You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Apache AuthLDAPURL与ldapsearch匹配问题排查求助

问题描述

在Ubuntu 22.04环境中,使用OpenLDAP(2022年5月12日版本)与Apache 2.4.41,可通过ldapsearch成功验证用户凭据,但转换为Apache配置后无法正常工作。配置AuthLDAPURL后,存在的用户billy及不存在的用户eric均报“密码不匹配”错误,需要调整AuthLDAPURL以匹配ldapsearch逻辑,或模拟Apache的LDAP搜索行为排查问题。

环境与测试信息

可用的ldapsearch验证命令

# 用管理员账号搜索用户billy的条目
ldapsearch -x -LLL -H ldap://testserver -D "cn=admin,dc=testserver" -W -b "ou=people,dc=testserver" -s children "(&(objectClass=posixAccount)(uid=billy))" dn
# 输入密码后返回:
dn: uid=billy,ou=people,dc=testserver

# 用用户billy的账号绑定并搜索目录
ldapsearch -x -LLL -H ldap://testserver -D "uid=billy,ou=people,dc=testserver" -W -b "dc=testserver" -s children "(objectClass=*)"
# 输入正确密码后可打印dc=testserver下的目录树

当前Apache配置

<Location /svn/>
    DAV svn
    SVNParentPath /var/svn
    SVNListParentPath On
    AuthName '请使用你的Testserver账号登录'
    AuthType Basic
    AuthBasicProvider ldap
    AuthLDAPBindDN "cn=admin,dc=testserver"
    AuthLDAPBindPassword "password"
    # 测试用的用户账号配置
    AuthLDAPURL "ldap://testserver:389/ou=people,dc=testserver?uid?sub?(ObjectClass=*)"
    require valid-user
</Location>

LDAP目录结构

dn: ou=people,dc=testserver
objectClass: organizationalUnit
ou: people

dn: ou=groups,dc=testserver
objectClass: organizationalUnit
ou: groups

dn: uid=billy,ou=people,dc=testserver
objectClass: inetOrgPerson
objectClass: posixAccount
objectClass: shadowAccount
cn: Bill
sn: Belichick
userPassword: {SSHA}pr4TabkZcr/ZAtiHBgL6bF1jvuvIJ6dn
loginShell: /bin/bash
uidNumber: 2001
gidNumber: 2001
homeDirectory: /home/bill

dn: ou=svn,ou=groups,dc=testserver
objectClass: organizationalUnit
ou: groups

dn: cn=svn_folder_repo1_rw,ou=svn,ou=groups,dc=testserver
objectClass: groupOfNames
cn: svn_folder_repo1_rw
member: uid=billy,ou=people,dc=testserver

Apache错误日志

[Thu Aug 11 02:24:04.914162 2022] [auth_basic:error] [pid 4631] [client 192.168.99.1:49323] AH01617: user billy: authentication failure for "/svn/": Password Mismatch

# 测试不存在的用户eric时的错误
[Thu Aug 11 11:43:13.916494 2022] [auth_basic:error] [pid 619] [client 192.168.99.1:60322] AH01617: user eric: authentication failure for "/svn/": Password Mismatch

解决方案

1. 修正AuthLDAPURL配置,匹配ldapsearch逻辑

当前AuthLDAPURL的搜索范围和过滤器与ldapsearch不一致,导致无法正确定位用户条目。修改为:

AuthLDAPURL "ldap://testserver:389/ou=people,dc=testserver?uid?one?(objectClass=posixAccount)"
  • one:对应ldapsearch的-s children,仅搜索ou=people的直接子节点(用户条目)
  • (objectClass=posixAccount):和ldapsearch中的过滤器一致,精准匹配用户条目

2. 验证Apache LDAP模块是否加载

确保mod_ldap和mod_authnz_ldap已加载:

apache2ctl -M | grep ldap

若未加载,执行以下命令启用:

a2enmod ldap authnz_ldap
systemctl restart apache2

3. 启用LDAP调试日志排查细节

在Apache全局配置中添加调试日志级别,查看详细的LDAP交互过程:

LogLevel ldap_debug

重启Apache后,查看错误日志(默认路径/var/log/apache2/error.log),可获取搜索的DN、过滤器、绑定状态等信息,定位具体问题。

4. 模拟Apache的LDAP搜索流程

用ldapsearch复现Apache的验证步骤,确认LDAP服务本身无问题:

  1. 用管理员账号搜索用户条目(模拟Apache查找用户DN的过程):
ldapsearch -x -LLL -H ldap://testserver -D "cn=admin,dc=testserver" -w "password" -b "ou=people,dc=testserver" -s one "(objectClass=posixAccount)" dn
  1. 用找到的用户DN尝试绑定(模拟Apache验证密码的过程):
ldapsearch -x -LLL -H ldap://testserver -D "uid=billy,ou=people,dc=testserver" -w "用户输入的密码" -b "dc=testserver" -s children "(objectClass=*)"

若这两步都成功,说明LDAP服务正常,问题出在Apache配置细节。


内容的提问来源于stack exchange,提问作者Mister Rose

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.23 01:54:22