You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Outlook for iOS通过外部LDAP查找SMIME公钥失败,返回NoSuchObject错误

Outlook for iOS通过外部LDAP查找SMIME公钥失败,返回NoSuchObject错误

看起来你遇到了个挺头疼的问题:明明外部LDAP目录在Windows版Outlook和MaaS360的iOS邮件客户端都能正常跑,但用Intune配置给Outlook for iOS后,虽然能成功绑定LDAP,却在搜索收件人SMIME公钥时返回NoSuchObject错误,导致加密邮件发不出去。结合你提供的日志细节,我整理了几个值得排查的方向:

1. 核对LDAP搜索根DN的准确性

日志里的<BaseObject>字段被脱敏成了Pii,但实际在Intune配置的LDAP搜索根DN,可能和Windows Outlook/MaaS360使用的不一致。比如Windows端用的是宽泛的根目录(比如DC=contoso,DC=com),而iOS端配置的是一个不存在的OU,或者拼写有细微错误。建议直接对比Windows Outlook里的LDAP配置根DN,确保Intune里的配置完全匹配。

2. 模拟Outlook iOS的搜索请求,验证过滤逻辑

从日志里能看到,Outlook iOS的搜索请求同时用了mail、rfc822Mailbox、mailNickName、sAMAccountName、proxyAddresses这几个属性做匹配。你可以用LDAP浏览器(比如Windows自带的LDP.exe),用和Intune配置相同的绑定账号,从同一个根DN出发,用完全一样的过滤条件搜索目标收件人,看看是否能返回结果。如果浏览器里也搜不到,那可能是过滤属性和你目录里的存储属性不匹配(比如有些目录用email而非mail);如果浏览器能搜到,那就是Outlook iOS的搜索逻辑有特殊要求。

3. 检查LDAP绑定账号的权限范围

虽然日志显示绑定成功,但绑定账号可能没有足够的权限遍历整个目录树(日志里搜索范围是WholeSubtree)。比如Windows端用的账号有全目录读取权限,但Intune配置的账号只能访问某个特定OU,而目标收件人在另一个OU下;或者目录服务器的ACL限制了该账号读取某些关键属性。可以用Intune里的绑定账号,通过LDAP浏览器执行相同的搜索操作,确认是否能获取到收件人的证书属性。

4. 排查SSL/TLS相关的潜在问题

日志里显示用了SecureFromStart(LDAPS,端口636)且绑定成功,证书信任问题的可能性较低,但也可以确认下Outlook iOS设备是否信任LDAP服务器的证书(比如是否是公共CA签发,或者已导入设备信任列表)。另外有些LDAP服务器在LDAPS模式下会有不同的访问控制策略,也需要排查。

5. 核对Intune配置策略的参数完整性

可能Intune的LDAP配置里遗漏了某些关键参数,比如是否开启了“搜索子树”的选项,或者是否正确指定了SMIME公钥对应的LDAP属性(比如userCertificate)。可以对比MaaS360的LDAP配置项,看看有没有在Intune里没设置的参数。

附:你提供的LDAP请求日志

<request>

<AccountId>4352</AccountId>

<LogTime>2023-09-21T00:48:00.875Z</LogTime>

<RequestId>16589</RequestId>

<RequestGuid>{992A7273-570B-F944-B00C-EAD372D5979F}</RequestGuid>

<CommandId>LdapSearch</CommandId>

<Tag>hx_8zv05k</Tag>

<Username></Username>

<Server>fakedirectory.contoso.com</Server>

<Port>636</Port>

<SslScheme>SecureFromStart</SslScheme>

<Content>

<BindRequest>

<Tag>808464432</Tag>

<RequestId>0</RequestId>

<MessageId>1</MessageId>

<LdapProtocolOp>BindRequest</LdapProtocolOp>

<LdapVersion>3</LdapVersion>

<Username></Username>

<AuthenticationChoice>Simple</AuthenticationChoice>

</BindRequest>

<BindResponse>

<Tag>808464432</Tag>

<RequestId>0</RequestId>

<MessageId>1</MessageId>

<LdapProtocolOp>BindResponse</LdapProtocolOp>

<LdapResult>

<LdapResultCode>Success</LdapResultCode>

<MatchedDN>Pii</MatchedDN>

<DiagnosticMessage></DiagnosticMessage>

<Referrals />

</LdapResult>

</BindResponse>

<BindRequest>

<Tag>808464432</Tag>

<RequestId>0</RequestId>

<MessageId>2</MessageId>

<LdapProtocolOp>BindRequest</LdapProtocolOp>

<LdapVersion>3</LdapVersion>

<Username></Username>

<AuthenticationChoice>Simple</AuthenticationChoice>

</BindRequest>

<BindResponse>

<Tag>808464432</Tag>

<RequestId>0</RequestId>

<MessageId>2</MessageId>

<LdapProtocolOp>BindResponse</LdapProtocolOp>

<LdapResult>

<LdapResultCode>Success</LdapResultCode>

<MatchedDN>Pii</MatchedDN>

<DiagnosticMessage></DiagnosticMessage>

<Referrals />

</LdapResult>

</BindResponse>

<SearchRequest>

<Tag>4246338630</Tag>

<RequestId>16589</RequestId>

<MessageId>3</MessageId>

<LdapProtocolOp>SearchRequest</LdapProtocolOp>

<BaseObject>Pii</BaseObject>

<Scope>WholeSubtree</Scope>

<DerefAliases>DerefAlways</DerefAliases>

<SizeLimit>0</SizeLimit>

<TimeLimit>30</TimeLimit>

<TypesOnly>0</TypesOnly>

<Or>

<EqualityMatch>

<AttributeDescription>mail</AttributeDescription>

<AssertionValue>Pii</AssertionValue>

</EqualityMatch>

<EqualityMatch>

<AttributeDescription>rfc822Mailbox</AttributeDescription>

<AssertionValue>Pii</AssertionValue>

</EqualityMatch>

<EqualityMatch>

<AttributeDescription>mailNickName</AttributeDescription>

<AssertionValue>Pii</AssertionValue>

</EqualityMatch>

<EqualityMatch>

<AttributeDescription>sAMAccountName</AttributeDescription>

<AssertionValue>Pii</AssertionValue>

</EqualityMatch>

<EqualityMatch>

<AttributeDescription>proxyAddresses</AttributeDescription>

<AssertionValue>Pii</AssertionValue>

</EqualityMatch>

</Or>

<AttributeValues>

<AttributeValue>Pii</AttributeValue>

<AttributeValue>Pii</AttributeValue>

<AttributeValue>Pii</AttributeValue>

<AttributeValue>Pii</AttributeValue>

<AttributeValue>Pii</AttributeValue>

<AttributeValue>Pii</AttributeValue>

</AttributeValues>

</SearchRequest>

<SearchResultDoneResponse>

<Tag>808464432</Tag>

<RequestId>0</RequestId>

<MessageId>3</MessageId>

<LdapProtocolOp>SearchResultDoneResponse</LdapProtocolOp>

<LdapResult>

<LdapResultCode>NoSuchObject</LdapResultCode>

<MatchedDN>Pii</MatchedDN>

<DiagnosticMessage></DiagnosticMessage>

<Referrals />

</LdapResult>

</SearchResultDoneResponse>

<LdapMessage>

<Tag>808464432</Tag>

<RequestId>0</RequestId>

<MessageId>4</MessageId>

<LdapProtocolOp>UnbindRequest</LdapProtocolOp>

</LdapMessage>

</Content>

<Duration>315 msecs</Duration>

<QuitTag>7bwka</QuitTag>

<EndTag>c7n0o</EndTag>

<StatusCode>NoSuchObject</StatusCode>

<DisconnectReason>ServerClosed</DisconnectReason>

</request>

备注:内容来源于stack exchange,提问作者jdbst56

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.21 12:40:34