Grails集成OpenLDAP登录失败:无法匹配用户名与密码
Hey there, let’s work through why your Grails LDAP login is failing with that "user not found" error. Here are the key areas to check step by step:
1. Complete Your LDAP Context Server Configuration
It looks like your grails.plugin.springsecurity.ldap.context.server config was cut off—this is a critical setting that tells Grails where your LDAP server lives. Add this line to your Config.groovy:
grails.plugin.springsecurity.ldap.context.server = 'ldap://your-ldap-host:389'
If you’re using LDAPS, switch it to ldaps://your-ldap-host:636 and make sure the port is open and your server is reachable from your Grails app.
2. Verify User Search Rules
LDAP needs to know how to locate user entries based on the login username. You’re likely missing these key search configurations:
// The base DN where your user accounts are stored grails.plugin.springsecurity.ldap.search.base = 'ou=users,dc=sw01,dc=com' // The LDAP attribute that matches the login username (adjust if you use cn/mail instead of uid) grails.plugin.springsecurity.ldap.search.filter = 'uid={0}'
The {0} gets replaced with the username entered at login. Double-check that the attribute in the filter matches what’s actually stored in your LDAP user entries.
3. Test the Manager DN Credentials
First, confirm your admin LDAP credentials work outside of Grails. Use the ldapsearch command to test the manager bind:
ldapsearch -x -D "uid=admin,dc=sw01,dc=com" -w "Admin123" -H ldap://your-ldap-host:389 -b "dc=sw01,dc=com" "(objectClass=*)"
If this command fails, your manager DN is incorrect, the password is wrong, or the LDAP server is refusing connections. Fix this first before moving on.
4. Validate the Test User’s Existence and Password
Make sure the username you’re trying to log in with actually exists in LDAP, and its password is correct. Use the manager credentials to search for the user:
ldapsearch -x -D "uid=admin,dc=sw01,dc=com" -w "Admin123" -H ldap://your-ldap-host:389 -b "ou=users,dc=sw01,dc=com" "(uid=your-test-username)"
If the user is found, try binding directly with their credentials to confirm the password works:
ldapsearch -x -D "uid=your-test-username,ou=users,dc=sw01,dc=com" -w "user-password" -H ldap://your-ldap-host:389 -b "dc=sw01,dc=com" "(objectClass=*)"
A failure here means the user’s password is incorrect or their account is locked/restricted.
5. Enable Debug Logging for Spring Security
Add debug logging to Config.groovy to see exactly what’s happening during the LDAP authentication flow:
log4j = { debug 'org.springframework.security', 'org.springframework.ldap' }
The logs will show details like whether the LDAP bind succeeded, if the user search returned any results, and where the process fails—this is often the fastest way to pinpoint the issue.
6. Check LDAP Server Permissions
Ensure your manager account has permission to search user entries, and that regular user accounts are allowed to bind to the server (some LDAP configurations restrict this). Also, confirm the userPassword attribute exists on user entries and uses a format your Grails setup supports (like SSHA or plaintext, though plaintext is not recommended for production).
内容的提问来源于stack exchange,提问作者alchn

