android - LDAP 更改 Active Directory 上的用户密码

标签 android active-directory passwords unboundid-ldap-sdk

我声明我是 LDAP 的初学者。
我必须让用户通过 Android 设备更改自己的密码。用户没有管理权限。
使用UnboudId LDAP SDK对于 Java,我可以绑定(bind)到服务器并使用以下代码获取用户条目:

final SocketFactory _socket_factory;
final SSLUtil _ssl_util = new SSLUtil(new TrustAllTrustManager());
try {               
  _socket_factory = _ssl_util.createSSLSocketFactory();             
}
catch (Exception e) {
  Log.e(LOG_TAG, "*** Unable to initialize ssl", e);
}

LDAPConnectionOptions _ldap_connection_options = new LDAPConnectionOptions();
_ldap_connection_options.setAutoReconnect(true);
_ldap_connection_options.setConnectTimeoutMillis(30000);
_ldap_connection_options.setFollowReferrals(false);
_ldap_connection_options.setMaxMessageSize(1024*1024);

LDAPConnection _ldap_connection = new LDAPConnection(_socket_factory, _ldap_connection_options, [host ip], 636, [username], [password]);

Filter _filter = Filter.create("(userPrincipalName=" + [username] + ")");
SearchRequest _search_request = new SearchRequest([base DN], SearchScope.SUB, _filter);
_search_request.setSizeLimit(1000);
_search_request.setTimeLimitSeconds(30);            

SearchResult _search_result = _connection.search(_search_request);

这有效,我得到 1 个条目和所有相关属性。现在我的任务是用新的[新密码]更改密码[密码]。
我的尝试:

PasswordModifyExtendedRequest _password_modify_request = new PasswordModifyExtendedRequest([found entry DN], [password], [new password]);
PasswordModifyExtendedResult _password_modify_result = (PasswordModifyExtendedResult)_ldap_connection.processExtendedOperation(_password_modify_request);

由于 LDAPException,这不起作用

LDAPException(resultCode=2 (protocol error), errorMessage='0000203D: LdapErr: DSID-0C090C7D, comment: Unknown extended request OID, data 0, vece��', diagnosticMessage='0000203D: LdapErr: DSID-0C090C7D, comment: Unknown extended request OID, data 0, vece��')

然后我就尝试了

final Modification _replace_modification = new Modification(ModificationType.REPLACE, "unicodePwd", _get_quoted_string_bytes([new password]));
LDAPResult _result = _connection.modify([found entry DN], _replace_modification);           

由于 LDAPException,这不起作用

LDAPException(resultCode=50 (insufficient access rights), errorMessage='00000005: SecErr: DSID-031A0F44, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0)

我终于尝试了

final Modification _delete_old_modification = new Modification(ModificationType.DELETE, "unicodePwd", _get_quoted_string_bytes([password]));
final Modification _add_new_modification = new Modification(ModificationType.ADD, "unicodePwd", _get_quoted_string_bytes([new password]));
final ArrayList<Modification> _modifications = new ArrayList<Modification>();
_modifications.add(_delete_old_modification);
_modifications.add(_add_new_modification);
LDAPResult _result = _connection.modify([found entry DN], _modifications);

由于 LDAPException,这不起作用

LDAPException(resultCode=19 (constraint violation), errorMessage='00000005: AtrErr: DSID-03190F00, #1:0: 00000005: DSID-03190F00, problem 1005 (CONSTRAINT_ATT_TYPE), data 0, Att 9005a (unicodePwd)��', diagnosticMessage='00000005: AtrErr: DSID-03190F00, #1: 0: 00000005: DSID-03190F00, problem 1005 (CONSTRAINT_ATT_TYPE), data 0, Att 9005a (unicodePwd) ��')

现在我没有更多的想法...任何帮助将不胜感激,提前致谢

最佳答案

final Modification _delete_old_modification = new Modification(ModificationType.DELETE, "unicodePwd", ('"' + oldPassword + '"').getBytes("UTF-16LE"));
final Modification _add_new_modification = new Modification(ModificationType.ADD, "unicodePwd", ('"' + newPassword + '"').getBytes("UTF-16LE"));

成功了。

关于android - LDAP 更改 Active Directory 上的用户密码,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/11178481/

相关文章:

android - ConstraintLayout 没有为在 RecyclerView 上单击的项目设置 NavController

android - 无法启动Android工作室

node.js - NPM - ActiveDirectory 模块身份验证

c++ - 如何使用 C++ Win32API 检查 ADuser "Password never expires"属性检查或不检查?

javascript - (Javascript)我可以为单个输入框设置 "autocomplete=off"吗?

javascript - 用于检查是否至少存在 4 个不同字符组中的 3 个的正则表达式

Android前台服务始终抛出 "java.lang.IllegalArgumentException: Service not registered"异常

android - PackageManager.getInstalledApplications(0);在安卓 7.0

asp.net-mvc - 如何找出我的 'On-Premises Authority' 网址?

javascript - 使用 Javascript 验证密码