Apache AuthLDAPURL与ldapsearch匹配问题排查求助
问题描述
在Ubuntu 22.04环境中,使用OpenLDAP(2022年5月12日版本)与Apache 2.4.41,可通过ldapsearch成功验证用户凭据,但转换为Apache配置后无法正常工作。配置AuthLDAPURL后,存在的用户billy及不存在的用户eric均报“密码不匹配”错误,需要调整AuthLDAPURL以匹配ldapsearch逻辑,或模拟Apache的LDAP搜索行为排查问题。
环境与测试信息
可用的ldapsearch验证命令
# 用管理员账号搜索用户billy的条目 ldapsearch -x -LLL -H ldap://testserver -D "cn=admin,dc=testserver" -W -b "ou=people,dc=testserver" -s children "(&(objectClass=posixAccount)(uid=billy))" dn # 输入密码后返回: dn: uid=billy,ou=people,dc=testserver # 用用户billy的账号绑定并搜索目录 ldapsearch -x -LLL -H ldap://testserver -D "uid=billy,ou=people,dc=testserver" -W -b "dc=testserver" -s children "(objectClass=*)" # 输入正确密码后可打印dc=testserver下的目录树
当前Apache配置
<Location /svn/> DAV svn SVNParentPath /var/svn SVNListParentPath On AuthName '请使用你的Testserver账号登录' AuthType Basic AuthBasicProvider ldap AuthLDAPBindDN "cn=admin,dc=testserver" AuthLDAPBindPassword "password" # 测试用的用户账号配置 AuthLDAPURL "ldap://testserver:389/ou=people,dc=testserver?uid?sub?(ObjectClass=*)" require valid-user </Location>
LDAP目录结构
dn: ou=people,dc=testserver objectClass: organizationalUnit ou: people dn: ou=groups,dc=testserver objectClass: organizationalUnit ou: groups dn: uid=billy,ou=people,dc=testserver objectClass: inetOrgPerson objectClass: posixAccount objectClass: shadowAccount cn: Bill sn: Belichick userPassword: {SSHA}pr4TabkZcr/ZAtiHBgL6bF1jvuvIJ6dn loginShell: /bin/bash uidNumber: 2001 gidNumber: 2001 homeDirectory: /home/bill dn: ou=svn,ou=groups,dc=testserver objectClass: organizationalUnit ou: groups dn: cn=svn_folder_repo1_rw,ou=svn,ou=groups,dc=testserver objectClass: groupOfNames cn: svn_folder_repo1_rw member: uid=billy,ou=people,dc=testserver
Apache错误日志
[Thu Aug 11 02:24:04.914162 2022] [auth_basic:error] [pid 4631] [client 192.168.99.1:49323] AH01617: user billy: authentication failure for "/svn/": Password Mismatch # 测试不存在的用户eric时的错误 [Thu Aug 11 11:43:13.916494 2022] [auth_basic:error] [pid 619] [client 192.168.99.1:60322] AH01617: user eric: authentication failure for "/svn/": Password Mismatch
解决方案
1. 修正AuthLDAPURL配置,匹配ldapsearch逻辑
当前AuthLDAPURL的搜索范围和过滤器与ldapsearch不一致,导致无法正确定位用户条目。修改为:
AuthLDAPURL "ldap://testserver:389/ou=people,dc=testserver?uid?one?(objectClass=posixAccount)"
one:对应ldapsearch的-s children,仅搜索ou=people的直接子节点(用户条目)(objectClass=posixAccount):和ldapsearch中的过滤器一致,精准匹配用户条目
2. 验证Apache LDAP模块是否加载
确保mod_ldap和mod_authnz_ldap已加载:
apache2ctl -M | grep ldap
若未加载,执行以下命令启用:
a2enmod ldap authnz_ldap systemctl restart apache2
3. 启用LDAP调试日志排查细节
在Apache全局配置中添加调试日志级别,查看详细的LDAP交互过程:
LogLevel ldap_debug
重启Apache后,查看错误日志(默认路径/var/log/apache2/error.log),可获取搜索的DN、过滤器、绑定状态等信息,定位具体问题。
4. 模拟Apache的LDAP搜索流程
用ldapsearch复现Apache的验证步骤,确认LDAP服务本身无问题:
- 用管理员账号搜索用户条目(模拟Apache查找用户DN的过程):
ldapsearch -x -LLL -H ldap://testserver -D "cn=admin,dc=testserver" -w "password" -b "ou=people,dc=testserver" -s one "(objectClass=posixAccount)" dn
- 用找到的用户DN尝试绑定(模拟Apache验证密码的过程):
ldapsearch -x -LLL -H ldap://testserver -D "uid=billy,ou=people,dc=testserver" -w "用户输入的密码" -b "dc=testserver" -s children "(objectClass=*)"
若这两步都成功,说明LDAP服务正常,问题出在Apache配置细节。
内容的提问来源于stack exchange,提问作者Mister Rose
相关产品推荐
相关产品推荐

