【问题标题】:How to do LDAP query using Powershell and PKI如何使用 Powershell 和 PKI 进行 LDAP 查询
【发布时间】:2014-06-11 11:56:13
【问题描述】:

我是 Powershell 新手,我正在尝试使用 PKI 身份验证进行安全 LDAP 查询。我被困在如何设置证书和密钥上。基于谷歌搜索/研究,我有一些基础知识,例如:

$connection = new-object System.DirectoryServices.Protocols.LDAPConnection('$domainName:$portNum')
[string[] $get] = "$attribute1", "$attribute2", "attribute3"
$request = new-object System.DirectoryServices.Protocol.SearchRequest("$targetOu", "$filter", "subtree", $get)
$response = new-object $connection.SendRequest($request)

就像我说的,我一直在纠结如何设置/发送证书和密钥。我以为我可以做到$connection.ClientCertificates = $path,但该属性是只读的。我还认为我必须对$System.Net.NetworkCredential 做点什么,但我不确定证书和密钥是否真的对应于用户名和密码。我提到了一个执行 LDAP 查询并使用 PKI 的 Perl 脚本,你可以这样做:

clientcert => '/path/to/cert.pem'
clientkey => '/path/to/key.pem'

Powershell 的等价物是什么?我必须对System.Security.Cryptography.X509Certificates.X509Certificate 做点什么吗?

任何帮助将不胜感激!

【问题讨论】:

    标签: powershell ssl ldap pki ldap-query


    【解决方案1】:
    $connection.ClientCertificates.Add($cert)
    

    $cert 必须是 X509Certificate 类 并使用

    从商店获取证书
    $allPersonalCerts = @( Get-ChildItem -Path 'Cert:\CurrentUser\my' )
    

    它返回 X509Certificate 对象的数组(或 X509Certificate2 这是 X509Certificate 的子类)

    注意:在进行 PowerShell 编程时,您始终可以通过谷歌搜索 C# 或 VB.net 解决方案来寻求帮助。这是 .Net,面向 .net 语言的示例只是语法不同

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 1970-01-01
      • 2011-03-05
      • 1970-01-01
      • 1970-01-01
      • 2014-11-18
      • 1970-01-01
      • 2017-02-03
      • 1970-01-01
      相关资源
      最近更新 更多