You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用ldapjs修改Weblogic LDAP密码后,旧Webservice验证失败

ldapjs修改Weblogic LDAP密码后遗留API验证失败问题

问题现象

  • 遗留Webservice API改密后,ldapjs和API均可正常验证用户;
  • Weblogic控制台改密后,两者身份验证均正常;
  • ldapjs改密后,ldapjs自身验证正常,但遗留API提示invalid password验证失败。

所有测试基于同一用户、域和Weblogic LDAP服务器,仅改密方式不同,怀疑是ldapjs与Weblogic控制台存储密码的格式不一致导致。

现有ldapjs改密代码

export async function ldapChangePassword(username, password) {
  //create the client
  const ldapClient = ldap.createClient({
    url: 'ldap://' + LDAPURL,  //stored in env.local (root directory)
    timeout: 10000, //ms
    connectTimeout: 10000,
  });

  //bind to the server with a user authorized to perform the password change.
  try{
    bindToAdmin(ldapClient);
  }catch(err){
    ldapClient.unbind();      
    throw (err)
  }finally{

  }   

  // Set the new password
  const dn = `uid=${username},ou=people,ou=myrealm,dc=${DC}`;

  const newPassword = 'abcd1234655';
  console.log(`Changing password: ${username} ${newPassword}`);

  const userPasswordAttribute = new ldap.Attribute({
    type: 'userPassword',
    vals: newPassword
  });


  ldapClient.modify(dn, 
    [
      new ldap.Change({
        operation: 'replace',
        modification: userPasswordAttribute
      })
    ],  
    (err) => {
      if (err) {
        console.log(err);
      } else {
        console.log('Password change successful');
      }
      ldapClient.unbind();
    });
}

代码执行输出

Changing password: myUserNameABC abcd1234655
Password change successful

问题原因与解决方法

原因分析

Weblogic LDAP默认要求userPassword属性存储为SSHA加密格式,当前ldapjs代码直接写入明文密码。ldapjs自身支持明文密码验证,但遗留Webservice API仅识别Weblogic标准的加密密码格式,因此验证失败。

解决方法

将明文密码转换为SSHA加密格式后再存储,代码修改如下:

import crypto from 'crypto';

export async function ldapChangePassword(username, password) {
  const ldapClient = ldap.createClient({
    url: 'ldap://' + LDAPURL,
    timeout: 10000,
    connectTimeout: 10000,
  });

  try{
    await bindToAdmin(ldapClient); // 若bindToAdmin为异步方法需添加await
  }catch(err){
    ldapClient.unbind();      
    throw err;
  }

  const dn = `uid=${username},ou=people,ou=myrealm,dc=${DC}`;
  const newPassword = 'abcd1234655';
  console.log(`Changing password: ${username} ${newPassword}`);

  // 生成SSHA加密密码
  const salt = crypto.randomBytes(8);
  const hash = crypto.createHash('sha1');
  hash.update(newPassword);
  hash.update(salt);
  const hashBuffer = Buffer.concat([hash.digest(), salt]);
  const sshaPassword = `{SSHA}${hashBuffer.toString('base64')}`;

  const userPasswordAttribute = new ldap.Attribute({
    type: 'userPassword',
    vals: sshaPassword
  });

  ldapClient.modify(dn, 
    [
      new ldap.Change({
        operation: 'replace',
        modification: userPasswordAttribute
      })
    ],  
    (err) => {
      if (err) {
        console.log(err);
      } else {
        console.log('Password change successful');
      }
      ldapClient.unbind();
    });
}

说明

  1. SSHA是SHA-1哈希加盐后的格式,为Weblogic默认的密码存储格式;
  2. 必须添加{SSHA}前缀,告知LDAP服务器密码的加密类型;
  3. 若bindToAdmin为异步方法,需添加await确保绑定完成后再执行修改操作。

内容的提问来源于stack exchange,提问作者NL3294

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 05:47:45