You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AD用户密码更新遵循密码历史策略功能失效,如何排查解决?

Active Directory重置密码未遵循密码历史策略问题

我尝试在更新AD用户密码时遵循密码历史策略,现有代码参考微软官方技术文档及Stack Overflow相关类似问题帖,但现有解决方案在我的场景下均不生效。无论使用何种参数组合,即便是已经使用过的历史密码依然可以成功设置为新密码。

已完成排查步骤

  • 同时尝试过已废弃的旧版OID 1.2.840.113556.1.4.2066和新版OID 1.2.840.113556.1.4.2239
  • 尝试将DirectoryControl的value设置为Berconverted 0x1,也试过其他案例提到的字节数组byte[] { 48, (byte)132, 0, 0, 0, 3, 2, 1, 1 }
  • 使用ldap.exe验证过RootDSE同时支持1.2.840.113556.1.4.2066(对应POLICY_HINTS_DEPRECATED)和1.2.840.113556.1.4.2239(对应POLICY_HINTS)
  • 手动修改过测试账号密码,确认用于测试的密码确实处于该账号的密码历史记录中

当前运行代码

public bool ResetUserPassword(string userID, string password)
{
    bool isSuccess = false;

    using (LdapConnection ldapConnection = new LdapConnection(ADServer + ":636"))
    {
        NetworkCredential networkCredential = new NetworkCredential(ADAdminUserID, ADAdminPwd, ADDomain);
        ldapConnection.SessionOptions.SecureSocketLayer = true;
        ldapConnection.AuthType = AuthType.Negotiate;

        // Enforce LDAP version 3
        ldapConnection.SessionOptions.ProtocolVersion = 3;

        ldapConnection.SessionOptions.VerifyServerCertificate = new VerifyServerCertificateCallback((con, cer) => true);

        // Bind connection
        ldapConnection.Bind(networkCredential);

        // the 'unicodePWD' attribute is used to handle pwd handling requests
        string attribute = "unicodePWD";

        // our modification control
        DirectoryAttributeModification[] damList = null;

        // the modifiy request
        ModifyRequest mrCall = null;

        // modification control for the replace operation
        DirectoryAttributeModification damReplace = new DirectoryAttributeModification();

        // attribute to handle
        damReplace.Name = attribute;

        // value to be send with the request
        damReplace.Add(Encoding.Unicode.GetBytes(string.Format("\"{0}\"", password)));

        // this is a replace operation
        damReplace.Operation = DirectoryAttributeOperation.Replace;

        // combine modification controls
        damList = new DirectoryAttributeModification[] { damReplace };

        // create DN string
        string distinguishedName = "CN=TestUser,OU=Test,DC=com";

        // init modify request
        mrCall = new ModifyRequest(distinguishedName, damList);

        // the actual extended control OID                     
        string LDAP_SERVER_POLICY_HINTS_OID = "1.2.840.113556.1.4.2239";

        // build value utilizing berconverter
        //byte[] value = BerConverter.Encode("{i}", new object[] { 0x1 });
        byte[] value = new byte[] { 48, (byte)132, 0, 0, 0, 3, 2, 1, 1 };

        // init extended control
        DirectoryControl pwdHistory = new DirectoryControl(LDAP_SERVER_POLICY_HINTS_OID, value, true, true);

        // add extended control to modify request
        mrCall.Controls.Add(pwdHistory);

        DirectoryResponse drResult = null;

        string msg = "";

        try
        {
            /* send the request into the DirectoryConnection
             * and receive the response */
            drResult = ldapConnection.SendRequest(mrCall);

            // display result code
            msg = TranslateEx(drResult, null, distinguishedName);
        }
        catch (DirectoryOperationException doex)
                { msg = TranslateEx(drResult, doex, distinguishedName); }
        catch (Exception ex)
                { msg = TranslateEx(drResult, ex, distinguishedName); }

        Console.WriteLine(msg);
    }

    return isSuccess;
}

服务端返回结果

字段名值类型
dr{System.DirectoryServices.Protocols.ModifyResponse}System.DirectoryServices.Protocols.DirectoryResponse {System.DirectoryServices.Protocols.ModifyResponse}
Controls{System.DirectoryServices.Protocols.DirectoryControl[0]}System.DirectoryServices.Protocols.DirectoryControl[]
ErrorMessagenullstring
MatchedDN""string
Referral{System.Uri[0]}System.Uri[]
RequestIdnullstring
ResultCodeSuccessSystem.DirectoryServices.Protocols.ResultCode
directoryControlsnullSystem.DirectoryServices.Protocols.DirectoryControl[]
directoryMessagenullstring
directoryReferralnullSystem.Uri[]
directoryRequestIDnullstring
dn""string
dsmlNSnullSystem.Xml.XmlNamespaceManager
dsmlNodenullSystem.Xml.XmlNode
dsmlRequestfalsebool
requestIDnullstring
resultSuccessSystem.DirectoryServices.Protocols.ResultCode

目前暂无其他排查思路,希望能得到相关指导或新的排查方向建议。


内容的提问来源于stack exchange,提问作者inurbits

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.01 16:15:01