Django项目中LDAP用户认证问题求助(Python 2.7环境)
Hey there! Let's work through your LDAP authentication issue with Django Admin on Python 2.7. I’ve tackled plenty of these scenarios before, so here’s a step-by-step breakdown to get you sorted:
settings.py Most LDAP auth failures boil down to misconfigured settings. Here’s what to verify:
- Server URI: Ensure
AUTH_LDAP_SERVER_URIuses the correct protocol (ldap://for unencrypted,ldaps://for SSL) and matches your LDAP server’s address/port (default 389 for ldap, 636 for ldaps). - Bind Credentials: Confirm
AUTH_LDAP_BIND_DNandAUTH_LDAP_BIND_PASSWORDbelong to an account with permission to search and read user attributes on your LDAP server. - User Search: Check that
AUTH_LDAP_USER_SEARCHuses the right base DN (e.g.,ou=users,dc=yourdomain,dc=com) and filter (e.g.,(uid=%(user)s)or(sAMAccountName=%(user)s)for Active Directory) that matches your LDAP user structure. - Attribute Mapping: Make sure
AUTH_LDAP_USER_ATTR_MAPcorrectly maps LDAP attributes to Django user fields (likeusernametouidoremailtomail). - Authentication Backends: Don’t forget to include both the LDAP backend and Django’s default backend in
AUTHENTICATION_BACKENDSif you want to log in with local superusers too:
Example of a solid basic LDAP config snippet:
import ldap from django_auth_ldap.config import LDAPSearch AUTH_LDAP_SERVER_URI = "ldap://your-ldap-server:389" AUTH_LDAP_BIND_DN = "cn=admin,dc=yourdomain,dc=com" AUTH_LDAP_BIND_PASSWORD = "your-admin-pass" AUTH_LDAP_USER_SEARCH = LDAPSearch( "ou=users,dc=yourdomain,dc=com", ldap.SCOPE_SUBTREE, "(uid=%(user)s)" ) AUTH_LDAP_USER_ATTR_MAP = { "username": "uid", "email": "mail" } # Keep default backend for local superuser access AUTHENTICATION_BACKENDS = ( 'django_auth_ldap.backend.LDAPBackend', 'django.contrib.auth.backends.ModelBackend', )
auth_connection.py Custom Logic If this is a custom file handling LDAP connections, watch for these pitfalls:
- Did you accidentally override
django_auth_ldap’s default binding or user lookup flow? Even small changes here can break authentication. - Are you properly handling LDAP exceptions (like connection timeouts or invalid credentials) and passing them up to Django’s auth system?
- If this is a custom auth backend, confirm it’s listed in
AUTHENTICATION_BACKENDSand implements the required methods correctly.
pip freeze Python 2.7 has strict version compatibility rules, so check these:
- python-ldap: For Python 2.7, stick to versions like
2.4.45—newer versions dropped Python 2 support. Make sure it’s compatible with your LDAP server (OpenLDAP vs. Active Directory). - django-auth-ldap: Match it to your Django version (Django 1.11 is the last release supporting Python 2.7; use
django-auth-ldap==1.7.0for compatibility). - Dependency Conflicts: Check for mismatched versions of
pyasn1orpyasn1-modules—these are critical forpython-ldapto work properly.
Turn on Django’s LDAP debug logs to see exactly what’s going wrong during authentication. Add this to your settings.py:
import logging logger = logging.getLogger('django_auth_ldap') logger.addHandler(logging.StreamHandler()) logger.setLevel(logging.DEBUG)
Try logging in again, then check your console for details like:
- Did the LDAP connection succeed?
- Was the user found in the LDAP directory?
- Are attributes being mapped correctly to Django user fields?
If your local Django superuser can’t log in, make sure:
- You haven’t removed
django.contrib.auth.backends.ModelBackendfromAUTHENTICATION_BACKENDS—the LDAP backend only handles LDAP users, not local superusers. - Your superuser account is active in the Django database (check via
python manage.py shellor the database directly).
If you can share the exact error message, your full settings.py LDAP config, auth_connection.py code, and pip freeze output, I can narrow this down even further!
内容的提问来源于stack exchange,提问作者Dr.Gonzo

