如何通过LDAP查询从指定FSP的SID获取对应账户名?
Got it, let's get your SID mapped to its username using an LDAP query. The key catch here is that LDAP doesn’t work with the human-readable SID string directly—you need to use its binary representation in the filter. Here’s a step-by-step solution tailored to your specific SID:
Step 1: Convert Your SID to LDAP-Compatible Binary Format
First, we translate your SID (S-1-5-21-2127521184-1604012920-1887927527-72713) into a hexadecimal byte string, where each byte is prefixed with \ (required for LDAP filter syntax). For your SID, the converted binary string is:
\01\05\00\00\00\00\00\05\15\00\00\00\80\00\00\08\78\00\00\60\67\00\00\70\09\B0\01\00
Step 2: Build the Complete LDAP Query
Use the objectSID attribute (which stores account SIDs in binary) along with filters to target user accounts specifically. Here’s the ready-to-use query:
(&(objectCategory=person)(objectClass=user)(objectSID=\01\05\00\00\00\00\00\05\15\00\00\00\80\00\00\08\78\00\00\60\67\00\00\70\09\B0\01\00))
Query Breakdown:
objectCategory=person+objectClass=user: Ensures we only return user objects (filters out groups, computers, and other non-user accounts).objectSID=<binary-value>: Matches the exact SID you provided.
Step 3: Run the Query
You can execute this query with common tools:
- ldp.exe: The built-in Windows LDAP browser. Connect to your domain, bind with appropriate credentials, then paste the filter into the search window and run it.
- PowerShell (for testing): Even though you wanted a raw LDAP query, here’s a quick way to validate it:
$sid = [System.Security.Principal.SecurityIdentifier]::new("S-1-5-21-2127521184-1604012920-1887927527-72713") $binarySid = (-join $sid.BinaryValue.ForEach({"\{0:X2}" -f $_})) $ldapFilter = "(&(objectCategory=person)(objectClass=user)(objectSID=$binarySid))" Get-ADUser -LDAPFilter $ldapFilter
How to Convert Any SID to Binary for LDAP
For future reference, here’s how to convert any SID to the required format:
- Use a .NET method (like the PowerShell snippet above) to get the binary representation of the SID.
- Convert each byte of the binary array to a two-digit hex string, adding a
\before each one. - Plug this string into your LDAP filter as the value for
objectSID.
内容的提问来源于stack exchange,提问作者user3529850

