Python LDAP搜索添加OU过滤时遇错误及无结果问题
LDAP搜索脚本扩展OU过滤条件遇问题
问题描述
我有一个用于LDAP服务器搜索的Python脚本,之前仅在Base DN中设置DC过滤条件时运行正常。现在想要扩展过滤条件到OU,但在Base DN中加入OU后出现以下错误:
/usr/bin/python3.6 /home/zeinab/PycharmProjects/ldap-test/main.py Traceback (most recent call last): File "/home/zeinab/PycharmProjects/ldap-test/main.py", line 29, in <module> search_scope=SUBTREE) File "/home/zeinab/.local/lib/python3.6/site-packages/ldap3/core/connection.py", line 853, in search response = self.post_send_search(self.send('searchRequest', request, controls)) File "/home/zeinab/.local/lib/python3.6/site-packages/ldap3/strategy/sync.py", line 178, in post_send_search responses, result = self.get_response(message_id) File "/home/zeinab/.local/lib/python3.6/site-packages/ldap3/strategy/base.py", line 403, in get_response raise LDAPOperationResult(result=result['result'], description=result['description'], dn=result['dn'], message=result['message'], response_type=result['type']) ldap3.core.exceptions.LDAPOperationsErrorResult: LDAPOperationsErrorResult - 1 - operationsError - None - 000020D6: SvcErr: DSID-03100837, problem 5012 (DIR_ERROR), data 0 - searchResDone - None
原脚本代码如下:
from ldap3 import Server, Connection, SIMPLE, ALL, SUBTREE server = Server(host=host, port=port, get_info=ALL, connect_timeout=10, use_ssl=True) connection = Connection( server=server, user=username, password=password, raise_exceptions=True, authentication=SIMPLE, ) connection.open() connection.bind() base_dn = "dc=dc1,dc=local,ou=ou0,ou=ou1" search_filter = "(&(objectClass=person)(mail=john*))" search_attribute = ['mail'] connection.search(search_base=base_dn, search_filter=search_filter, attributes=search_attribute, search_scope=SUBTREE) resp = connection.response print(len(resp)) print(resp) connection.unbind()
尝试的解决方法
编辑1
尝试在搜索过滤器中添加OU匹配条件,保持原Base DN不变:
base_dn = "dc=dc1,dc=local,ou=ou0,ou=ou1" search_filter = "(&(objectClass=person)(mail=john*)(ou:dn:=ou1))"
结果:出现完全相同的错误。
编辑2
调整Base DN为根域,在过滤器中添加OU条件,尝试两种写法:
方式一:
base_dn = "dc=dc1,dc=local" search_filter = "(&(objectClass=person)(mail=john*)(ou:dn:=ou1))"
方式二:
base_dn = "dc=dc1,dc=local" search_filter = "(&(objectClass=person)(mail=john*)(ou:=ou1))"
结果:两种方式均未报错,但未返回任何结果,实际上存在符合过滤条件的数据。
内容的提问来源于stack exchange,提问作者Zeinab Abbasimazar
相关产品推荐
相关产品推荐

