You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在PHP中获取Active Directory的LDAP组名称及组类型?

获取Active Directory组类型的方法

Active Directory中,组的类型信息存储在groupType属性里,你不需要额外调用专门的函数,只要在通过ldap_get_entries获取组条目时,确保包含这个属性即可。

关键说明

groupType是一个位掩码整数,不同的位对应不同的组属性:

  • 0x80000000:表示这是一个安全组(反之则是通讯组)
  • 0x00000002:全局组
  • 0x00000004:本地域组
  • 0x00000008:通用组

PHP代码示例

假设你已经完成LDAP连接、搜索的基础操作,以下是解析组类型的代码片段:

// 假设$entries是ldap_get_entries返回的结果
foreach ($entries as $entry) {
    // 跳过结果集中的第一个空条目
    if (!isset($entry['dn'])) continue;

    // 获取组名称
    $groupName = $entry['name'][0];
    // 获取并转换groupType为整数
    $groupType = isset($entry['grouptype'][0]) ? intval($entry['grouptype'][0]) : 0;

    // 解析组的安全类型
    $securityType = ($groupType & 0x80000000) !== 0 ? '安全组' : '通讯组';
    // 解析组的作用域
    $scope = '';
    if ($groupType & 0x00000002) {
        $scope = '全局组';
    } elseif ($groupType & 0x00000004) {
        $scope = '本地域组';
    } elseif ($groupType & 0x00000008) {
        $scope = '通用组';
    }

    // 此处将$groupName、$securityType、$scope存入数据库
    // 示例输出:
    echo "组名:{$groupName} | 类型:{$securityType} | 作用域:{$scope}\n";
}

注意事项

  • 在执行ldap_search时,要明确指定需要获取grouptype属性,比如:
    $filter = '(objectClass=group)';
    // 指定要获取的属性列表,包含name和grouptype
    $attributes = ['name', 'grouptype'];
    $searchResult = ldap_search($ldapConn, $baseDn, $filter, $attributes);
    
  • 不需要单独根据组名称去查询类型,只要在获取组条目时包含groupType属性,就能直接解析。

内容的提问来源于stack exchange,提问作者tony

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 02:35:16