You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用DirectorySearcher进行AD搜索时忽略证书错误的方法

解决方案:在DirectorySearcher/DirectoryEntry中忽略AD证书错误

DirectoryEntry和DirectorySearcher(属于System.DirectoryServices)本身没有提供像LdapConnection那样的直接证书验证回调配置,因为它们底层依赖ADSI(Active Directory Service Interfaces),证书验证逻辑由系统默认处理。以下是两种可行的解决方式:

方式一:全局证书验证回调(简单但需注意范围)

通过设置全局的SSL证书验证回调,可以让整个应用忽略所有证书错误(包括AD的LDAPS连接)。注意:此设置会影响应用内所有SSL/TLS请求,非必要不推荐在生产环境使用。

// 在应用启动或AD连接代码前添加此回调
System.Net.ServicePointManager.ServerCertificateValidationCallback += 
    (sender, certificate, chain, sslPolicyErrors) => true;

// 正常使用DirectoryEntry和DirectorySearcher
using (var adEntry = new DirectoryEntry(
    "LDAPS://your-ad-server:636",
    "domain\\username",
    "password",
    AuthenticationTypes.SecureSocketsLayer | AuthenticationTypes.Secure
))
{
    using (var searcher = new DirectorySearcher(adEntry))
    {
        searcher.Filter = "(objectClass=user)";
        searcher.PropertiesToLoad.AddRange(new[] { "samaccountname", "displayname" });
        
        foreach (SearchResult result in searcher.FindAll())
        {
            // 处理搜索结果
            Console.WriteLine($"用户名:{result.Properties["samaccountname"][0]}");
        }
    }
}

如果需要在使用后恢复默认验证逻辑,可以移除回调:

System.Net.ServicePointManager.ServerCertificateValidationCallback -= 
    (sender, certificate, chain, sslPolicyErrors) => true;

方式二:结合LdapConnection与DirectoryEntry(更安全精准)

利用LdapConnection(System.DirectoryServices.Protocols)的证书验证配置完成AD连接,再将搜索结果转换为DirectoryEntry对象,既保留精准的证书控制,又能使用DirectoryEntry的功能。

using System.DirectoryServices.Protocols;
using System.Net;

// 配置LdapConnection并忽略证书错误
var ldapId = new LdapDirectoryIdentifier("your-ad-server", 636);
using (var connection = new LdapConnection(ldapId))
{
    connection.Credential = new NetworkCredential("domain\\username", "password");
    connection.SessionOptions.SecureSocketLayer = true;
    connection.SessionOptions.VerifyServerCertificate = (conn, cert) => true;
    
    // 绑定到AD
    connection.Bind();

    // 构建搜索请求
    var searchRequest = new SearchRequest(
        "DC=your-domain,DC=com", // AD搜索根节点
        "(objectClass=user)",    // 过滤条件
        SearchScope.Subtree,
        "distinguishedname", "samaccountname" // 需要返回的属性
    );

    // 执行搜索
    var searchResponse = (SearchResponse)connection.SendRequest(searchRequest);

    // 将搜索结果转换为DirectoryEntry
    foreach (SearchResultEntry entry in searchResponse.Entries)
    {
        using (var dirEntry = new DirectoryEntry(
            $"LDAPS://your-ad-server:636/{entry.DistinguishedName}",
            "domain\\username",
            "password",
            AuthenticationTypes.SecureSocketsLayer | AuthenticationTypes.Secure
        ))
        {
            // 操作DirectoryEntry对象
            Console.WriteLine($"用户显示名:{dirEntry.Properties["displayname"].Value}");
        }
    }
}

注意事项

  • 全局回调方式虽然简单,但会降低应用整体的SSL安全性,仅建议在测试环境临时使用。
  • 结合LdapConnection的方式更安全,仅针对AD的LDAPS连接生效,适合生产环境使用。

内容的提问来源于stack exchange,提问作者Kaygee Del Hlobo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 08:45:46