You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Django配置多LDAP服务器问题:按指定语法配置仍无法实现

Configuring Multiple LDAP Servers in Django Settings

Hey there! Let's walk through setting up multiple LDAP servers in your Django project—this is a common scenario that the docs sometimes gloss over, so I'll break it down into two practical approaches depending on your needs.

Approach 1: Multiple Independent LDAP Authentication Backends

Use this if you need users to authenticate against two distinct LDAP servers (e.g., one for internal staff, another for external partners). Each server will have its own configuration and act as a separate authentication backend.

First, if you haven’t already, make sure django-auth-ldap is installed. Then update your settings.py like this:

import ldap
from django_auth_ldap.config import LDAPSearch, GroupOfNamesType
from django_auth_ldap.backend import LDAPBackend

# ------------------------------
# First LDAP Server Configuration
# ------------------------------
AUTH_LDAP_SERVER_URI = "ldap://first-ldap.example.com"
AUTH_LDAP_BIND_DN = "cn=admin,dc=example,dc=com"
AUTH_LDAP_BIND_PASSWORD = "your_first_ldap_bind_password"
AUTH_LDAP_USER_SEARCH = LDAPSearch(
    "ou=users,dc=example,dc=com",
    ldap.SCOPE_SUBTREE,
    "(uid=%(user)s)"  # Adjust this filter to match your LDAP's user identifier
)
AUTH_LDAP_GROUP_SEARCH = LDAPSearch(
    "ou=groups,dc=example,dc=com",
    ldap.SCOPE_SUBTREE,
    "(objectClass=groupOfNames)"
)
AUTH_LDAP_GROUP_TYPE = GroupOfNamesType(name_attr="cn")
AUTH_LDAP_USER_ATTR_MAP = {
    "first_name": "givenName",
    "last_name": "sn",
    "email": "mail"
}

# ------------------------------
# Second LDAP Server Backend
# ------------------------------
# Create a custom backend to isolate the second LDAP's configuration
class SecondaryLDAPBackend(LDAPBackend):
    # This prefix tells the backend to use settings starting with AUTH_LDAP_SECONDARY_
    settings_prefix = "AUTH_LDAP_SECONDARY_"

# Second LDAP Server Configuration
AUTH_LDAP_SECONDARY_SERVER_URI = "ldap://second-ldap.example.com"
AUTH_LDAP_SECONDARY_BIND_DN = "cn=admin,dc=another,dc=com"
AUTH_LDAP_SECONDARY_BIND_PASSWORD = "your_second_ldap_bind_password"
AUTH_LDAP_SECONDARY_USER_SEARCH = LDAPSearch(
    "ou=users,dc=another,dc=com",
    ldap.SCOPE_SUBTREE,
    "(sAMAccountName=%(user)s)"  # Example for Active Directory
)
AUTH_LDAP_SECONDARY_GROUP_SEARCH = LDAPSearch(
    "ou=groups,dc=another,dc=com",
    ldap.SCOPE_SUBTREE,
    "(objectClass=groupOfNames)"
)
AUTH_LDAP_SECONDARY_GROUP_TYPE = GroupOfNamesType(name_attr="cn")
AUTH_LDAP_SECONDARY_USER_ATTR_MAP = {
    "first_name": "givenName",
    "last_name": "sn",
    "email": "mail"
}

# ------------------------------
# Add Both Backends to Authentication List
# ------------------------------
AUTHENTICATION_BACKENDS = [
    # Keep ModelBackend if you want to allow local Django users too
    "django.contrib.auth.backends.ModelBackend",
    # First LDAP backend
    "django_auth_ldap.backend.LDAPBackend",
    # Second custom LDAP backend (use the correct path to your class)
    "your_project.settings.SecondaryLDAPBackend",
]

How This Works

When a user tries to log in, Django will attempt to authenticate against each backend in the order listed. If the first LDAP server rejects the credentials, it will fall back to the second one.


Approach 2: LDAP Server Pool (Failover/Load Balancing)

Use this if you have multiple identical LDAP servers (e.g., primary and secondary for high availability) and want Django to automatically switch between them if one goes down.

import ldap
from django_auth_ldap.config import LDAPSearch, GroupOfNamesType, PooledConnectionFactory

# ------------------------------
# Server Pool Configuration
# ------------------------------
# List your LDAP servers in order of priority
AUTH_LDAP_SERVER_URI = ["ldap://primary-ldap.example.com", "ldap://secondary-ldap.example.com"]

# Enable connection pooling for better performance and failover
AUTH_LDAP_CONNECTION_FACTORY = PooledConnectionFactory(
    ldap.OPT_X_TLS_DEMAND,
    timeout=30,
    pool_size=10,
)

# ------------------------------
# Shared LDAP Configuration
# ------------------------------
# These settings apply to all servers in the pool (since they're identical)
AUTH_LDAP_BIND_DN = "cn=admin,dc=example,dc=com"
AUTH_LDAP_BIND_PASSWORD = "your_bind_password"
AUTH_LDAP_USER_SEARCH = LDAPSearch(
    "ou=users,dc=example,dc=com",
    ldap.SCOPE_SUBTREE,
    "(uid=%(user)s)"
)
AUTH_LDAP_GROUP_SEARCH = LDAPSearch(
    "ou=groups,dc=example,dc=com",
    ldap.SCOPE_SUBTREE,
    "(objectClass=groupOfNames)"
)
AUTH_LDAP_GROUP_TYPE = GroupOfNamesType(name_attr="cn")
AUTH_LDAP_USER_ATTR_MAP = {
    "first_name": "givenName",
    "last_name": "sn",
    "email": "mail"
}

# ------------------------------
# Authentication Backends
# ------------------------------
AUTHENTICATION_BACKENDS = [
    "django_auth_ldap.backend.LDAPBackend",
    "django.contrib.auth.backends.ModelBackend",
]

How This Works

Django will try the first server in the list; if it’s unreachable, it will automatically fall back to the next one. This is ideal for high availability setups where all servers share the same directory structure.


Key Notes to Remember

  • Test Individually First: Before combining configurations, verify that each LDAP server works correctly on its own.
  • Adjust Filters/Attributes: Make sure user search filters (like (uid=%(user)s) or (sAMAccountName=%(user)s)) match your LDAP server’s schema.
  • Debug Logging: Enable debug logs for django-auth-ldap to troubleshoot authentication issues:
    LOGGING = {
        "version": 1,
        "disable_existing_loggers": False,
        "handlers": {
            "console": {"class": "logging.StreamHandler"},
        },
        "loggers": {
            "django_auth_ldap": {
                "handlers": ["console"],
                "level": "DEBUG",
            },
        },
    }
    

内容的提问来源于stack exchange,提问作者Sahil Sahay

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 10:35:05