使用DirectorySearcher进行AD搜索时忽略证书错误的方法
解决方案:在DirectorySearcher/DirectoryEntry中忽略AD证书错误
DirectoryEntry和DirectorySearcher(属于System.DirectoryServices)本身没有提供像LdapConnection那样的直接证书验证回调配置,因为它们底层依赖ADSI(Active Directory Service Interfaces),证书验证逻辑由系统默认处理。以下是两种可行的解决方式:
方式一:全局证书验证回调(简单但需注意范围)
通过设置全局的SSL证书验证回调,可以让整个应用忽略所有证书错误(包括AD的LDAPS连接)。注意:此设置会影响应用内所有SSL/TLS请求,非必要不推荐在生产环境使用。
// 在应用启动或AD连接代码前添加此回调 System.Net.ServicePointManager.ServerCertificateValidationCallback += (sender, certificate, chain, sslPolicyErrors) => true; // 正常使用DirectoryEntry和DirectorySearcher using (var adEntry = new DirectoryEntry( "LDAPS://your-ad-server:636", "domain\\username", "password", AuthenticationTypes.SecureSocketsLayer | AuthenticationTypes.Secure )) { using (var searcher = new DirectorySearcher(adEntry)) { searcher.Filter = "(objectClass=user)"; searcher.PropertiesToLoad.AddRange(new[] { "samaccountname", "displayname" }); foreach (SearchResult result in searcher.FindAll()) { // 处理搜索结果 Console.WriteLine($"用户名:{result.Properties["samaccountname"][0]}"); } } }
如果需要在使用后恢复默认验证逻辑,可以移除回调:
System.Net.ServicePointManager.ServerCertificateValidationCallback -= (sender, certificate, chain, sslPolicyErrors) => true;
方式二:结合LdapConnection与DirectoryEntry(更安全精准)
利用LdapConnection(System.DirectoryServices.Protocols)的证书验证配置完成AD连接,再将搜索结果转换为DirectoryEntry对象,既保留精准的证书控制,又能使用DirectoryEntry的功能。
using System.DirectoryServices.Protocols; using System.Net; // 配置LdapConnection并忽略证书错误 var ldapId = new LdapDirectoryIdentifier("your-ad-server", 636); using (var connection = new LdapConnection(ldapId)) { connection.Credential = new NetworkCredential("domain\\username", "password"); connection.SessionOptions.SecureSocketLayer = true; connection.SessionOptions.VerifyServerCertificate = (conn, cert) => true; // 绑定到AD connection.Bind(); // 构建搜索请求 var searchRequest = new SearchRequest( "DC=your-domain,DC=com", // AD搜索根节点 "(objectClass=user)", // 过滤条件 SearchScope.Subtree, "distinguishedname", "samaccountname" // 需要返回的属性 ); // 执行搜索 var searchResponse = (SearchResponse)connection.SendRequest(searchRequest); // 将搜索结果转换为DirectoryEntry foreach (SearchResultEntry entry in searchResponse.Entries) { using (var dirEntry = new DirectoryEntry( $"LDAPS://your-ad-server:636/{entry.DistinguishedName}", "domain\\username", "password", AuthenticationTypes.SecureSocketsLayer | AuthenticationTypes.Secure )) { // 操作DirectoryEntry对象 Console.WriteLine($"用户显示名:{dirEntry.Properties["displayname"].Value}"); } } }
注意事项
- 全局回调方式虽然简单,但会降低应用整体的SSL安全性,仅建议在测试环境临时使用。
- 结合
LdapConnection的方式更安全,仅针对AD的LDAPS连接生效,适合生产环境使用。
内容的提问来源于stack exchange,提问作者Kaygee Del Hlobo
相关产品推荐
相关产品推荐

