You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Grails集成OpenLDAP登录失败:无法匹配用户名与密码

Hey there, let’s work through why your Grails LDAP login is failing with that "user not found" error. Here are the key areas to check step by step:

Troubleshooting Grails LDAP Login Failure

1. Complete Your LDAP Context Server Configuration

It looks like your grails.plugin.springsecurity.ldap.context.server config was cut off—this is a critical setting that tells Grails where your LDAP server lives. Add this line to your Config.groovy:

grails.plugin.springsecurity.ldap.context.server = 'ldap://your-ldap-host:389'

If you’re using LDAPS, switch it to ldaps://your-ldap-host:636 and make sure the port is open and your server is reachable from your Grails app.

2. Verify User Search Rules

LDAP needs to know how to locate user entries based on the login username. You’re likely missing these key search configurations:

// The base DN where your user accounts are stored
grails.plugin.springsecurity.ldap.search.base = 'ou=users,dc=sw01,dc=com'
// The LDAP attribute that matches the login username (adjust if you use cn/mail instead of uid)
grails.plugin.springsecurity.ldap.search.filter = 'uid={0}'

The {0} gets replaced with the username entered at login. Double-check that the attribute in the filter matches what’s actually stored in your LDAP user entries.

3. Test the Manager DN Credentials

First, confirm your admin LDAP credentials work outside of Grails. Use the ldapsearch command to test the manager bind:

ldapsearch -x -D "uid=admin,dc=sw01,dc=com" -w "Admin123" -H ldap://your-ldap-host:389 -b "dc=sw01,dc=com" "(objectClass=*)"

If this command fails, your manager DN is incorrect, the password is wrong, or the LDAP server is refusing connections. Fix this first before moving on.

4. Validate the Test User’s Existence and Password

Make sure the username you’re trying to log in with actually exists in LDAP, and its password is correct. Use the manager credentials to search for the user:

ldapsearch -x -D "uid=admin,dc=sw01,dc=com" -w "Admin123" -H ldap://your-ldap-host:389 -b "ou=users,dc=sw01,dc=com" "(uid=your-test-username)"

If the user is found, try binding directly with their credentials to confirm the password works:

ldapsearch -x -D "uid=your-test-username,ou=users,dc=sw01,dc=com" -w "user-password" -H ldap://your-ldap-host:389 -b "dc=sw01,dc=com" "(objectClass=*)"

A failure here means the user’s password is incorrect or their account is locked/restricted.

5. Enable Debug Logging for Spring Security

Add debug logging to Config.groovy to see exactly what’s happening during the LDAP authentication flow:

log4j = {
    debug 'org.springframework.security', 'org.springframework.ldap'
}

The logs will show details like whether the LDAP bind succeeded, if the user search returned any results, and where the process fails—this is often the fastest way to pinpoint the issue.

6. Check LDAP Server Permissions

Ensure your manager account has permission to search user entries, and that regular user accounts are allowed to bind to the server (some LDAP configurations restrict this). Also, confirm the userPassword attribute exists on user entries and uses a format your Grails setup supports (like SSHA or plaintext, though plaintext is not recommended for production).


内容的提问来源于stack exchange,提问作者alchn

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 08:28:33