AD用户密码更新遵循密码历史策略功能失效,如何排查解决?
Active Directory重置密码未遵循密码历史策略问题
我尝试在更新AD用户密码时遵循密码历史策略,现有代码参考微软官方技术文档及Stack Overflow相关类似问题帖,但现有解决方案在我的场景下均不生效。无论使用何种参数组合,即便是已经使用过的历史密码依然可以成功设置为新密码。
已完成排查步骤
- 同时尝试过已废弃的旧版OID 1.2.840.113556.1.4.2066和新版OID 1.2.840.113556.1.4.2239
- 尝试将DirectoryControl的value设置为Berconverted 0x1,也试过其他案例提到的字节数组
byte[] { 48, (byte)132, 0, 0, 0, 3, 2, 1, 1 } - 使用ldap.exe验证过RootDSE同时支持1.2.840.113556.1.4.2066(对应POLICY_HINTS_DEPRECATED)和1.2.840.113556.1.4.2239(对应POLICY_HINTS)
- 手动修改过测试账号密码,确认用于测试的密码确实处于该账号的密码历史记录中
当前运行代码
public bool ResetUserPassword(string userID, string password) { bool isSuccess = false; using (LdapConnection ldapConnection = new LdapConnection(ADServer + ":636")) { NetworkCredential networkCredential = new NetworkCredential(ADAdminUserID, ADAdminPwd, ADDomain); ldapConnection.SessionOptions.SecureSocketLayer = true; ldapConnection.AuthType = AuthType.Negotiate; // Enforce LDAP version 3 ldapConnection.SessionOptions.ProtocolVersion = 3; ldapConnection.SessionOptions.VerifyServerCertificate = new VerifyServerCertificateCallback((con, cer) => true); // Bind connection ldapConnection.Bind(networkCredential); // the 'unicodePWD' attribute is used to handle pwd handling requests string attribute = "unicodePWD"; // our modification control DirectoryAttributeModification[] damList = null; // the modifiy request ModifyRequest mrCall = null; // modification control for the replace operation DirectoryAttributeModification damReplace = new DirectoryAttributeModification(); // attribute to handle damReplace.Name = attribute; // value to be send with the request damReplace.Add(Encoding.Unicode.GetBytes(string.Format("\"{0}\"", password))); // this is a replace operation damReplace.Operation = DirectoryAttributeOperation.Replace; // combine modification controls damList = new DirectoryAttributeModification[] { damReplace }; // create DN string string distinguishedName = "CN=TestUser,OU=Test,DC=com"; // init modify request mrCall = new ModifyRequest(distinguishedName, damList); // the actual extended control OID string LDAP_SERVER_POLICY_HINTS_OID = "1.2.840.113556.1.4.2239"; // build value utilizing berconverter //byte[] value = BerConverter.Encode("{i}", new object[] { 0x1 }); byte[] value = new byte[] { 48, (byte)132, 0, 0, 0, 3, 2, 1, 1 }; // init extended control DirectoryControl pwdHistory = new DirectoryControl(LDAP_SERVER_POLICY_HINTS_OID, value, true, true); // add extended control to modify request mrCall.Controls.Add(pwdHistory); DirectoryResponse drResult = null; string msg = ""; try { /* send the request into the DirectoryConnection * and receive the response */ drResult = ldapConnection.SendRequest(mrCall); // display result code msg = TranslateEx(drResult, null, distinguishedName); } catch (DirectoryOperationException doex) { msg = TranslateEx(drResult, doex, distinguishedName); } catch (Exception ex) { msg = TranslateEx(drResult, ex, distinguishedName); } Console.WriteLine(msg); } return isSuccess; }
服务端返回结果
| 字段名 | 值 | 类型 |
|---|---|---|
| dr | {System.DirectoryServices.Protocols.ModifyResponse} | System.DirectoryServices.Protocols.DirectoryResponse {System.DirectoryServices.Protocols.ModifyResponse} |
| Controls | {System.DirectoryServices.Protocols.DirectoryControl[0]} | System.DirectoryServices.Protocols.DirectoryControl[] |
| ErrorMessage | null | string |
| MatchedDN | "" | string |
| Referral | {System.Uri[0]} | System.Uri[] |
| RequestId | null | string |
| ResultCode | Success | System.DirectoryServices.Protocols.ResultCode |
| directoryControls | null | System.DirectoryServices.Protocols.DirectoryControl[] |
| directoryMessage | null | string |
| directoryReferral | null | System.Uri[] |
| directoryRequestID | null | string |
| dn | "" | string |
| dsmlNS | null | System.Xml.XmlNamespaceManager |
| dsmlNode | null | System.Xml.XmlNode |
| dsmlRequest | false | bool |
| requestID | null | string |
| result | Success | System.DirectoryServices.Protocols.ResultCode |
目前暂无其他排查思路,希望能得到相关指导或新的排查方向建议。
内容的提问来源于stack exchange,提问作者inurbits
相关产品推荐
相关产品推荐

