You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Python ldap3获取域控制器列表时绑定连接报错求助

用Python ldap3连接LDAP时出现LDAPBindError,无法获取域控制器列表

我正在编写脚本,尝试通过Python ldap3库获取某域的所有域控制器列表,但建立连接时出现LDAPBindError错误。以下是我的代码及报错信息:

代码

#!/usr/bin/python3

from ldap3 import Server, Connection

# LDAP server configuration
ldap_server = 'ldap://company.com'
ldap_user = 'username'
ldap_password = 'mypassword'

# Connect to the LDAP server
server = Server(ldap_server, get_info=Server.info)
conn = Connection(server, ldap_user, ldap_password, auto_bind=True)

# Search for domain controllers
conn.search(search_base='CN=Domain Controllers,DC=company,DC=com',
            search_filter='(objectClass=computer)',
            attributes=['name'])

# Print the list of domain controllers
print("Domain Controllers:")
for entry in conn.entries:
    print(entry.name)

报错输出

Traceback (most recent call last):
  File "./query-dc-list4.py", line 13, in <module>
    conn = Connection(server, ldap_user, ldap_password, auto_bind=True)
  File "/usr/lib/python3.6/site-packages/ldap3/core/connection.py", line 356, in __init__
    self._do_auto_bind()
  File "/usr/lib/python3.6/site-packages/ldap3/core/connection.py", line 405, in _do_auto_bind
    raise LDAPBindError(error)

解决建议

  • 修正用户名格式:域环境绑定LDAP必须使用完整身份标识,要么是用户主体名称(UPN)格式username@company.com,要么是域前缀格式COMPANY\username,不能只写单纯的username。
  • 确认LDAP服务器地址有效性:ldap://company.com可能无法正确解析到域控制器,建议直接指定具体域控制器的主机名或IP,比如ldap://dc01.company.com。
  • 检查连接加密与端口:如果域要求SSL连接,需改用ldaps://company.com(默认端口636),并在创建Server对象时添加use_ssl=True参数;若用普通LDAP(端口389),确保网络未拦截该端口。
  • 验证账号状态:确认绑定账号密码正确、未被锁定,且拥有域内LDAP读取权限,同时当前主机在域的允许访问范围内。
  • 开启调试日志:修改Connection初始化代码,添加调试参数获取详细错误信息:
    conn = Connection(server, ldap_user, ldap_password, auto_bind=True, raise_exceptions=True, logger=print)
    

调整后的示例代码

#!/usr/bin/python3
from ldap3 import Server, Connection

# 调整后的LDAP配置
ldap_server = 'ldap://dc01.company.com'  # 指定具体域控制器
ldap_user = 'username@company.com'       # 使用UPN格式用户名
ldap_password = 'mypassword'

# 根据实际情况设置use_ssl
server = Server(ldap_server, get_info=Server.info, use_ssl=False)
# 开启调试输出,便于排查问题
conn = Connection(server, ldap_user, ldap_password, auto_bind=True, raise_exceptions=True, logger=print)

# 搜索域控制器
conn.search(search_base='CN=Domain Controllers,DC=company,DC=com',
            search_filter='(objectClass=computer)',
            attributes=['name'])

print("Domain Controllers:")
for entry in conn.entries:
    print(entry.name)

内容的提问来源于stack exchange,提问作者Frosty.Fluffy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 01:42:52