Django配置多LDAP服务器问题:按指定语法配置仍无法实现
Hey there! Let's walk through setting up multiple LDAP servers in your Django project—this is a common scenario that the docs sometimes gloss over, so I'll break it down into two practical approaches depending on your needs.
Approach 1: Multiple Independent LDAP Authentication Backends
Use this if you need users to authenticate against two distinct LDAP servers (e.g., one for internal staff, another for external partners). Each server will have its own configuration and act as a separate authentication backend.
First, if you haven’t already, make sure django-auth-ldap is installed. Then update your settings.py like this:
import ldap from django_auth_ldap.config import LDAPSearch, GroupOfNamesType from django_auth_ldap.backend import LDAPBackend # ------------------------------ # First LDAP Server Configuration # ------------------------------ AUTH_LDAP_SERVER_URI = "ldap://first-ldap.example.com" AUTH_LDAP_BIND_DN = "cn=admin,dc=example,dc=com" AUTH_LDAP_BIND_PASSWORD = "your_first_ldap_bind_password" AUTH_LDAP_USER_SEARCH = LDAPSearch( "ou=users,dc=example,dc=com", ldap.SCOPE_SUBTREE, "(uid=%(user)s)" # Adjust this filter to match your LDAP's user identifier ) AUTH_LDAP_GROUP_SEARCH = LDAPSearch( "ou=groups,dc=example,dc=com", ldap.SCOPE_SUBTREE, "(objectClass=groupOfNames)" ) AUTH_LDAP_GROUP_TYPE = GroupOfNamesType(name_attr="cn") AUTH_LDAP_USER_ATTR_MAP = { "first_name": "givenName", "last_name": "sn", "email": "mail" } # ------------------------------ # Second LDAP Server Backend # ------------------------------ # Create a custom backend to isolate the second LDAP's configuration class SecondaryLDAPBackend(LDAPBackend): # This prefix tells the backend to use settings starting with AUTH_LDAP_SECONDARY_ settings_prefix = "AUTH_LDAP_SECONDARY_" # Second LDAP Server Configuration AUTH_LDAP_SECONDARY_SERVER_URI = "ldap://second-ldap.example.com" AUTH_LDAP_SECONDARY_BIND_DN = "cn=admin,dc=another,dc=com" AUTH_LDAP_SECONDARY_BIND_PASSWORD = "your_second_ldap_bind_password" AUTH_LDAP_SECONDARY_USER_SEARCH = LDAPSearch( "ou=users,dc=another,dc=com", ldap.SCOPE_SUBTREE, "(sAMAccountName=%(user)s)" # Example for Active Directory ) AUTH_LDAP_SECONDARY_GROUP_SEARCH = LDAPSearch( "ou=groups,dc=another,dc=com", ldap.SCOPE_SUBTREE, "(objectClass=groupOfNames)" ) AUTH_LDAP_SECONDARY_GROUP_TYPE = GroupOfNamesType(name_attr="cn") AUTH_LDAP_SECONDARY_USER_ATTR_MAP = { "first_name": "givenName", "last_name": "sn", "email": "mail" } # ------------------------------ # Add Both Backends to Authentication List # ------------------------------ AUTHENTICATION_BACKENDS = [ # Keep ModelBackend if you want to allow local Django users too "django.contrib.auth.backends.ModelBackend", # First LDAP backend "django_auth_ldap.backend.LDAPBackend", # Second custom LDAP backend (use the correct path to your class) "your_project.settings.SecondaryLDAPBackend", ]
How This Works
When a user tries to log in, Django will attempt to authenticate against each backend in the order listed. If the first LDAP server rejects the credentials, it will fall back to the second one.
Approach 2: LDAP Server Pool (Failover/Load Balancing)
Use this if you have multiple identical LDAP servers (e.g., primary and secondary for high availability) and want Django to automatically switch between them if one goes down.
import ldap from django_auth_ldap.config import LDAPSearch, GroupOfNamesType, PooledConnectionFactory # ------------------------------ # Server Pool Configuration # ------------------------------ # List your LDAP servers in order of priority AUTH_LDAP_SERVER_URI = ["ldap://primary-ldap.example.com", "ldap://secondary-ldap.example.com"] # Enable connection pooling for better performance and failover AUTH_LDAP_CONNECTION_FACTORY = PooledConnectionFactory( ldap.OPT_X_TLS_DEMAND, timeout=30, pool_size=10, ) # ------------------------------ # Shared LDAP Configuration # ------------------------------ # These settings apply to all servers in the pool (since they're identical) AUTH_LDAP_BIND_DN = "cn=admin,dc=example,dc=com" AUTH_LDAP_BIND_PASSWORD = "your_bind_password" AUTH_LDAP_USER_SEARCH = LDAPSearch( "ou=users,dc=example,dc=com", ldap.SCOPE_SUBTREE, "(uid=%(user)s)" ) AUTH_LDAP_GROUP_SEARCH = LDAPSearch( "ou=groups,dc=example,dc=com", ldap.SCOPE_SUBTREE, "(objectClass=groupOfNames)" ) AUTH_LDAP_GROUP_TYPE = GroupOfNamesType(name_attr="cn") AUTH_LDAP_USER_ATTR_MAP = { "first_name": "givenName", "last_name": "sn", "email": "mail" } # ------------------------------ # Authentication Backends # ------------------------------ AUTHENTICATION_BACKENDS = [ "django_auth_ldap.backend.LDAPBackend", "django.contrib.auth.backends.ModelBackend", ]
How This Works
Django will try the first server in the list; if it’s unreachable, it will automatically fall back to the next one. This is ideal for high availability setups where all servers share the same directory structure.
Key Notes to Remember
- Test Individually First: Before combining configurations, verify that each LDAP server works correctly on its own.
- Adjust Filters/Attributes: Make sure user search filters (like
(uid=%(user)s)or(sAMAccountName=%(user)s)) match your LDAP server’s schema. - Debug Logging: Enable debug logs for
django-auth-ldapto troubleshoot authentication issues:LOGGING = { "version": 1, "disable_existing_loggers": False, "handlers": { "console": {"class": "logging.StreamHandler"}, }, "loggers": { "django_auth_ldap": { "handlers": ["console"], "level": "DEBUG", }, }, }
内容的提问来源于stack exchange,提问作者Sahil Sahay

