【问题标题】:Setting up Shibboleth IdP with LDAP使用 LDAP 设置 Shibboleth IdP
【发布时间】:2014-07-24 07:22:18
【问题描述】:

我正在尝试将 LDAP 与 Shibboleth 一起使用。我快到了,但我无法进行身份验证。我关注了these instructions,我的 login.config 文件包含以下内容:

ShibUserPassAuth {
  edu.vt.middleware.ldap.jaas.LdapLoginModule required
  host="ldap://localhost:10389" base="ou=users,ou=system"
  ssl="false" userField="uid";
};

我已经尝试了上述的几种变体。

我可以使用 TestShib 访问我的 IdP 的登录页面,但在我尝试进行身份验证时总是收到“登录失败。请仔细检查您的用户名和密码”。

如果我能设法获得任何身份验证日志消息,这可能更容易调试自己,但我似乎也无法让这些消息正常工作。

请注意,以下ldapsearch 命令可以正常工作:

ldapsearch -h "ldap.example.com:10389" -w testpass -x -D "uid=testuser,ou=users,ou=system" -b "dc=example,dc=com" '(objectclass=*)'

如果您能告诉我我的问题可能是什么,或者至少如何启用日志记录,那将非常有帮助。

【问题讨论】:

    标签: ldap shibboleth


    【解决方案1】:

    我有这个在本地工作。我已经采用了我的工作配置,并将我的 LDAP 主机和基本路径替换为您在上述问题中的配置。

    ShibUserPassAuth {
      edu.vt.middleware.ldap.jaas.LdapLoginModule required
        ldapUrl="ldap://localhost:10389"
        baseDn="ou=users,ou=system"
        userFilter="uid={0}";
    };
    

    【讨论】:

      猜你喜欢
      • 2016-02-26
      • 2018-11-12
      • 2016-08-18
      • 2019-11-17
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2019-08-15
      • 1970-01-01
      相关资源
      最近更新 更多