新手求助:CentOS通过LDAP/Kerberos对接AD认证失败
Hey there, let's work through this AD authentication issue step by step—since you're new to this space, I'll keep things straightforward and actionable.
1. Verify Basic Network & DNS Connectivity
First, make sure your CentOS host can reach the AD server both via IP and hostname:
- Ping the AD server IP:
ping 10.0.2.15 - Ping the AD server hostname:
ping SERVER.EXAMPLE.LOCAL
If hostname resolution fails, check your/etc/resolv.confto ensure it includes your AD server's DNS IP (AD relies heavily on DNS for Kerberos and LDAP lookups).
2. Validate Kerberos Configuration & Ticket Retrieval
Kerberos is often the culprit here—let's confirm it's working correctly:
a. Check Time Synchronization
Kerberos requires your CentOS host and AD server to have a time difference of no more than 5 minutes. Sync your time with the AD server:
ntpdate 10.0.2.15 # Or set up chrony permanently (recommended) echo "server 10.0.2.15 iburst" >> /etc/chrony.conf systemctl restart chronyd
b. Test Kerberos Ticket Acquisition
Use a valid AD user account to request a Kerberos ticket:
kinit your_ad_username@EXAMPLE.LOCAL
If this fails, note the error message:
- "Preauthentication failed": Double-check the password or ensure the user isn't locked in AD.
- "Cannot contact any KDC for realm": Confirm the KDC IP is correct and port 88 (Kerberos) is open on both firewalls.
c. Verify krb5.conf Settings
Ensure your /etc/krb5.conf has these critical entries (adjust if missing):
[libdefaults] default_realm = EXAMPLE.LOCAL dns_lookup_realm = true dns_lookup_kdc = true [realms] EXAMPLE.LOCAL = { kdc = 10.0.2.15 admin_server = SERVER.EXAMPLE.LOCAL default_domain = EXAMPLE.LOCAL } [domain_realm] .example.local = EXAMPLE.LOCAL example.local = EXAMPLE.LOCAL
3. Test LDAP Connectivity & Schema Compatibility
Next, confirm your CentOS host can query the AD LDAP service:
a. Run an LDAP Search Test
ldapsearch -x -H ldap://10.0.2.15 -b dc=example,dc=local
If this returns no results or errors:
- Check that port 389 (LDAP) is open on the AD server and your CentOS firewall:
firewall-cmd --add-port=389/tcp --permanent firewall-cmd --reload
b. Update SSSD LDAP Settings for AD
Since you're connecting to Active Directory, your sssd.conf needs AD-specific schema settings. Add these to your domain section:
[domain/example.local] autofs_provider = ldap cache_credentials = True krb5_kpasswd = SERVER.EXAMPLE.LOCAL ldap_search_base = dc=example,dc=local krb5_server = 10.0.2.15 id_provider = ldap auth_provider = krb5 # Critical AD-specific additions ldap_schema = ad ldap_user_principal = userPrincipalName ldap_sasl_mech = GSSAPI
c. Secure SSSD Configuration File
SSSD requires strict permissions on its config file—fix it if needed:
chmod 600 /etc/sssd/sssd.conf
4. Restart Services & Check Logs
After updating configs, restart the SSSD service and verify it's running:
systemctl restart sssd systemctl status sssd
If it fails to start, check the SSSD logs for detailed errors:
- Tail the domain-specific log:
tail -f /var/log/sssd/sssd_example.local.log - Check the main SSSD log:
tail -f /var/log/sssd/sssd.log
Look for messages like "LDAP query failed" or "Kerberos authentication failed"—these will point you to the exact issue.
5. Test Authentication
Once SSSD is running, test if you can resolve an AD user:
getent passwd your_ad_username
If this returns the user's details, try switching to the user account to confirm authentication works:
su - your_ad_username
内容的提问来源于stack exchange,提问作者estelarules

