[英]Adding Users to AD Universal Group from Different Domains C#
我们在同一个目录林中有许多域(即sw.main.company.com,nw.main.company.com,main.company.com),并且我在sw.main.company.com中拥有一个OU的控制权设置通用Active Directory组。
我在默认的AD端口上使用System.DirectoryServices.AccountManagement .NET 4.5等实用地(c#)将“ sw”域用户添加到组中没有任何困难,但是在添加来自其他域(nw,mw,等等),设置新的PrincipalContext(ContextType.Domain“ sw.main”时,出现“ HResult = -2147016651 Message =服务器不愿意处理请求”和“不允许通过GC端口,数据0,v1db1进行的操作”。 company.com:3268","DC=主要,DC =公司,DC = com“)。
所有域控制器也是全局编录服务器,并且调用端口3268允许来自其他域的用户正确解析,但是我不能使用GlobalPrincipal.Save()命令提交附加操作,而不会引发错误。
我在下面包括了相关代码以及详细的错误堆栈。 我需要这方面的帮助。
public void SyncADUsers()
{
AddUserToGroup("MW\\abc123user", "Universal_Group_1");
}
public void AddUserToGroup(string userId, string groupName)
{
try
{
using (PrincipalContext pc = new PrincipalContext(ContextType.Domain, "sw.main.company.com:3268", "DC=main,DC=company,DC=com"))
{
GroupPrincipal group = GroupPrincipal.FindByIdentity(pc, groupName);
group.Members.Add(pc, IdentityType.SamAccountName, userId);
group.Save();
}
}
catch (System.DirectoryServices.DirectoryServicesCOMException E)
{
//doSomething with E.Message.ToString();
}
}
未处理System.InvalidOperationException HResult = -2146233079 Message =服务器不愿意处理该请求。 Source = System.DirectoryServices.AccountManagement StackTrace:位于System.DirectoryServices.AccountManagement.ADStoreCtx.UpdateGroupMembership(主体组,DirectoryEntry de,NetCred凭据,AuthenticationTypes authTypes)位于System.DirectoryServices.AccountManagement.SDSUtils.ApplyChangesToDirectoryMembership(主体p,UpdateCtx,StoreCtx在c的ExampleUsers.SyncAD.AddUserToGroup(String userId,String groupName)的System.DirectoryServices.AccountManagement.ADStoreCtx.Update(Principal p)的System.DirectoryServices.AccountManagement.ADStoreCtx.Update(Principal p)处的updateGroupMembership,NetCred凭证authTypes) \\ SourceControl \\ ExampleUsers \\ ExampleUsers \\ SyncAD.cs:第33行,位于c:\\ SourceControl \\ ExampleUsers \\ ExampleUsers \\ SyncAD.cs:第13行,位于ExampleUsers.Program.Main(String [] args)中c:\\ SourceControl \\ ExampleUsers \\ ExampleUsers \\ Program.cs:System.AppDomain._nExecuteAssembly中的第62行(RuntimeAssembly程序集,String []参数 )在System.AppDomain.ExecuteAssembly(String assemblyFile,Evidence assemblySecurity,String [] args)在Microsoft.VisualStudio.HostingProcess.HostProc.RunUsersAssembly()在System.Threading.ThreadHelper.ThreadStart_Context(Object state)在System.Threading.ExecutionContext。 System.Threading.ExecutionContext.Run(ExecutionContext执行上下文,ContextCallback回调,对象状态,布尔值保持SyncCtx)在System.Threading.ExecutionContext.Run(ExecutionContext执行上下文,ContextCallback回调,对象状态,BooleanCallbackSyncCtx) System.Threading.ThreadHelper.ThreadStart()上的对象状态)InnerException:System.DirectoryServices.DirectoryServicesCOMException HResult = -2147016651 Message =服务器不愿意处理该请求。 源= System.DirectoryServices错误代码= -2147016651 ExtendedError = 8245 ExtendedErrorMessage = 00002035:LdapErr:DSID-0C090B3E,注释:不允许通过GC端口,数据0,v1db1 StackTrace进行操作:位于系统的System.DirectoryServices.DirectoryEntry.CommitChanges()。 DirectoryServices.AccountManagement.ADStoreCtx.UpdateGroupMembership(主体组,DirectoryEntry de,NetCred凭据,AuthenticationTypes authTypes)InnerException:
参考BaldPate的响应,如果Global Catalog是只读的,我们需要使用3268端口读取和解析不同域中的用户,然后在相同的上下文中使用389端口保存用户。 这可以通过以下代码(请注意分别对3268和默认389端口的调用)来完成,并感谢BaldPate的明确说明:
using System;
using System.Collections;
using System.Data;
using System.Data.SqlClient;
using System.Collections.Generic;
using System.DirectoryServices.AccountManagement;
using System.Linq;
using System.Text;
using System.Threading.Tasks;
using System.Configuration;
namespace OurUsers
{
class SyncAD
{
#region Variables
private string sDomain = "sw.main.company.com";
private string sDomainGC = "sw.main.company.com:3268";
private string sDefaultOU = "DC=sw,DC=main,DC=company,DC=com";
private string sDefaultRootOU = "DC=main,DC=company,DC=com";
private string sGroupName = "Production_Universal_AD_Group";
private string connectionString = "Server=OurServerName\\PROD; Integrated Security=True; Initial Catalog=OurUsers";
private string sqlAdd = "SELECT FullID FROM ViewFolkstoAdd";
private string sqlRemove = "SELECT FullID FROM ViewFolkstoRemove";
#endregion
public void SyncADUsers()
{
// Get Database Ready and Remove Users
SqlConnection connectionRemove = new SqlConnection(connectionString);
SqlCommand commandRemove = new SqlCommand(sqlRemove, connectionRemove);
connectionRemove.Open();
SqlDataReader readerRemove = commandRemove.ExecuteReader();
if (readerRemove.HasRows)
{
int i = 0;
while (readerRemove.Read())
{
string sUserName = readerRemove.GetString(0);
RemoveUserFromGroup(sUserName, sGroupName);
i = i + 1;
Console.WriteLine("{0} {1}", i, sUserName);
}
}
else
{
Console.WriteLine("No rows found.");
}
readerRemove.Close();
// Get Database Ready and Add Users
SqlConnection connectionAdd = new SqlConnection(connectionString);
SqlCommand commandAdd = new SqlCommand(sqlAdd, connectionAdd);
connectionAdd.Open();
SqlDataReader readerAdd = commandAdd.ExecuteReader();
if (readerAdd.HasRows)
{
int i = 0;
while (readerAdd.Read())
{
string sUserName = readerAdd.GetString(0);
AddUserToGroup(sUserName, sGroupName);
i = i + 1;
Console.WriteLine("{0} {1}", i, sUserName);
}
}
else
{
Console.WriteLine("No rows found.");
}
readerAdd.Close();
}
/// Gets a certain user on Active Directory
/// Returns the UserPrincipal Object
public UserPrincipal GetUser(string sUserName)
{
PrincipalContext oPrincipalContext = GetPrincipalContextGC();
UserPrincipal oUserPrincipal = UserPrincipal.FindByIdentity(oPrincipalContext, sUserName);
return oUserPrincipal;
}
/// Adds the user for a given group
/// Returns true if successful
public bool AddUserToGroup(string sUserName, string sGroupName)
{
try
{
UserPrincipal oUserPrincipal = GetUser(sUserName);
GroupPrincipal oGroupPrincipal = GetGroup(sGroupName);
if (oUserPrincipal != null && oGroupPrincipal != null)
{
oGroupPrincipal.Members.Add(oUserPrincipal);
oGroupPrincipal.Save();
}
return true;
}
catch
{
return false;
}
}
/// Removes user from a given group
/// Returns true if successful
public bool RemoveUserFromGroup(string sUserName, string sGroupName)
{
try
{
UserPrincipal oUserPrincipal = GetUser(sUserName);
GroupPrincipal oGroupPrincipal = GetGroup(sGroupName);
if (oUserPrincipal != null && oGroupPrincipal != null)
{
oGroupPrincipal.Members.Remove(oUserPrincipal);
oGroupPrincipal.Save();
}
return true;
}
catch
{
return false;
}
}
/// Gets PrincipalContext from the Local Domain
/// Returns the PrincipalContext
public PrincipalContext GetPrincipalContext()
{
PrincipalContext oPrincipalContext = new PrincipalContext(ContextType.Domain, sDomain, sDefaultOU, ContextOptions.Negotiate);
return oPrincipalContext;
}
/// Gets PrincipalContext from the Global Catalog
/// Returns the PrincipalContext
public PrincipalContext GetPrincipalContextGC()
{
PrincipalContext oPrincipalContext = new PrincipalContext(ContextType.Domain, sDomainGC, sDefaultRootOU, ContextOptions.Negotiate);
return oPrincipalContext;
}
/// Gets a certain group on Active Directory
/// Returns the GroupPrincipal Object
public GroupPrincipal GetGroup(string sGroupName)
{
PrincipalContext oPrincipalContext = GetPrincipalContext();
GroupPrincipal oGroupPrincipal = GroupPrincipal.FindByIdentity(oPrincipalContext, sGroupName);
return oGroupPrincipal;
}
}
}
全局编录是只读的。
请连接到LDAP端口(默认为389)以更新组。
声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.