如何解决Jenkins LDAP-根DN和显示名称LDAP属性
此问题与Jenkins LDAP root DN
和Display Name LDAP attribute
环境:-
Jenkins Version - 2.235.5(LTS)
LDAP Plugin - 1.24
我正在尝试在我们的Jenkins中配置LDAP(AD)身份验证,以下是配置设置。
root DN - DC=Company,DC=domain,DC=com
User search base: OU=Users,OU=Division,OU=Team,DC=Company,DC=com
User search filter: sAMAccountName={0}
Group search base: OU=Users,DC=com
Group search filter: (&(objectclass=group)(cn={0}))
Group membership
Group membership filter - (&(objectCategory=group)(member:1.2.840.113556.1.4.1941:={0}))
Manager DN: CN=jenkins,OU=Users,DC=com
Manager Password: password
Display Name LDAP attribute: displayname
Email Address LDAP attribute: mail
但是在测试LDAP连接时,它在出现以下错误时失败。
Login
Authentication: failed for user "jenkins-user"
Lookup
User lookup: failed for user "jenkins-user"
LdapCallback;[LDAP: error code 32 - 0000208D: NameErr: DSID-03100241,problem 2001 (NO_OBJECT),data 0,best match of:
'DC=domain,DC=com'
]; nested exception is javax.naming.NameNotFoundException: [LDAP: error code 32 - 0000208D: NameErr: DSID-03100241,DC=com'
]; remaining name 'OU=Users,DC=com'
LDAP Group lookup: could not verify.
Please try with a user that is a member of at least one LDAP group.
Lockout
The user "jenkins-user" will be unable to login with the supplied password.
If this is your own account this would mean you would be locked out!
Are you sure you want to save this configuration?
假设我将root DN
保留为空,将enabled the tick mark
-Allow blank rootDN
保留为空。我的测试连接成功。
但是我想知道当前我正在root DN
的情况下运行为空,而enabled - Allow blank rootDN
在插件部分中。这样对生产环境好吗?
对于已登录的用户,如下所示的显示名称也太长了。
First-Name/Sur-Name/Team-Name/Location/Title/Company-Name
我只想显示First-Name + Sur-Name
。为此,我尝试将Display Name LDAP attribute:
更改为name,givenName,cn & sn
,但没有一个起作用。那么在詹金斯中只能显示名字+姓氏吗?
解决方法
我已修复它。每次当我们在LDAP配置部分中change/update
的{{1}}值时,我们就需要Display Name LDAP attribute
来自人员类别的用户并需要登录。发布它显示配置的设置。
版权声明:本文内容由互联网用户自发贡献,该文观点与技术仅代表作者本人。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如发现本站有涉嫌侵权/违法违规的内容, 请发送邮件至 dio@foxmail.com 举报,一经查实,本站将立刻删除。