You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Apache2 LDAP认证从UID切换为ANR方法及部分用户未找到问题咨询

问题解答

1. 什么是ANR

ANR是*Ambiguous Name Resolution(模糊名称解析)*的缩写,是微软Active Directory专属的查询特性。开启ANR校验后,AD会自动将用户输入的登录名同时匹配多个用户属性,包括sAMAccountName(AD默认登录名)、显示名、邮箱、别名等常用字段,无需单独指定查询单个属性,适配性远高于单字段匹配。

2. 少数用户登录失败的原因

你当前的配置没有指定LDAP查询的匹配字段,Apache mod_ldap模块默认使用uid字段匹配用户输入的登录名。

  • 大部分用户可以正常登录,是因为他们的AD账号中uid属性值和日常使用的登录名一致
  • 那2名登录失败的用户,AD账号中要么没有填充uid属性,要么uid属性值和他们日常使用的登录名不一致,所以查询返回不存在。其他AD服务正常是因为这类服务默认使用ANR或者sAMAccountName做匹配,没有依赖uid字段。

3. 切换为ANR校验的配置修改方法

只需要修改<Proxy>段中的AuthLDAPURL配置项即可,修改后的完整配置如下:

<VirtualHost *:80>
    ServerName mydomain
    Redirect permanent / https://mydomain/
</VirtualHost>

<VirtualHost *:443>
    SSLProxyEngine on
    SSLCertificateFile /etc/apache2/ssl/mydomain.pem
    SSLCertificateKeyFile /etc/apache2/ssl/mydomain.key
    ProxyPreserveHost on
    ProxyRequests off
    ServerName mydomain
    ProxyPass / http://0.0.0.0:8080/
    ProxyPassReverse / http://0.0.0.0:8080/
    <Proxy *>
        AuthType Basic
        Authname "Password Required"
        AuthBasicProvider ldap
        <!-- 修改此行,替换<domain>为你实际的域前缀,和AuthLDAPBindDN中的DC值保持一致 -->
        AuthLDAPURL ldaps://realm.domain.local:3269/DC=<domain>,DC=local?anr?sub?(objectClass=user)
        #AuthLDAPCompareAsUser on
        #LDAPReferrals off
        AuthLDAPBindDN "CN=SVC-Auth,OU=ServiceAccounts,DC=<domain>,DC=local"
        AuthLDAPBindPassword "<password>"
        Require valid-user
    </Proxy>
</VirtualHost>

修改完成后执行systemctl restart apache2(Debian/Ubuntu系)或systemctl restart httpd(RHEL/CentOS系)重启服务生效。


内容的提问来源于stack exchange,提问作者Nate Houk

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.30 19:54:06