Laravel 5.8集成LdapRecord实现Active Directory认证失败求助
Hey there! Since your OpenLDAP auth is working, your core Laravel + LdapRecord setup is solid—let's focus on the Active Directory-specific quirks that are likely causing the issue. Here's a step-by-step breakdown to fix this:
1. Add a Valid LDAP Bind User
Active Directory requires a dedicated bind user to perform user searches (unlike some OpenLDAP configurations that allow anonymous access). Right now, your ldap.php config has empty username and password values—let's fix that:
First, update your .env file with a valid AD bind account (use either the DOMAIN\username format or UPN like username@mydomain.local):
LDAP_USERNAME="mydomain\ad_bind_user" LDAP_PASSWORD="your_bind_user_password"
This bind user needs permission to read user entries in your AD domain. If you don't have one, create a low-privilege account specifically for LDAP queries.
2. Fix the Authentication Field Mapping
You're using uid in your LoginController's credentials method—but AD uses sAMAccountName as the default login field (this is the "username" users use to log into Windows). OpenLDAP commonly uses uid, which is why that worked.
Update your LoginController's credentials method:
protected function credentials(Request $request) { return [ 'sAMAccountName' => $request->get('username'), 'password' => $request->get('password'), ]; }
If your users log in with their full UPN (e.g., user@mydomain.local), replace sAMAccountName with userPrincipalName instead.
3. Correct the User Model Trait
I noticed your App\User model includes HasLdapUser but doesn't specify the full namespace. This will cause a fatal error. Update the trait import to:
use LdapRecord\Laravel\Auth\HasLdapUser;
Your corrected model traits should look like:
use Notifiable, AuthenticatesWithLdap, HasLdapUser;
4. Check LDAP Logs for Detailed Errors
You already enabled LDAP_LOGGING=true—great! Head to storage/logs/laravel.log and look for LDAP-related entries. Common errors here include:
Invalid credentials: Either the bind user or end-user credentials are wrongInsufficient access rights: The bind user doesn't have permission to read AD user entriesNo such object: YourLDAP_BASE_DNis incorrect, or the user can't be found in the specified base DN
These logs will give you precise clues about what's failing.
5. Verify AD Connection & Base DN
- Double-check that
LDAP_HOSTis the correct IP or hostname of your AD domain controller (ensure your Laravel server can ping it). - Confirm your
LDAP_BASE_DNmatches your AD domain exactly. For example, if your domain ismydomain.local,dc=mydomain,dc=localis correct—but if users are stored in an OU likeOU=Employees,DC=mydomain,DC=local, update your base DN to include that, or add asearch_baseto your LDAP provider inauth.php:'ldap' => [ 'driver' => 'ldap', 'model' => LdapRecord\Models\ActiveDirectory\User::class, 'database' => [ // ... existing database config ], 'search_base' => 'ou=Employees,dc=mydomain,dc=local', ]
6. Test Direct LDAP Binding (Bypass Laravel Auth)
To rule out issues with Laravel's auth layer, create a quick test route to directly bind an AD user:
Route::get('/test-ad-auth', function () { $username = request('username'); $password = request('password'); $user = LdapRecord\Models\ActiveDirectory\User::where('sAMAccountName', $username)->first(); if ($user && $user->canBind($password)) { return "Successfully authenticated user: {$user->cn}"; } return "Authentication failed. Check logs for details."; });
Visit this route with ?username=your_ad_user&password=their_password—if this works, the issue is in your Laravel auth setup; if not, the problem is with LDAP/AD configuration itself.
Start with steps 1 and 2—those are the most common AD gotchas. Let me know what you find in the logs!
内容的提问来源于stack exchange,提问作者Алина Смирнова

