Django LDAP身份验证:simple_bind_s有效,但是身份验证失败:用户身份验证失败:LDAP服务器拒绝了用户DN /密码

时间:2020-11-02 06:33:48

标签: django authentication active-directory ldap

我在使用ldap的Django中实现身份验证非常困难。

“我的配置”在settings.py中如下:

  void OnTick()
  {  
       string print = "\n\n\n\n\n\n" +
                      "\n op1= "   + iOpen(NULL,PERIOD_CURRENT,0) +
                      "\n op2= "   + iOpen(NULL,PERIOD_M5,0) +
                      "\n EMA1 : " +   iMA(NULL,PERIOD_CURRENT,21,0,MODE_EMA,PRICE_CLOSE,0) +
                      "\n EMA2 : " +   iMA(NULL,PERIOD_M5,21,0,MODE_EMA,PRICE_CLOSE,0);
    
       Comment(print);        
  }

然后在此处进行简单测试:

AUTH_LDAP_SERVER_URI = "ldap://192.168.10.5"

# AUTH_LDAP_BIND_DN = "cn=admin,dc=my,dc=domain,dc=com"
# AUTH_LDAP_BIND_PASSWORD = "adminPass"
# AUTH_LDAP_USER_SEARCH = LDAPSearch(
#     "dc=dc=my,dc=domain,dc=com", ldap.SCOPE_SUBTREE, "(cn=%(user)s)"
# )


AUTH_LDAP_USER_DN_TEMPLATE = 'sAMAccountName=%(user)s,dc=my,dc=domain,dc=com'
AUTH_LDAP_USER_QUERY_FIELD = 'username'

AUTH_LDAP_GROUP_SEARCH = LDAPSearch(
    "dc=dc=my,dc=domain,dc=com",
    ldap.SCOPE_SUBTREE,
    "(objectClass=group)",
)
AUTH_LDAP_GROUP_TYPE = GroupOfNamesType(name_attr="cn")

AUTH_LDAP_REQUIRE_GROUP = "dc=my,dc=domain,dc=com"

AUTH_LDAP_USER_ATTR_MAP = {
    "username": "sAMAccountName",
    "first_name": "givenName",
    "last_name": "sn",
    "email": "mail",
}

AUTH_LDAP_USER_FLAGS_BY_GROUP = {
    "is_active": "dc=my,dc=domain,dc=com",
    "is_staff": "dc=my,dc=domain,dc=com",
    "is_superuser": "dc=my,dc=domain,dc=com",
}


AUTH_LDAP_FIND_GROUP_PERMS = True

AUTH_LDAP_CACHE_TIMEOUT = 3600

AUTHENTICATION_BACKENDS = (
    "django_auth_ldap.backend.LDAPBackend",
    "django.contrib.auth.backends.ModelBackend",
)

我从上述测试中注意到了以下内容

  1. 测试1永远不会成功。我尝试从sAMAccountName更改为cn更改为principalName,这似乎与AD Explorer的不同。结果始终相同:

def test(request): #1 test authentication obj = LDAPBackend() me = obj.authenticate(request, 'admin', 'adminPass') #2 Test Connection and auth con = obj.ldap.initialize(uri='ldap://192.168.10.5') t = con.simple_bind_s('admin', 'adminPass') # return HttpResponse('Empty')

  1. 仅当我在用户名后缀“ @ my.domain.com”时,测试2似乎成功。没有这个后缀,它将失败并显示错误:
Authentication failed for admin: admin DN/password rejected by LDAP server.

我尝试为测试1添加相同的后缀,但无济于事。

任何帮助将不胜感激。

0 个答案:

没有答案