使用PowerShell通过LDAP添加用户时遇类型未定义错误求助
问题:PowerShell添加LDAP用户时报"The type is not defined"错误
我尝试通过PowerShell向LDAP服务器添加用户时,出现以下错误:
Exception calling "SendRequest" with "1" argument(s): "The type is not defined." At line:11 char:1 + $response = $connection.SendRequest($request) + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : NotSpecified: (:) [], MethodInvocationException + FullyQualifiedErrorId : DirectoryOperationException
我的代码如下:
$credential = New-Object -TypeName System.Net.NetworkCredential -ArgumentList ($ldapUser, $ldapPass) $directoryIdentifier = New-Object -TypeName System.DirectoryServices.Protocols.LdapDirectoryIdentifier -ArgumentList ($ldapServer, $ldapPort) $connection = New-Object -TypeName System.DirectoryServices.Protocols.LdapConnection -ArgumentList ($directoryIdentifier, $credential, [DirectoryServices.Protocols.AuthType]::Basic) $connection.SessionOptions.ProtocolVersion = 3 $connection.Bind() $request = New-Object -TypeName System.DirectoryServices.Protocols.AddRequest $request.DistinguishedName = "uid=Test_Thomas,ou=Users,ou=DE,ou=saria,dc=ext,dc=saria,dc=com" $request.Attributes.Add((New-Object -TypeName System.DirectoryServices.Protocols.DirectoryAttribute -ArgumentList "objectclass", @("top","organizationalPerson","person","inetorgperson"))) | Out-Null $request.Attributes.Add((New-Object -TypeName System.DirectoryServices.Protocols.DirectoryAttribute -ArgumentList "cn", $ExistingFrontlineWorkers[1].cn)) | Out-Null $request.Attributes.Add((New-Object -TypeName System.DirectoryServices.Protocols.DirectoryAttribute -ArgumentList "sn", $ExistingFrontlineWorkers[1].sn)) | Out-Null $request.Attributes.Add((New-Object -TypeName System.DirectoryServices.Protocols.DirectoryAttribute -ArgumentList "mail", $ExistingFrontlineWorkers[1].mail)) | Out-Null $request.Attributes.Add((New-Object -TypeName System.DirectoryServices.Protocols.DirectoryAttribute -ArgumentList "uid", "Test_Thomas")) | Out-Null $request.Attributes.Add((New-Object -TypeName System.DirectoryServices.Protocols.DirectoryAttribute -ArgumentList "uidNumber", "1000")) | Out-Null $request.Attributes.Add((New-Object -TypeName System.DirectoryServices.Protocols.DirectoryAttribute -ArgumentList "gidNumber", "1000")) | Out-Null $request.Attributes.Add((New-Object -TypeName System.DirectoryServices.Protocols.DirectoryAttribute -ArgumentList "homeDirectory", "")) | Out-Null $response = $connection.SendRequest($request)
LDAP连接无问题,我可以正常执行搜索操作。
问题分析与解决
这个错误核心原因是LDAP服务器无法识别请求中的属性类型或格式,以下是针对性修改方案:
1. 调整objectClass顺序
部分LDAP服务器(如OpenLDAP)要求objectClass按继承顺序声明,父类需排在子类前面。将objectclass的属性值顺序改为:@("top","person","organizationalPerson","inetorgperson")
2. 修正uidNumber和gidNumber的类型
uidNumber和gidNumber是LDAP中的整数类型属性,不能传入字符串值,需改为数值类型(如1000而非"1000")。
3. 为homeDirectory设置有效值
多数LDAP服务器不允许homeDirectory为空字符串,需指定合法的用户主目录路径,比如/home/Test_Thomas。
修改后的代码片段
$request = New-Object -TypeName System.DirectoryServices.Protocols.AddRequest $request.DistinguishedName = "uid=Test_Thomas,ou=Users,ou=DE,ou=saria,dc=ext,dc=saria,dc=com" # 调整objectClass继承顺序 $request.Attributes.Add((New-Object -TypeName System.DirectoryServices.Protocols.DirectoryAttribute -ArgumentList "objectclass", @("top","person","organizationalPerson","inetorgperson"))) | Out-Null $request.Attributes.Add((New-Object -TypeName System.DirectoryServices.Protocols.DirectoryAttribute -ArgumentList "cn", $ExistingFrontlineWorkers[1].cn)) | Out-Null $request.Attributes.Add((New-Object -TypeName System.DirectoryServices.Protocols.DirectoryAttribute -ArgumentList "sn", $ExistingFrontlineWorkers[1].sn)) | Out-Null $request.Attributes.Add((New-Object -TypeName System.DirectoryServices.Protocols.DirectoryAttribute -ArgumentList "mail", $ExistingFrontlineWorkers[1].mail)) | Out-Null $request.Attributes.Add((New-Object -TypeName System.DirectoryServices.Protocols.DirectoryAttribute -ArgumentList "uid", "Test_Thomas")) | Out-Null # 使用数值类型的ID值 $request.Attributes.Add((New-Object -TypeName System.DirectoryServices.Protocols.DirectoryAttribute -ArgumentList "uidNumber", 1000)) | Out-Null $request.Attributes.Add((New-Object -TypeName System.DirectoryServices.Protocols.DirectoryAttribute -ArgumentList "gidNumber", 1000)) | Out-Null # 设置有效的主目录路径 $request.Attributes.Add((New-Object -TypeName System.DirectoryServices.Protocols.DirectoryAttribute -ArgumentList "homeDirectory", "/home/Test_Thomas")) | Out-Null $response = $connection.SendRequest($request)
额外验证
如果修改后仍报错,可通过LDAP搜索确认服务器是否支持inetorgperson等objectClass,确保相关Schema已在服务器中加载。
内容的提问来源于stack exchange,提问作者thomas fidorin
相关产品推荐
相关产品推荐

