You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在C#中配置Active Directory账户支持AES 128/256加密

配置AD账户支持AES 128/256加密的C#实现方案

你遇到的异常是因为使用了错误的AD属性名称,正确控制加密算法支持的属性是msDS-SupportedEncryptionTypes。该属性仅在Windows Server 2008及以上的域功能级别中可用,以下是两种可行的C#实现方式:

方式一:使用System.DirectoryServices.DirectoryEntry

直接操作目录条目,修改目标属性:

using System.DirectoryServices;

public void EnableAesEncryptionForUser(string userDistinguishedName, string domainUsername, string domainPassword)
{
    // 绑定到目标用户对象
    using (var userEntry = new DirectoryEntry(
        $"LDAP://{userDistinguishedName}",
        domainUsername,
        domainPassword,
        AuthenticationTypes.Secure))
    {
        try
        {
            // AES 128 = 0x8, AES 256 = 0x10,叠加值为24
            userEntry.Properties["msDS-SupportedEncryptionTypes"].Value = 24;
            userEntry.CommitChanges();
        }
        catch (DirectoryServicesCOMException ex)
        {
            // 处理异常:比如域级别过低、权限不足、属性不存在
            Console.WriteLine($"操作失败: {ex.Message}");
            throw;
        }
    }
}

方式二:使用System.DirectoryServices.AccountManagement

通过UserPrincipal简化操作,需要扩展属性来访问msDS-SupportedEncryptionTypes:

using System.DirectoryServices.AccountManagement;

public void EnableAesEncryptionWithAccountManagement(string userSamAccountName, string domainContext)
{
    using (var context = new PrincipalContext(ContextType.Domain, domainContext))
    {
        using (var user = UserPrincipal.FindByIdentity(context, userSamAccountName))
        {
            if (user == null)
                throw new ArgumentException("未找到目标用户");

            try
            {
                // 扩展设置属性值
                user.ExtensionSet("msDS-SupportedEncryptionTypes", 24);
                user.Save();
            }
            catch (PrincipalOperationException ex)
            {
                Console.WriteLine($"操作失败: {ex.Message}");
                throw;
            }
        }
    }
}

关键注意事项

  • 域功能级别要求:必须确保你的Active Directory域功能级别为Windows Server 2008或更高,否则msDS-SupportedEncryptionTypes属性不存在,会抛出你遇到的异常。
  • 权限要求:执行代码的账户需要拥有修改目标AD用户属性的权限。
  • 属性值说明:24是AES128(8)和AES256(16)的叠加值,如果需要保留其他加密类型(比如RC4),可以叠加对应数值(RC4是0x4)。

内容的提问来源于stack exchange,提问作者chaya vayzer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 21:40:52