Postfix+LDAP临时查找失败:Docker-MailServer无法连接LDAP服务器
Let's break down the possible issues and fixes step by step, since you've already confirmed the LDAP entry exists and containers are on a custom bridge:
1. Verify Connectivity from docker-mailserver to OpenLDAP Container
First, make sure the mail server container can actually reach your OpenLDAP container. Just because the host machine can run ldapsearch successfully doesn't mean the mail container has the same access.
- Exec into the docker-mailserver container:
docker exec -it <your-mailserver-container-name> bash - Run an
ldapsearchcommand inside the container using the container name of your OpenLDAP instance (since you're using a custom bridge, Docker's internal DNS should resolve this):
If this fails, double-check:ldapsearch -x -H ldap://<openldap-container-name>:389 -b "dc=x,dc=y,dc=z,dc=com" "cn=abc"- Both containers are attached to the same custom bridge (run
docker network inspect <your-bridge-name>to confirm both are listed underContainers). - The OpenLDAP container is listening on the correct internal port (default 389 for LDAP, 636 for LDAPS). You can verify with
docker inspect <openldap-container-name> | grep "PortBindings"(though internal access doesn't rely on port mappings to the host).
- Both containers are attached to the same custom bridge (run
2. Validate docker-mailserver LDAP Configuration
Ensure your mail server's LDAP settings are pointing to the right target inside the bridge network:
- Check your
docker-mailserverLDAP config (usually indocker-compose.ymlor environment variables):- Confirm
LDAP_HOSTis set to your OpenLDAP container's name (e.g.,openldap) or its internal IP (you can get this withdocker inspect <openldap-container-name> | grep "IPAddress"). Avoid using the host's public/private IP here unless you've explicitly mapped the LDAP port to the host and allowed container access through the host firewall. - Verify
LDAP_SEARCH_BASEmatches your entry's base DN:ou=people,dc=x,dc=y,dc=z,dc=com - Check that
LDAP_BIND_DNandLDAP_BIND_PW(if using authenticated binding) are correct and have permissions to search the LDAP tree.
- Confirm
3. Check Host Firewall and AWS Security Group Rules
Even though containers are on the same host, you need to make sure:
- The host machine's firewall (ufw, iptables) isn't blocking traffic between the custom bridge network and the containers. Docker usually manages iptables rules for bridges, but if you've modified them manually, this could cause issues.
- For the external Ubuntu VM sending emails: Ensure the AWS security group for your mail server host allows inbound traffic on SMTP ports (25, 587, or 465 depending on your setup). The error mentions a lookup failure, but if the external VM can't reach the mail server at all, that could trigger related issues.
4. Check OpenLDAP Container Logs for Connection Issues
Look for clues in the OpenLDAP logs to see if connection attempts from the mail server are being rejected:
docker logs <openldap-container-name>
Look for entries like connection refused, invalid credentials, or access denied—these would indicate whether the issue is with authentication, network access, or LDAP permissions.
5. Verify DNS Resolution Inside docker-mailserver
If you're using a hostname for LDAP_HOST, confirm the mail container can resolve it:
docker exec -it <your-mailserver-container-name> nslookup <openldap-container-name>
If the lookup fails, you might need to explicitly set the LDAP host to the container's internal IP instead of the name, or check if your custom bridge has DNS enabled (it should be by default in Docker).
内容的提问来源于stack exchange,提问作者Vivek Suhanda

