【问题标题】:Modify non-AD LDAP object with Powershell使用 Powershell 修改非 AD LDAP 对象
【发布时间】:2016-05-31 19:23:36
【问题描述】:

我正在寻找一种使用 PowerShell 修改非 Active Directory LDAP 对象的方法。我在网上找到了许多脚本来访问 LDAP 对象信息,但没有一个显示如何修改它们。下面是通过组合我在网上找到的各种脚本获得的最接近的结果。我无法通过“$c.Bind()”行,因为我总是收到“LDAP 服务器不可用”错误。我知道服务器名称是正确的,并且它已启动并正在运行。

有人有什么想法吗?

[System.Reflection.Assembly]::LoadWithPartialName("System.DirectoryServices.Protocols")
[System.Reflection.Assembly]::LoadWithPartialName("System.Net")

$credentials = new-object System.Net.NetworkCredential("cn=adminID,o=edu","password")
$NetWareServer=New-Object System.DirectoryServices.Protocols.LdapDirectoryIdentifier("LDAP://ldapserver.system.edu:636")
$c = New-Object System.DirectoryServices.Protocols.LdapConnection($NetWareServer, $credentials)

$c.SessionOptions.SecureSocketLayer = $true;
$c.SessionOptions.ProtocolVersion = 3
$c.AuthType = [System.DirectoryServices.Protocols.AuthType]::Basic

$c.Bind() 

$r = (new-object "System.DirectoryServices.Protocols.ModifyRequest")
$r.DistinguishedName = "uid=testID,ou=test,o=edu";

$a = New-Object "System.DirectoryServices.Protocols.DirectoryAttributeModification"
$a.Name = "description"
$a.Operation = [System.DirectoryServices.Protocols.DirectoryAttributeOperation]::Add
$a.Add("testdescription")

$r.Modifications.Add($a)

$re = $c.SendRequest($r);

if ($re.ResultCode -ne System.directoryServices.Protocols.ResultCode]::Success)
{
    write-host "Failed!"
    write-host ("ResultCode: " + $re.ResultCode)
    write-host ("Message: " + $re.ErrorMessage)
} 

【问题讨论】:

  • 会不会是ldapserver.system.edu:636出示的证书不可信?
  • 可以的。但我对证书知之甚少,也不知道如何测试。
  • 我遇到了这个问题,通过获取 AD 根证书并将其添加到我信任的根权限中解决了这个问题。

标签: powershell ldap


【解决方案1】:

尝试使用 uid 而不是 cn 作为凭据。尝试不使用 SSL 进行连接。验证端口和用户信息是否正确,以及服务器和该端口是否可以从您所在的位置访问。

我就是这样做的:

$c = New-Object -TypeName System.DirectoryServices.Protocols.LdapConnection -ArgumentList "ldapserver.system.edu:636"
$c.SessionOptions.SecureSocketLayer = $true;
$c.SessionOptions.ProtocolVersion = 3
$c.AuthType = [System.DirectoryServices.Protocols.AuthType]::Basic
if ([string]::IsNullOrWhiteSpace($ConnectWithUser))
{
  $ConnectWithUser = Read-Host -Prompt "User:"
}
if ([string]::IsNullOrWhiteSpace($ConnectWithPassword))
{
  $ConnectWithPassword = Read-Host -Prompt "Password:" -AsSecureString
}
$ConnectWithUser = "uid="+$ConnectWithUser+",OU=admins,O=edu"

$credentials = New-Object -TypeName System.Net.NetworkCredential -ArgumentList $ConnectWithUser,$ConnectWithPassword
$c.Bind($credentials)

祝你好运

【讨论】:

    【解决方案2】:

    将 ("LDAP://ldapserver.system.edu:636") 更改为 ("ldapserver.system.edu:636"),它应该可以工作。

    $credentials = new-object System.Net.NetworkCredential("cn= Your account,ou=Your OU,o=Your Org,c=US","YourPassword")
    $NetWareServer = New-Object System.DirectoryServices.Protocols.LdapDirectoryIdentifier("ldapserver.system.edu:636")
    
    
    $c = New-Object System.DirectoryServices.Protocols.LdapConnection($NetWareServer, $credentials)
    
    $c.SessionOptions.SecureSocketLayer = $true;
    $c.SessionOptions.ProtocolVersion = 3
    $c.AuthType = [System.DirectoryServices.Protocols.AuthType]::Basic
    
    $c.Bind() 
    
    $r = (new-object "System.DirectoryServices.Protocols.ModifyRequest")
    $r.DistinguishedName = "uid=aas,ou=yourou,o=yourorg,c=US";
    
    $a = New-Object "System.DirectoryServices.Protocols.DirectoryAttributeModification"
    $a.Name = "description"
    $a.Operation = [System.DirectoryServices.Protocols.DirectoryAttributeOperation]::Add
    $a.Add("testdescription")
    
    $r.Modifications.Add($a)
    
    $re = $c.SendRequest($r);
    
    if ($re.ResultCode -ne [System.directoryServices.Protocols.ResultCode]::Success)
    {
        write-host "Failed!"
        write-host ("ResultCode: " + $re.ResultCode)
        write-host ("Message: " + $re.ErrorMessage)
    } 
    

    【讨论】:

      猜你喜欢
      • 2018-06-16
      • 1970-01-01
      • 2012-12-10
      • 1970-01-01
      • 2016-04-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多