mirror of
https://github.com/BookStackApp/BookStack.git
synced 2026-02-13 19:06:31 +03:00
LDAP over SSO - ldap_bind(): Unable to bind to server: Can't contact LDAP server #3800
Closed
opened 2026-02-05 07:30:31 +03:00 by OVERLORD
·
6 comments
No Branch/Tag Specified
development
l10n_development
release
v25-12
llm_only
vectors
v25-11
docker_env
drawio_rendering
user_permissions
ldap_host_failover
svg_image
prosemirror
captcha_example
fix/video-export
v25.12.3
v25.12.2
v25.12.1
v25.12
v25.11.6
v25.11.5
v25.11.4
v24.11.4
v25.11.3
v25.11.2
v25.11.1
v25.11
v25.07.3
v25.07.2
v25.07.1
v25.07
v25.05.2
v25.05.1
v25.05
v25.02.5
v25.02.4
v25.02.3
v25.02.2
v25.02.1
v25.02
v24.12.1
v24.12
v24.10.3
v24.10.2
v24.10.1
v24.10
v24.05.4
v24.05.3
v24.05.2
v24.05.1
v24.05
v24.02.3
v24.02.2
v24.02.1
v24.02
v23.12.3
v23.12.2
v23.12.1
v23.12
v23.10.4
v23.10.3
v23.10.2
v23.10.1
v23.10
v23.08.3
v23.08.2
v23.08.1
v23.08
v23.06.2
v23.06.1
v23.06
v23.05.2
v23.05.1
v23.05
v23.02.3
v23.02.2
v23.02.1
v23.02
v23.01.1
v23.01
v22.11.1
v22.11
v22.10.2
v22.10.1
v22.10
v22.09.1
v22.09
v22.07.3
v22.07.2
v22.07.1
v22.07
v22.06.2
v22.06.1
v22.06
v22.04.2
v22.04.1
v22.04
v22.03.1
v22.03
v22.02.3
v22.02.2
v22.02.1
v22.02
v21.12.5
v21.12.4
v21.12.3
v21.12.2
v21.12.1
v21.12
v21.11.3
v21.11.2
v21.11.1
v21.11
v21.10.3
v21.10.2
v21.10.1
v21.10
v21.08.6
v21.08.5
v21.08.4
v21.08.3
v21.08.2
v21.08.1
v21.08
v21.05.4
v21.05.3
v21.05.2
v21.05.1
v21.05
v21.04.6
v21.04.5
v21.04.4
v21.04.3
v21.04.2
v21.04.1
v21.04
v0.31.8
v0.31.7
v0.31.6
v0.31.5
v0.31.4
v0.31.3
v0.31.2
v0.31.1
v0.31.0
v0.30.7
v0.30.6
v0.30.5
v0.30.4
v0.30.3
v0.30.2
v0.30.1
v0.30.0
v0.29.3
v0.29.2
v0.29.1
v0.29.0
v0.28.3
v0.28.2
v0.28.1
v0.28.0
v0.27.5
v0.27.4
v0.27.3
v0.27.2
v0.27.1
v0.27
v0.26.4
v0.26.3
v0.26.2
v0.26.1
v0.26.0
v0.25.5
v0.25.4
v0.25.3
v0.25.2
v0.25.1
v0.25.0
v0.24.3
v0.24.2
v0.24.1
v0.24.0
v0.23.2
v0.23.1
v0.23.0
v0.22.0
v0.21.0
v0.20.3
v0.20.2
v0.20.1
v0.20.0
v0.19.0
v0.18.5
v0.18.4
v0.18.3
v0.18.2
v0.18.1
v0.18.0
v0.17.4
v0.17.3
v0.17.2
v0.17.1
v0.17.0
v0.16.3
v0.16.2
v0.16.1
v0.16.0
v0.15.3
v0.15.2
v0.15.1
v0.15.0
v0.14.3
v0.14.2
v0.14.1
v0.14.0
v0.13.1
v0.13.0
v0.12.2
v0.12.1
v0.12.0
v0.11.2
v0.11.1
v0.11.0
v0.10.0
v0.9.3
v0.9.2
v0.9.1
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.6
v0.7.5
v0.7.4
v0.7.3
0.7.2
v.0.7.1
v0.7.0
v0.6.3
v0.6.2
v0.6.1
v0.6.0
v0.5.0
Labels
Clear labels
🎨 Design
📖 Docs Update
🐛 Bug
🐛 Bug
:cat2:🐈 Possible duplicate
💿 Database
☕ Open to discussion
💻 Front-End
🐕 Support
🚪 Authentication
🌍 Translations
🔌 API Task
🏭 Back-End
⛲ Upstream
🔨 Feature Request
🛠️ Enhancement
🛠️ Enhancement
🛠️ Enhancement
❤️ Happy feedback
🔒 Security
🔍 Pending Validation
💆 UX
📝 WYSIWYG Editor
🌔 Out of scope
🔩 API Request
:octocat: Admin/Meta
🖌️ View Customization
❓ Question
🚀 Priority
🛡️ Blocked
🚚 Export System
♿ A11y
🔧 Maintenance
> Markdown Editor
pull-request
Mirrored from GitHub Pull Request
No Label
🐕 Support
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/BookStack#3800
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @TomBachelot on GitHub (May 12, 2023).
Attempted Debugging
Searched GitHub Issues
Describe the Scenario
Hi Dan,
I am currently trying to connect my Bookstack server (on Xampp) to my active directory but it is not working and I can't figure out why. I work in a large company, so I need to set up LDAP based authentication. I want an authenticated user to have direct access to boockstack without needing to authenticate through the sso link.
I followed your video on ldpa but when I use it, it doesn't work, the problem would come from the Active Directory consultation. Here is the error I get:

Here is the AD part of my configuration file:

Exact BookStack Version
v23.05.1
Log Content
Details
PHP Version
8.2.4
Hosting Environment
Windows 10 , xampp server, Theme Configured: custom
@ssddanbrown commented on GitHub (May 13, 2023):
Hi @TomBachelot, typically either BookStack is failing to reach the LDAP system, or the TLS is failing when attempted to be upgraded by the host system.
Does the result change when you change
LDAP_START_TLStotrue?Otherwise, are you confident the LDAP system in contactable on the configured address?
@TomBachelot commented on GitHub (May 15, 2023):
@ssddanbrown, Yes the result does change when I change LDAP_START_TLS to true but I still get an error unfortunately:

Otherwise, yes I'm sure that the LDAP system can be reached on the configured address.
I can provide you the Stack Trace if you want ?
@ssddanbrown commented on GitHub (May 15, 2023):
I don't think the BookStack stack trace will provide any extra context in this case.
Have you done anything to check the connection from this specific host system?
Since you're on a Windows server, you may be able to do something like this via PowerShell:
@TomBachelot commented on GitHub (May 16, 2023):
@ssddanbrown, thanks for helping me because im very in need !
I tried the PowerShell command you gave me and it seems to be ok :

but I made a typing error in the server address. Now it's working a bit more, here is what I got:

I tried the ldap auth method without using the LDPA_START_TLS and i've got no errors but without knowing why it says "this informations does not match any account"

And when I try with the LDAP_START_TLS=true , i have an issue :

@ssddanbrown commented on GitHub (May 18, 2023):
Okay, leave
LDAP_START_TLSasfalseunless you specifically needtlssince it looks like your server does not actively support it using the current connection details.This usually indicates that the password is incorrect or, more likely, no matching user is coming back in the LDAP search BookStack is performing.
Are you sure your
LDAP_USER_FILTERvalue is correct? For AD systems I usually expect to see something along the lines ofLDAP_USER_FILTER=(&(sAMAccountName=${user}))instead.The only other immediately suspicious element of your config is the
LDAP_BASE_DN, it looks quite specific. Remember that all searches will be performed with this DN as a base. YourLDAP_DNis also outside of this base which could maybe cause issues (but I'm not so sure about this, might depend on the LDAP system). Start with theLDAP_USER_FILTERbefore attempting to alter anything here.@ssddanbrown commented on GitHub (May 30, 2023):
Since there's been no further follow up I'll close this off.