4

我在 Tomcat server.xml 文件的 Tomcat 安全领域中引用 LDAP。但是我遇到了一个不寻常的错误:Tomcat 没有启动,进入日志我看到它无法连接到 localhost:389 - Tomcat 的默认 LDAP URL。

但是,Tomcat 被配置为指向不同的 URL(不是同一台机器的外部 URL;完全不同),如下所示:

<Realm className="org.apache.catalina.realm.JNDIRealm" debug="99" 
        connectionURL="ldap://XXX.XX.XX.XXX:389" 
        userSubtree="true"  
        userPattern="(cn={0},ou=XXXXXXXX,ou=XXXXX,o=XXX)"  
        roleBase="ou=XXXXXXXX,o=XXX"  
        roleName="cn"  
        roleSearch="member={0}"  
        connectionName="cn=XXXXXXXX,ou=XXXXXXXX,o=XXX"  
        connectionPassword="XXXXXXXX"/>

基本上我不知道为什么它还在看 localhost:389。如果有人以前遇到过这种情况,我将不胜感激!我已经用谷歌搜索了一段时间,但是当人们将错误粘贴到页面中时,似乎没有很多答案。如果有人有任何建议,我将不胜感激。

这是日志文件:

24-Feb-2009 11:38:45 org.apache.coyote.http11.Http11Protocol init
INFO: Initializing Coyote HTTP/1.1 on http-8443
Starting service Tomcat-Standalone
Apache Tomcat/4.1.31
Catalina.start: LifecycleException:  Exception opening directory server connection:      
javax.naming.CommunicationException: localhost:389 
    [Root exception is java.net.ConnectException: Connection refused: connect]
LifecycleException:  Exception opening directory server connection:   
javax.naming.CommunicationException: localhost:389 
    [Root exception is java.net.ConnectException: Connection refused: connect]
at org.apache.catalina.realm.JNDIRealm.start(JNDIRealm.java:1558)
at org.apache.catalina.core.ContainerBase.start(ContainerBase.java:1126)
at org.apache.catalina.core.StandardEngine.start(StandardEngine.java:316)
at org.apache.catalina.core.StandardService.start(StandardService.java:450)
at org.apache.catalina.core.StandardServer.start(StandardServer.java:2143)
at org.apache.catalina.startup.Catalina.start(Catalina.java:463)
at org.apache.catalina.startup.Catalina.execute(Catalina.java:350)
at org.apache.catalina.startup.Catalina.process(Catalina.java:129)
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
at java.lang.reflect.Method.invoke(Method.java:324)
at org.apache.catalina.startup.Bootstrap.main(Bootstrap.java:156)
----- Root Cause -----
javax.naming.CommunicationException: localhost:389 
    [Root exception is java.net.ConnectException: Connection refused: connect]
at com.sun.jndi.ldap.Connection.<init>(Connection.java:204)
at com.sun.jndi.ldap.LdapClient.<init>(LdapClient.java:119)
at com.sun.jndi.ldap.LdapClient.getInstance(LdapClient.java:1668)
at com.sun.jndi.ldap.LdapCtx.connect(LdapCtx.java:2599)
at com.sun.jndi.ldap.LdapCtx.<init>(LdapCtx.java:290)
at com.sun.jndi.ldap.LdapCtxFactory.getInitialContext(LdapCtxFactory.java:53)
at javax.naming.spi.NamingManager.getInitialContext(NamingManager.java:662)
at javax.naming.InitialContext.getDefaultInitCtx(InitialContext.java:243)
at javax.naming.InitialContext.init(InitialContext.java:219)
at javax.naming.InitialContext.<init>(InitialContext.java:195)
at javax.naming.directory.InitialDirContext.<init>(InitialDirContext.java:80)
at org.apache.catalina.realm.JNDIRealm.open(JNDIRealm.java:1482)
at org.apache.catalina.realm.JNDIRealm.start(JNDIRealm.java:1556)
at org.apache.catalina.core.ContainerBase.start(ContainerBase.java:1126)
at org.apache.catalina.core.StandardEngine.start(StandardEngine.java:316)
at org.apache.catalina.core.StandardService.start(StandardService.java:450)
at org.apache.catalina.core.StandardServer.start(StandardServer.java:2143)
at org.apache.catalina.startup.Catalina.start(Catalina.java:463)
at org.apache.catalina.startup.Catalina.execute(Catalina.java:350)
at org.apache.catalina.startup.Catalina.process(Catalina.java:129)
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
at java.lang.reflect.Method.invoke(Method.java:324)
at org.apache.catalina.startup.Bootstrap.main(Bootstrap.java:156)
Caused by: java.net.ConnectException: Connection refused: connect
at java.net.PlainSocketImpl.socketConnect(Native Method)
at java.net.PlainSocketImpl.doConnect(PlainSocketImpl.java:305)
at java.net.PlainSocketImpl.connectToAddress(PlainSocketImpl.java:171)
at java.net.PlainSocketImpl.connect(PlainSocketImpl.java:158)
at java.net.Socket.connect(Socket.java:452)
at java.net.Socket.connect(Socket.java:402)
at java.net.Socket.<init>(Socket.java:309)
at java.net.Socket.<init>(Socket.java:124)
at com.sun.jndi.ldap.Connection.createSocket(Connection.java:346)
at com.sun.jndi.ldap.Connection.<init>(Connection.java:181)
... 24 more
Stopping service Tomcat-Standalone
Catalina.stop: LifecycleException:  Coyote connector has not been started
LifecycleException:  Coyote connector has not been started
at org.apache.coyote.tomcat4.CoyoteConnector.stop(CoyoteConnector.java:1296)
at org.apache.catalina.core.StandardService.stop(StandardService.java:499)
at org.apache.catalina.core.StandardServer.stop(StandardServer.java:2178)
at org.apache.catalina.startup.Catalina.start(Catalina.java:494)
at org.apache.catalina.startup.Catalina.execute(Catalina.java:350)
at org.apache.catalina.startup.Catalina.process(Catalina.java:129)
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
at java.lang.reflect.Method.invoke(Method.java:324)
at org.apache.catalina.startup.Bootstrap.main(Bootstrap.java:156)
4

3 回答 3

2

尝试添加与 connectionURL 具有相同值的“alternateURL”属性。出于某种原因,当我遇到类似问题时,这对我有用。

于 2009-09-14T14:40:53.013 回答
2

我知道这是一篇很老的帖子,但我最近遇到了这个问题,问题在于我将 JNDIRealm 嵌套在 LockoutRealm 中。

通过将 JNDIRealm 作为我的顶级领域,我不再遇到所描述的问题。但是,如果您确实需要锁定领域,则此解决方案没有帮助。

于 2011-12-12T22:04:21.063 回答
1
  • 许多 tomcats 配置元素支持debug属性。尝试将debug="99"添加到领域配置中。(参见 tomcats realm-howto中的示例,搜索debug="99"
  • 额外确保它不是拼写错误,例如在 connectionURL 的大写
  • 查看 conf/server.xml 中是否还有其他提及“localhost”(或“127.0”)
  • 查看 conf/*/*/*.xml 中是否提到“localhost”(或“127.0”)(尽管这不应该导致 tomcat 无法启动:它只会影响该应用程序)
  • 从一个最小的 server.xml 开始——如果你使用 tomcat 5.xa 文件“server-minimal.xml”,它比默认的 server.xml 可读性更好
  • 确保您不受 server.xml 中各种 xml 注释的影响——我已经被它们咬过很多次了。
于 2009-03-07T12:25:21.263 回答