You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

新手求助:CentOS通过LDAP/Kerberos对接AD认证失败

Troubleshooting AD Authentication Failure on CentOS with LDAP/Kerberos

Hey there, let's work through this AD authentication issue step by step—since you're new to this space, I'll keep things straightforward and actionable.

1. Verify Basic Network & DNS Connectivity

First, make sure your CentOS host can reach the AD server both via IP and hostname:

  • Ping the AD server IP: ping 10.0.2.15
  • Ping the AD server hostname: ping SERVER.EXAMPLE.LOCAL
    If hostname resolution fails, check your /etc/resolv.conf to ensure it includes your AD server's DNS IP (AD relies heavily on DNS for Kerberos and LDAP lookups).

2. Validate Kerberos Configuration & Ticket Retrieval

Kerberos is often the culprit here—let's confirm it's working correctly:

a. Check Time Synchronization

Kerberos requires your CentOS host and AD server to have a time difference of no more than 5 minutes. Sync your time with the AD server:

ntpdate 10.0.2.15
# Or set up chrony permanently (recommended)
echo "server 10.0.2.15 iburst" >> /etc/chrony.conf
systemctl restart chronyd

b. Test Kerberos Ticket Acquisition

Use a valid AD user account to request a Kerberos ticket:

kinit your_ad_username@EXAMPLE.LOCAL

If this fails, note the error message:

  • "Preauthentication failed": Double-check the password or ensure the user isn't locked in AD.
  • "Cannot contact any KDC for realm": Confirm the KDC IP is correct and port 88 (Kerberos) is open on both firewalls.

c. Verify krb5.conf Settings

Ensure your /etc/krb5.conf has these critical entries (adjust if missing):

[libdefaults]
default_realm = EXAMPLE.LOCAL
dns_lookup_realm = true
dns_lookup_kdc = true

[realms]
EXAMPLE.LOCAL = {
 kdc = 10.0.2.15
 admin_server = SERVER.EXAMPLE.LOCAL
 default_domain = EXAMPLE.LOCAL
}

[domain_realm]
.example.local = EXAMPLE.LOCAL
example.local = EXAMPLE.LOCAL

3. Test LDAP Connectivity & Schema Compatibility

Next, confirm your CentOS host can query the AD LDAP service:

a. Run an LDAP Search Test

ldapsearch -x -H ldap://10.0.2.15 -b dc=example,dc=local

If this returns no results or errors:

  • Check that port 389 (LDAP) is open on the AD server and your CentOS firewall:
    firewall-cmd --add-port=389/tcp --permanent
    firewall-cmd --reload
    

b. Update SSSD LDAP Settings for AD

Since you're connecting to Active Directory, your sssd.conf needs AD-specific schema settings. Add these to your domain section:

[domain/example.local]
autofs_provider = ldap
cache_credentials = True
krb5_kpasswd = SERVER.EXAMPLE.LOCAL
ldap_search_base = dc=example,dc=local
krb5_server = 10.0.2.15
id_provider = ldap
auth_provider = krb5
# Critical AD-specific additions
ldap_schema = ad
ldap_user_principal = userPrincipalName
ldap_sasl_mech = GSSAPI

c. Secure SSSD Configuration File

SSSD requires strict permissions on its config file—fix it if needed:

chmod 600 /etc/sssd/sssd.conf

4. Restart Services & Check Logs

After updating configs, restart the SSSD service and verify it's running:

systemctl restart sssd
systemctl status sssd

If it fails to start, check the SSSD logs for detailed errors:

  • Tail the domain-specific log: tail -f /var/log/sssd/sssd_example.local.log
  • Check the main SSSD log: tail -f /var/log/sssd/sssd.log
    Look for messages like "LDAP query failed" or "Kerberos authentication failed"—these will point you to the exact issue.

5. Test Authentication

Once SSSD is running, test if you can resolve an AD user:

getent passwd your_ad_username

If this returns the user's details, try switching to the user account to confirm authentication works:

su - your_ad_username

内容的提问来源于stack exchange,提问作者estelarules

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 03:16:45