gpt4 book ai didi

c# - 将来自不同域的用户添加到 AD 通用组 C#

转载 作者:太空宇宙 更新时间:2023-11-03 21:24:42 24 4
gpt4 key购买 nike

我们在同一个林中有很多域(即 sw.main.company.com、nw.main.company.com、main.company.com),我控制了 sw.main.company.com 中的一个 OU我在其中设置了通用 Active Directory 组。

我在默认 AD 端口上使用 System.DirectoryServices.AccountManagement .NET 4.5 等实用地 (c#) 将“sw”域用户添加到组中没有任何困难,但是当涉及到从其他域添加用户时 (nw , mw, 等),当设置新的 PrincipalContext(ContextType.Domain "sw .main.company.com:3268", "DC=main,DC=company,DC=com").

所有域 Controller 也是全局目录服务器,调用端口 3268 允许来自其他域的用户正确解析,但我无法在不抛出错误的情况下使用 GlobalPrincipal.Save() 命令提交添加。

我在下面包含了相关代码以及详细的错误堆栈。我需要这方面的帮助。

public void SyncADUsers()
{
AddUserToGroup("MW\\abc123user", "Universal_Group_1");
}

public void AddUserToGroup(string userId, string groupName)
{
try
{
using (PrincipalContext pc = new PrincipalContext(ContextType.Domain, "sw.main.company.com:3268", "DC=main,DC=company,DC=com"))
{
GroupPrincipal group = GroupPrincipal.FindByIdentity(pc, groupName);
group.Members.Add(pc, IdentityType.SamAccountName, userId);
group.Save();
}
}
catch (System.DirectoryServices.DirectoryServicesCOMException E)
{
//doSomething with E.Message.ToString();
}
}

System.InvalidOperationException 未处理 HResult=-2146233079 Message=服务器不愿处理请求。 Source=System.DirectoryServices.AccountManagement StackTrace:在 System.DirectoryServices.AccountManagement.ADStoreCtx System.DirectoryServices.AccountManagement.SDSUtils.ApplyChangesToDirectory(主体 p,StoreCtx storeCtx,GroupMembershipUpdater updateGroupMembership,NetCred 凭据,AuthenticationTypes authTypes)在 System.DirectoryServices.AccountManagement.ADStoreCtx。在 C:\SourceControl\ExampleUsers\ExampleUsers\SyncAD.cs 中的 ExampleUsers.SyncAD.AddUserToGroup(String userId, String groupName) 中的 System.DirectoryServices.AccountManagement.Principal.Save() 中更新(主体 p):ExampleUsers.SyncAD 中的第 33 行.SyncADUsers() 在 c:\SourceControl\ExampleUsers\ExampleUsers\SyncAD.cs:line 18 at ExampleUsers.Program.Main(String[] args) in c:\SourceControl\ExampleUsers\ExampleUsers\Program.cs:line 62 at System .AppDomain._nExecuteAssembly(RuntimeAssembly assembly, String[] args) 在 System.AppDomain.ExecuteAssembly(String assemblyFile, Evidence assemblySecurity, String[] args) 在 Microsoft.VisualStudio.HostingProcess.HostProc.RunUsersAssembly() 在 System.Threading.ThreadHelper。 ThreadStart_Context(对象状态)在 System.Threading.ExecutionContext.RunInternal(ExecutionContext executionContext,ContextCallback 回调,对象状态, bool 值 preserveSyncCtx)在 System.Threading.ExecutionContext.Run(ExecutionContext executionContext,ContextCallback 回调,对象状态, bool 值 preserveSyncCtx)在系统。 Threading.ExecutionContext.Run(ExecutionContext executionContext, ContextCallback callback, Object state) at System.Threading.ThreadHelper.ThreadStart() InnerException: System.DirectoryServices.DirectoryServicesCOMException HResult=-2147016651 Message=服务器不愿意处理请求。 Source=System.DirectoryServices ErrorCode=-2147016651 ExtendedError=8245 ExtendedErrorMessage=00002035: LdapErr: DSID-0C090B3E,注释:不允许通过 GC 端口进行操作,数据 0,v1db1 StackTrace:在 System.DirectoryServices.DirectoryEntry.CommitChanges( )在 System.DirectoryServices.AccountManagement.ADStoreCtx.UpdateGroupMembership(主体组、DirectoryEntry de、NetCred 凭据、AuthenticationTypes authTypes)InnerException:

最佳答案

引用BaldPate的回应,如果全局目录是只读的,我们需要使用3268端口读取和解析不同域中的用户,然后将使用389端口的用户全部保存在同一上下文中。这可以通过以下代码完成(注意对 3268 和默认 389 端口的单独调用)并感谢 BaldPate 使这一点变得清晰:

using System;
using System.Collections;
using System.Data;
using System.Data.SqlClient;
using System.Collections.Generic;
using System.DirectoryServices.AccountManagement;
using System.Linq;
using System.Text;
using System.Threading.Tasks;
using System.Configuration;

namespace OurUsers
{
class SyncAD
{
#region Variables

private string sDomain = "sw.main.company.com";
private string sDomainGC = "sw.main.company.com:3268";
private string sDefaultOU = "DC=sw,DC=main,DC=company,DC=com";
private string sDefaultRootOU = "DC=main,DC=company,DC=com";
private string sGroupName = "Production_Universal_AD_Group";
private string connectionString = "Server=OurServerName\\PROD; Integrated Security=True; Initial Catalog=OurUsers";
private string sqlAdd = "SELECT FullID FROM ViewFolkstoAdd";
private string sqlRemove = "SELECT FullID FROM ViewFolkstoRemove";

#endregion
public void SyncADUsers()
{
// Get Database Ready and Remove Users
SqlConnection connectionRemove = new SqlConnection(connectionString);
SqlCommand commandRemove = new SqlCommand(sqlRemove, connectionRemove);
connectionRemove.Open();
SqlDataReader readerRemove = commandRemove.ExecuteReader();

if (readerRemove.HasRows)
{
int i = 0;
while (readerRemove.Read())
{
string sUserName = readerRemove.GetString(0);
RemoveUserFromGroup(sUserName, sGroupName);
i = i + 1;
Console.WriteLine("{0} {1}", i, sUserName);
}
}
else
{
Console.WriteLine("No rows found.");
}
readerRemove.Close();

// Get Database Ready and Add Users
SqlConnection connectionAdd = new SqlConnection(connectionString);
SqlCommand commandAdd = new SqlCommand(sqlAdd, connectionAdd);
connectionAdd.Open();
SqlDataReader readerAdd = commandAdd.ExecuteReader();

if (readerAdd.HasRows)
{
int i = 0;
while (readerAdd.Read())
{
string sUserName = readerAdd.GetString(0);
AddUserToGroup(sUserName, sGroupName);
i = i + 1;
Console.WriteLine("{0} {1}", i, sUserName);
}
}
else
{
Console.WriteLine("No rows found.");
}
readerAdd.Close();
}

/// Gets a certain user on Active Directory
/// Returns the UserPrincipal Object
public UserPrincipal GetUser(string sUserName)
{
PrincipalContext oPrincipalContext = GetPrincipalContextGC();
UserPrincipal oUserPrincipal = UserPrincipal.FindByIdentity(oPrincipalContext, sUserName);
return oUserPrincipal;
}

/// Adds the user for a given group
/// Returns true if successful
public bool AddUserToGroup(string sUserName, string sGroupName)
{
try
{
UserPrincipal oUserPrincipal = GetUser(sUserName);
GroupPrincipal oGroupPrincipal = GetGroup(sGroupName);
if (oUserPrincipal != null && oGroupPrincipal != null)
{
oGroupPrincipal.Members.Add(oUserPrincipal);
oGroupPrincipal.Save();
}
return true;
}
catch
{
return false;
}
}

/// Removes user from a given group
/// Returns true if successful
public bool RemoveUserFromGroup(string sUserName, string sGroupName)
{
try
{
UserPrincipal oUserPrincipal = GetUser(sUserName);
GroupPrincipal oGroupPrincipal = GetGroup(sGroupName);
if (oUserPrincipal != null && oGroupPrincipal != null)
{
oGroupPrincipal.Members.Remove(oUserPrincipal);
oGroupPrincipal.Save();
}
return true;
}
catch
{
return false;
}
}

/// Gets PrincipalContext from the Local Domain
/// Returns the PrincipalContext
public PrincipalContext GetPrincipalContext()
{
PrincipalContext oPrincipalContext = new PrincipalContext(ContextType.Domain, sDomain, sDefaultOU, ContextOptions.Negotiate);
return oPrincipalContext;
}

/// Gets PrincipalContext from the Global Catalog
/// Returns the PrincipalContext
public PrincipalContext GetPrincipalContextGC()
{
PrincipalContext oPrincipalContext = new PrincipalContext(ContextType.Domain, sDomainGC, sDefaultRootOU, ContextOptions.Negotiate);
return oPrincipalContext;
}

/// Gets a certain group on Active Directory
/// Returns the GroupPrincipal Object
public GroupPrincipal GetGroup(string sGroupName)
{
PrincipalContext oPrincipalContext = GetPrincipalContext();
GroupPrincipal oGroupPrincipal = GroupPrincipal.FindByIdentity(oPrincipalContext, sGroupName);
return oGroupPrincipal;
}
}
}

关于c# - 将来自不同域的用户添加到 AD 通用组 C#,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/27940008/

24 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com