【问题标题】:Binding to a different active directory ldap instance in Powershell在 Powershell 中绑定到不同的活动目录 ldap 实例
【发布时间】:2014-10-20 11:25:26
【问题描述】:

我正在尝试使用要绑定的一组特定凭据连接到一些独立的 LDAP 存储(ADAM - Active Directory 应用程序模式),但无法找到最好的方法。这是一个我希望能起作用的例子:

$ldapHost = New-Object System.DirectoryServices.DirectoryEntry("LDAP://{serverip}:{port}/dc=acme,dc=com","cn=myuser,dc=acme,dc=com","myPassw0rd")
$ldapQuery = New-Object System.DirectoryServices.DirectorySearcher
$ldapQuery.SearchRoot = $ldapHost
$ldapQuery.Filter = "(objectclass=*)"
$ldapQuery.SearchScope = "Base"
$ldapQuery.FindAll()

这会让我着迷:

Exception calling "FindAll" with "0" argument(s): "A local error has occurred.
"
At line:1 char:19
+ $ldapQuery.FindAll <<<< ()
+ CategoryInfo          : NotSpecified: (:) [], MethodInvocationException
+ FullyQualifiedErrorId : DotNetMethodException    

我也试过了:

$ldapHost = New-Object System.DirectoryServices.DirectoryEntry("LDAP://{myip}:{port}/dc=acme,dc=com")
$ldapHost.Username = "cn=myuser,dc=acme,dc=com"

结果:

The following exception occurred while retrieving member "Username": "The specified directory            service attribute or valu
e does not exist.
"
At line:1 char:11
+ $ldapHost. <<<< Username = "cn=myuser,DC=acme,dc=com"
+ CategoryInfo          : InvalidOperation: (:) [], RuntimeException
+ FullyQualifiedErrorId : PropertyAssignmentException

我已经尝试了过滤器等的一些变体。我可以找到的大多数文档只是假设我从同一目录中连接到 ldap/正在连接正确的用户进行查询。

如果你熟悉 Python 的 ldap 模块,我就是这样做的:

import ldap
ld = ldap.initialize("ldap://{myip}:{port}")
ld.bind_s("cn=myuser,dc=acme,dc=com","Passw0rd")
ld.search_s("dc=acme,dc=com",ldap.SCOPE_BASE,"objectclass=*")

关于如何解决这个问题的任何指示?我绝对可以通过各种 LDAP 客户端进行连接。我可能需要明确指定身份验证,但我不确定,因为关于从域外查询的信息非常少。

【问题讨论】:

    标签: powershell active-directory ldap


    【解决方案1】:

    你可以试试这个……我用它来连接一个 OpenLDAP 实例,它运行良好。也适用于 AD,因此它应该满足您的需求。您需要更新 $basedn 变量和主机/用户名变量。

    $hostname = ''
    $username = ''
    
    $Null = [System.Reflection.Assembly]::LoadWithPartialName("System.DirectoryServices.Protocols")
    #Connects to LDAP
    $LDAPConnect = New-Object System.DirectoryServices.Protocols.LdapConnection "$HostName"
    
    #Set session options (SSL + LDAP V3)
    $LDAPConnect.SessionOptions.SecureSocketLayer = $true
    $LDAPConnect.SessionOptions.ProtocolVersion = 3
    
    # Pick Authentication type:
    # Anonymous, Basic, Digest, DPA (Distributed Password Authentication),
    # External, Kerberos, Msn, Negotiate, Ntlm, Sicily
    $LDAPConnect.AuthType = [System.DirectoryServices.Protocols.AuthType]::Basic
    
    # Gets username and password.
    $credentials = new-object "System.Net.NetworkCredential" -ArgumentList $UserName,(Read-Host "Password" -AsSecureString)
    # Bind with the network credentials. Depending on the type of server,
    # the username will take different forms.
    Try {
    $ErrorActionPreference = 'Stop'
    $LDAPConnect.Bind($credentials)
    $ErrorActionPreference = 'Continue'
    }
    Catch {
    Throw "Error binding to ldap  - $($_.Exception.Message)"
    }
    
    
    Write-Verbose "Successfully bound to LDAP!" -Verbose
    $basedn = "OU=Users and Groups,DC=TEST,DC=NET"
    $scope = [System.DirectoryServices.Protocols.SearchScope]::Subtree
    #Null returns all available attributes
    $attrlist = $null
    $filter = "(objectClass=*)"
    
    $ModelQuery = New-Object System.DirectoryServices.Protocols.SearchRequest -ArgumentList $basedn,$filter,$scope,$attrlist
    
    #$ModelRequest is a System.DirectoryServices.Protocols.SearchResponse
    Try {
    $ErrorActionPreference = 'Stop'
    $ModelRequest = $LDAPConnect.SendRequest($ModelQuery) 
    $ErrorActionPreference = 'Continue'
    }
    Catch {
    Throw "Problem looking up model account - $($_.Exception.Message)"
    }
    
    $ModelRequest
    

    大部分的功劳都在这里..

    http://mikemstech.blogspot.com/2013/03/searching-non-microsoft-ldap.html

    【讨论】:

    • 抱歉,我还没有机会对此进行测试。事情变得忙碌起来。一定会回复你的。
    • 感谢和抱歉耽搁了。我还没有设法让它工作,但在这一点上,我认为它是一个 LDAP 守护程序配置问题,而不是一个协议问题。您的绑定效果很好。
    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2019-04-02
    • 2011-12-15
    相关资源
    最近更新 更多