【发布时间】:2016-05-31 19:23:36
【问题描述】:
我正在寻找一种使用 PowerShell 修改非 Active Directory LDAP 对象的方法。我在网上找到了许多脚本来访问 LDAP 对象信息,但没有一个显示如何修改它们。下面是通过组合我在网上找到的各种脚本获得的最接近的结果。我无法通过“$c.Bind()”行,因为我总是收到“LDAP 服务器不可用”错误。我知道服务器名称是正确的,并且它已启动并正在运行。
有人有什么想法吗?
[System.Reflection.Assembly]::LoadWithPartialName("System.DirectoryServices.Protocols")
[System.Reflection.Assembly]::LoadWithPartialName("System.Net")
$credentials = new-object System.Net.NetworkCredential("cn=adminID,o=edu","password")
$NetWareServer=New-Object System.DirectoryServices.Protocols.LdapDirectoryIdentifier("LDAP://ldapserver.system.edu:636")
$c = New-Object System.DirectoryServices.Protocols.LdapConnection($NetWareServer, $credentials)
$c.SessionOptions.SecureSocketLayer = $true;
$c.SessionOptions.ProtocolVersion = 3
$c.AuthType = [System.DirectoryServices.Protocols.AuthType]::Basic
$c.Bind()
$r = (new-object "System.DirectoryServices.Protocols.ModifyRequest")
$r.DistinguishedName = "uid=testID,ou=test,o=edu";
$a = New-Object "System.DirectoryServices.Protocols.DirectoryAttributeModification"
$a.Name = "description"
$a.Operation = [System.DirectoryServices.Protocols.DirectoryAttributeOperation]::Add
$a.Add("testdescription")
$r.Modifications.Add($a)
$re = $c.SendRequest($r);
if ($re.ResultCode -ne System.directoryServices.Protocols.ResultCode]::Success)
{
write-host "Failed!"
write-host ("ResultCode: " + $re.ResultCode)
write-host ("Message: " + $re.ErrorMessage)
}
【问题讨论】:
-
会不会是
ldapserver.system.edu:636出示的证书不可信? -
可以的。但我对证书知之甚少,也不知道如何测试。
-
我遇到了这个问题,通过获取 AD 根证书并将其添加到我信任的根权限中解决了这个问题。
标签: powershell ldap