WSO2 Identity Server 5.x迁移AD用户商店:用户名自动追加域名配置咨询
Great question—this is a common scenario when migrating from LDAP to AD, and WSO2 Identity Server has built-in tools to handle exactly this without disrupting your users' login habits. Here are the two most reliable approaches tailored to your needs:
Since your AD environment uses UPNs (username@domain) and you want users to keep entering just the username portion, the cleanest solution is to configure WSO2 IS to automatically append your domain suffix to the input username before querying AD's userPrincipalName attribute. Here's how to set it up:
Open the
<IS_HOME>/repository/conf/user-mgt.xmlfile and locate your Active Directory user store configuration block (starts with<UserStoreManager class="org.wso2.carbon.user.core.ldap.ActiveDirectoryUserStoreManager">).Update the block with these key properties (adjust values to match your AD domain):
<!-- Set userPrincipalName as the username attribute to leverage UPNs --> <Property name="UserNameAttribute">userPrincipalName</Property> <!-- Enable the default username handler to rewrite login inputs --> <Property name="UsernameHandler">org.wso2.carbon.user.core.ldap.handler.DefaultUsernameHandler</Property> <!-- Capture usernames that don't include an @ symbol --> <Property name="UsernamePattern">^([^@]+)$</Property> <!-- Append your domain to the captured username --> <Property name="UsernameRewritePattern">$1@your-domain.com</Property>How this works:
- When a user enters
johndoe, the regex pattern captures the input (since it has no@), and the rewrite rule converts it tojohndoe@your-domain.com. - WSO2 IS then searches AD for a user where
userPrincipalNamematches this transformed value. - If a user does enter their full UPN (e.g.,
johndoe@your-domain.com), the pattern won't trigger, so the input is used as-is—no duplicate domain suffixes.
- When a user enters
Save the file and restart WSO2 Identity Server for changes to take effect.
If you still need to use sAMAccountName (for users who fit within the 20-character limit), you can configure the AD user store to automatically use your domain context when searching for users:
- In the same user store configuration block, set these properties:
<Property name="UserNameAttribute">sAMAccountName</Property> <Property name="DomainName">your-domain.com</Property> <Property name="UserSearchFilter">(&(objectClass=user)(sAMAccountName=?))</Property> - This tells WSO2 IS to search for the input username within your AD domain's context, but note this won't help with users who exceed the 20-character
sAMAccountNamelimit—so the UPN-based approach is still recommended for those cases.
After setting up either approach, test with a mix of users (those with short sAMAccountNames and those using longer UPNs) to ensure the login flow works as expected.
内容的提问来源于stack exchange,提问作者Jason Whitener

