sssd错误:无法启动TLS加密。 (未知错误代码)

时间:2019-11-15 09:39:33

标签: ldap single-sign-on nss sssd google-cloud-identity

我正在尝试使用Google安全LDAP配置Linux机器身份验证,并添加以下已完成的步骤

添加了具有以下权限的LDAP客户端:

  1. 访问权限:整个域
  2. 读取用户信息:整个域
  3. 读取组信息:开

在我的Ubuntu盒子(已在Azure中运行)中安装了SSSd

sudo apt install -y sssd sssd-tools

我的sssd.conf文件

[sssd]
debug_level = 7
services = nss, pam
domains = mydomain.com

[pam]
debug_level = 7

[nss]
debug_level = 7

[domain/mydomain.com]
debug_level = 7
cache_credentials = true
ldap_id_use_start_tls = true
ldap_tls_cacertdir = /home/ubuntu/ssl_Linux
ldap_tls_cacert = /home/ubuntu/ssl_Linux/gldap.crt
ldap_tls_cert = /home/ubuntu/ssl_Linux/gldap.crt
ldap_tls_key = /home/ubuntu/ssl_Linux/gldap.key
ldap_uri = ldaps://ldap.google.com:636
ldap_search_base = ou=Users,dc=mydomain,dc=com
ldap_group_name = uniqueMember
id_provider = ldap
auth_provider = ldap
ldap_schema = rfc2307bis
ldap_user_uuid = entryUUID
ldap_groups_use_matching_rule_in_chain = true
ldap_initgroups_use_matching_rule_in_chain = true
enumerate = false

在这里,我能够启动SSSD服务bt并得到以下错误

Nov 15 09:14:54 myserver systemd[1]: Started System Security Services Daemon.
Nov 15 09:14:55 myserver sssd[be[67530]: Could not start TLS encryption. (unknown error code)
Nov 15 09:16:11 myserver sssd[be[67530]: Could not start TLS encryption. (unknown error code)
Nov 15 09:16:11 myserver sssd[be[67530]: Backend is offline
Nov 15 09:17:19 myserver sssd[be[67530]: Could not start TLS encryption. (unknown error code)
Nov 15 09:19:48 myserver sssd[be[67530]: Could not start TLS encryption. (unknown error code)
Nov 15 09:24:02 myserver sssd[be[67530]: Could not start TLS encryption. (unknown error code)

仅供参考:我可以使用以下命令成功通过Google安全LDAP进行身份验证

LDAPTLS_CERT=mycrt.crt LDAPTLS_KEY=mykey.key ldapsearch -H ldaps://ldap.google.com:636 -b "ou=Users,dc=mydomain,dc=com" -D "my.user@mydomain.com" "(uid=my.user)" -W

简介https://helpcenter.itopia.com/en/articles/2394004-configuring-google-cloud-identity-ldap-on-ubuntu-16-04-for-user-logins

请帮助我

谢谢:)

1 个答案:

答案 0 :(得分:0)

我在新的虚拟机上尝试过相同的document,对我来说很好。

只需确保在http://admin.google.com/门户中配置google LDAP客户端后,最多可能需要24小时才能生效

谢谢