在 CentOS 上把 Jellyfin 集成 LDAP,通常有两种方式:
下面重点讲 最常用、最稳定的“Jellyfin LDAP 插件”方案。
ldap://192.168.1.10:389)dc=example,dc=com)http://<jellyfin_ip>:8096
路径:
控制台 → 插件 → 目录 → LDAP Authentication
点击 安装,安装完成后 重启 Jellyfin
systemctl restart jellyfin
路径:
控制台 → 插件 → LDAP Authentication → 配置
| 配置项 | 示例值 |
|---|---|
| LDAP Server | ldap://192.168.1.10:389 |
| Base DN | dc=example,dc=com |
| Bind DN | cn=admin,dc=example,dc=com |
| Bind Password | your_password |
| Search Filter | (uid={0}) |
| User Search Base | ou=users,dc=example,dc=com |
| Enable LDAP | ✅ |
| 配置项 | 示例值 |
|---|---|
| LDAP Server | ldap://dc.example.com:389 |
| Base DN | dc=example,dc=com |
| Bind DN | jellyfin@example.com |
| Search Filter | (sAMAccountName={0}) |
| User Search Base | cn=Users,dc=example,dc=com |
在 LDAP 插件 → User Mapping 中:
uid(OpenLDAP)或 sAMAccountName(AD)cnmail勾选:
⚠️ LDAP 只负责登录,不负责权限
Jellyfin 中:
路径:
控制台 → 用户 → 选择用户 → 权限
firewall-cmd --add-port=389/tcp --permanent
firewall-cmd --reload
setsebool -P nis_enabled 1
ldapsearch 测试:ldapsearch -x -H ldap://192.168.1.10 \
-D "cn=admin,dc=example,dc=com" \
-W -b "dc=example,dc=com"
ldaps://ip:636cp ldap-ca.crt /etc/pki/ca-trust/source/anchors/
update-ca-trust
如果你需要:
可以考虑:
如果你愿意,可以告诉我:
我可以直接给你 一份可复制的配置文件。