使用ldapjs修改Weblogic LDAP密码后,旧Webservice验证失败
ldapjs修改Weblogic LDAP密码后遗留API验证失败问题
问题现象
- 遗留Webservice API改密后,ldapjs和API均可正常验证用户;
- Weblogic控制台改密后,两者身份验证均正常;
- ldapjs改密后,ldapjs自身验证正常,但遗留API提示
invalid password验证失败。
所有测试基于同一用户、域和Weblogic LDAP服务器,仅改密方式不同,怀疑是ldapjs与Weblogic控制台存储密码的格式不一致导致。
现有ldapjs改密代码
export async function ldapChangePassword(username, password) { //create the client const ldapClient = ldap.createClient({ url: 'ldap://' + LDAPURL, //stored in env.local (root directory) timeout: 10000, //ms connectTimeout: 10000, }); //bind to the server with a user authorized to perform the password change. try{ bindToAdmin(ldapClient); }catch(err){ ldapClient.unbind(); throw (err) }finally{ } // Set the new password const dn = `uid=${username},ou=people,ou=myrealm,dc=${DC}`; const newPassword = 'abcd1234655'; console.log(`Changing password: ${username} ${newPassword}`); const userPasswordAttribute = new ldap.Attribute({ type: 'userPassword', vals: newPassword }); ldapClient.modify(dn, [ new ldap.Change({ operation: 'replace', modification: userPasswordAttribute }) ], (err) => { if (err) { console.log(err); } else { console.log('Password change successful'); } ldapClient.unbind(); }); }
代码执行输出
Changing password: myUserNameABC abcd1234655 Password change successful
问题原因与解决方法
原因分析
Weblogic LDAP默认要求userPassword属性存储为SSHA加密格式,当前ldapjs代码直接写入明文密码。ldapjs自身支持明文密码验证,但遗留Webservice API仅识别Weblogic标准的加密密码格式,因此验证失败。
解决方法
将明文密码转换为SSHA加密格式后再存储,代码修改如下:
import crypto from 'crypto'; export async function ldapChangePassword(username, password) { const ldapClient = ldap.createClient({ url: 'ldap://' + LDAPURL, timeout: 10000, connectTimeout: 10000, }); try{ await bindToAdmin(ldapClient); // 若bindToAdmin为异步方法需添加await }catch(err){ ldapClient.unbind(); throw err; } const dn = `uid=${username},ou=people,ou=myrealm,dc=${DC}`; const newPassword = 'abcd1234655'; console.log(`Changing password: ${username} ${newPassword}`); // 生成SSHA加密密码 const salt = crypto.randomBytes(8); const hash = crypto.createHash('sha1'); hash.update(newPassword); hash.update(salt); const hashBuffer = Buffer.concat([hash.digest(), salt]); const sshaPassword = `{SSHA}${hashBuffer.toString('base64')}`; const userPasswordAttribute = new ldap.Attribute({ type: 'userPassword', vals: sshaPassword }); ldapClient.modify(dn, [ new ldap.Change({ operation: 'replace', modification: userPasswordAttribute }) ], (err) => { if (err) { console.log(err); } else { console.log('Password change successful'); } ldapClient.unbind(); }); }
说明
- SSHA是SHA-1哈希加盐后的格式,为Weblogic默认的密码存储格式;
- 必须添加
{SSHA}前缀,告知LDAP服务器密码的加密类型; - 若
bindToAdmin为异步方法,需添加await确保绑定完成后再执行修改操作。
内容的提问来源于stack exchange,提问作者NL3294
相关产品推荐
相关产品推荐

