Outlook for iOS通过外部LDAP查找SMIME公钥失败,返回NoSuchObject错误
看起来你遇到了个挺头疼的问题:明明外部LDAP目录在Windows版Outlook和MaaS360的iOS邮件客户端都能正常跑,但用Intune配置给Outlook for iOS后,虽然能成功绑定LDAP,却在搜索收件人SMIME公钥时返回NoSuchObject错误,导致加密邮件发不出去。结合你提供的日志细节,我整理了几个值得排查的方向:
1. 核对LDAP搜索根DN的准确性
日志里的<BaseObject>字段被脱敏成了Pii,但实际在Intune配置的LDAP搜索根DN,可能和Windows Outlook/MaaS360使用的不一致。比如Windows端用的是宽泛的根目录(比如DC=contoso,DC=com),而iOS端配置的是一个不存在的OU,或者拼写有细微错误。建议直接对比Windows Outlook里的LDAP配置根DN,确保Intune里的配置完全匹配。
2. 模拟Outlook iOS的搜索请求,验证过滤逻辑
从日志里能看到,Outlook iOS的搜索请求同时用了mail、rfc822Mailbox、mailNickName、sAMAccountName、proxyAddresses这几个属性做匹配。你可以用LDAP浏览器(比如Windows自带的LDP.exe),用和Intune配置相同的绑定账号,从同一个根DN出发,用完全一样的过滤条件搜索目标收件人,看看是否能返回结果。如果浏览器里也搜不到,那可能是过滤属性和你目录里的存储属性不匹配(比如有些目录用email而非mail);如果浏览器能搜到,那就是Outlook iOS的搜索逻辑有特殊要求。
3. 检查LDAP绑定账号的权限范围
虽然日志显示绑定成功,但绑定账号可能没有足够的权限遍历整个目录树(日志里搜索范围是WholeSubtree)。比如Windows端用的账号有全目录读取权限,但Intune配置的账号只能访问某个特定OU,而目标收件人在另一个OU下;或者目录服务器的ACL限制了该账号读取某些关键属性。可以用Intune里的绑定账号,通过LDAP浏览器执行相同的搜索操作,确认是否能获取到收件人的证书属性。
4. 排查SSL/TLS相关的潜在问题
日志里显示用了SecureFromStart(LDAPS,端口636)且绑定成功,证书信任问题的可能性较低,但也可以确认下Outlook iOS设备是否信任LDAP服务器的证书(比如是否是公共CA签发,或者已导入设备信任列表)。另外有些LDAP服务器在LDAPS模式下会有不同的访问控制策略,也需要排查。
5. 核对Intune配置策略的参数完整性
可能Intune的LDAP配置里遗漏了某些关键参数,比如是否开启了“搜索子树”的选项,或者是否正确指定了SMIME公钥对应的LDAP属性(比如userCertificate)。可以对比MaaS360的LDAP配置项,看看有没有在Intune里没设置的参数。
附:你提供的LDAP请求日志
<request> <AccountId>4352</AccountId> <LogTime>2023-09-21T00:48:00.875Z</LogTime> <RequestId>16589</RequestId> <RequestGuid>{992A7273-570B-F944-B00C-EAD372D5979F}</RequestGuid> <CommandId>LdapSearch</CommandId> <Tag>hx_8zv05k</Tag> <Username></Username> <Server>fakedirectory.contoso.com</Server> <Port>636</Port> <SslScheme>SecureFromStart</SslScheme> <Content> <BindRequest> <Tag>808464432</Tag> <RequestId>0</RequestId> <MessageId>1</MessageId> <LdapProtocolOp>BindRequest</LdapProtocolOp> <LdapVersion>3</LdapVersion> <Username></Username> <AuthenticationChoice>Simple</AuthenticationChoice> </BindRequest> <BindResponse> <Tag>808464432</Tag> <RequestId>0</RequestId> <MessageId>1</MessageId> <LdapProtocolOp>BindResponse</LdapProtocolOp> <LdapResult> <LdapResultCode>Success</LdapResultCode> <MatchedDN>Pii</MatchedDN> <DiagnosticMessage></DiagnosticMessage> <Referrals /> </LdapResult> </BindResponse> <BindRequest> <Tag>808464432</Tag> <RequestId>0</RequestId> <MessageId>2</MessageId> <LdapProtocolOp>BindRequest</LdapProtocolOp> <LdapVersion>3</LdapVersion> <Username></Username> <AuthenticationChoice>Simple</AuthenticationChoice> </BindRequest> <BindResponse> <Tag>808464432</Tag> <RequestId>0</RequestId> <MessageId>2</MessageId> <LdapProtocolOp>BindResponse</LdapProtocolOp> <LdapResult> <LdapResultCode>Success</LdapResultCode> <MatchedDN>Pii</MatchedDN> <DiagnosticMessage></DiagnosticMessage> <Referrals /> </LdapResult> </BindResponse> <SearchRequest> <Tag>4246338630</Tag> <RequestId>16589</RequestId> <MessageId>3</MessageId> <LdapProtocolOp>SearchRequest</LdapProtocolOp> <BaseObject>Pii</BaseObject> <Scope>WholeSubtree</Scope> <DerefAliases>DerefAlways</DerefAliases> <SizeLimit>0</SizeLimit> <TimeLimit>30</TimeLimit> <TypesOnly>0</TypesOnly> <Or> <EqualityMatch> <AttributeDescription>mail</AttributeDescription> <AssertionValue>Pii</AssertionValue> </EqualityMatch> <EqualityMatch> <AttributeDescription>rfc822Mailbox</AttributeDescription> <AssertionValue>Pii</AssertionValue> </EqualityMatch> <EqualityMatch> <AttributeDescription>mailNickName</AttributeDescription> <AssertionValue>Pii</AssertionValue> </EqualityMatch> <EqualityMatch> <AttributeDescription>sAMAccountName</AttributeDescription> <AssertionValue>Pii</AssertionValue> </EqualityMatch> <EqualityMatch> <AttributeDescription>proxyAddresses</AttributeDescription> <AssertionValue>Pii</AssertionValue> </EqualityMatch> </Or> <AttributeValues> <AttributeValue>Pii</AttributeValue> <AttributeValue>Pii</AttributeValue> <AttributeValue>Pii</AttributeValue> <AttributeValue>Pii</AttributeValue> <AttributeValue>Pii</AttributeValue> <AttributeValue>Pii</AttributeValue> </AttributeValues> </SearchRequest> <SearchResultDoneResponse> <Tag>808464432</Tag> <RequestId>0</RequestId> <MessageId>3</MessageId> <LdapProtocolOp>SearchResultDoneResponse</LdapProtocolOp> <LdapResult> <LdapResultCode>NoSuchObject</LdapResultCode> <MatchedDN>Pii</MatchedDN> <DiagnosticMessage></DiagnosticMessage> <Referrals /> </LdapResult> </SearchResultDoneResponse> <LdapMessage> <Tag>808464432</Tag> <RequestId>0</RequestId> <MessageId>4</MessageId> <LdapProtocolOp>UnbindRequest</LdapProtocolOp> </LdapMessage> </Content> <Duration>315 msecs</Duration> <QuitTag>7bwka</QuitTag> <EndTag>c7n0o</EndTag> <StatusCode>NoSuchObject</StatusCode> <DisconnectReason>ServerClosed</DisconnectReason> </request>
备注:内容来源于stack exchange,提问作者jdbst56

