:Path配置的是完整且可访问的LDAP路径,比如LDAP://dc.yourdomain.com/DC=yourdomain,DC=com。如果容器内DNS解析存在问题,尝试直接使用DC服务器的IP地址替换域名测试,比如LDAP://192.168.1.10/DC=yourdomain,DC=com。

  • 调整容器网络与DNS设置
    Windows容器默认使用NAT网络,可能存在DNS解析异常。运行容器时可以手动指定DNS服务器为AD的DC地址:

    docker run --dns <DC_SERVER_IP> your-image-name
    

    或者直接使用host网络模式(仅适用于Windows容器的特定场景):

    docker run --network host your-image-name
    
  • 明确身份验证的域名前缀
    容器环境未加入域,因此在传入username时需要明确带上域名前缀,比如DOMAIN\username或用户主体名称(UPN)user@domain.com,避免身份验证时无法定位到AD域。

  • 检查LDAP协议与端口
    如果AD服务器要求使用LDAPS(加密连接),需将LDAP路径改为LDAPS://dc.yourdomain.com,同时确保容器能访问636端口。另外,容器默认没有域内根CA证书,需要将AD的CA证书导入到容器的受信任根证书存储中:

    1. 将CA证书文件复制到容器内
    2. 在容器中执行命令导入证书:
      certutil -addstore -f "Root" C:\path\to\ca-cert.cer
      
  • 确认容器内LDAP客户端可用性
    Windows Server Core镜像默认包含LDAP客户端组件,但可以在容器内手动测试LDAP连接:

    ldp.exe <DC_SERVER_IP> 389
    

    若连接失败,说明网络层存在问题,需进一步排查防火墙、路由规则。

内容的提问来源于stack exchange,提问作者Liam Björkman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 13:50:45