我正在使用java创建AD用户帐户。我可以成功创建用户帐户,并且该帐户确实在" AD用户和计算机" GUI但我无法访问创建的AD用户帐户。
我遇到的问题是我无法将"userAccountControl"
属性设置为"512"
,代表NORMAL_ACCOUNT
或"66048"
代表NORMAL_ACCOUNT, ACCOUNT_NEVER_EXPIRES
。
每当我设置上述值时,都会显示以下异常:
javax.naming.NameAlreadyBoundException: [LDAP: error code 68 - 00000524: UpdErr: DSID-031A122A, problem 6005 (ENTRY_EXISTS), data 0
]; remaining name 'cn=User Four,ou=DAT,DC=dat,DC=com'
at com.sun.jndi.ldap.LdapCtx.mapErrorCode(Unknown Source)
at com.sun.jndi.ldap.LdapCtx.processReturnCode(Unknown Source)
at com.sun.jndi.ldap.LdapCtx.processReturnCode(Unknown Source)
at com.sun.jndi.ldap.LdapCtx.c_createSubcontext(Unknown Source)
at com.sun.jndi.toolkit.ctx.ComponentDirContext.p_createSubcontext(Unknown Source)
at com.sun.jndi.toolkit.ctx.PartialCompositeDirContext.createSubcontext(Unknown Source)
at com.sun.jndi.toolkit.ctx.PartialCompositeDirContext.createSubcontext(Unknown Source)
at javax.naming.directory.InitialDirContext.createSubcontext(Unknown Source)
at NewUser.addUser(NewUser.java:94)
at MainClass.main(MainClass.java:7)
当我直接从AD GUI创建用户帐户时,使用"userAccountControl"
属性"512"
或"66048"
成功创建了帐户。我可以访问这些帐户。
有谁能告诉我如何解决这个问题。
这是我的addUser()方法。
public boolean addUser() throws NamingException {
Attributes container = new BasicAttributes();
Attribute objClasses = new BasicAttribute("objectClass");
objClasses.add("top");
objClasses.add("person");
objClasses.add("organizationalPerson");
objClasses.add("user");
String cnValue = new StringBuffer(firstName).append(" ").append(lastName).toString();
Attribute cn = new BasicAttribute("cn", cnValue);
Attribute sAMAccountName = new BasicAttribute("sAMAccountName", userName);
Attribute principalName = new BasicAttribute("userPrincipalName", userName
+ "@" + DOMAIN_NAME);
Attribute givenName = new BasicAttribute("givenName", firstName);
Attribute sn = new BasicAttribute("sn", lastName);
Attribute uid = new BasicAttribute("uid", userName);
Attribute userPassword = new BasicAttribute("userpassword", password);
Attribute userAccountControl = new BasicAttribute("userAccountControl", "512");
container.put(objClasses);
container.put(sAMAccountName);
container.put(principalName);
container.put(cn);
container.put(sn);
container.put(givenName);
container.put(uid);
container.put(userPassword);
container.put(userAccountControl);
try {
context.createSubcontext(getUserDN(cnValue, organisationUnit), container);
return true;
} catch (Exception e) {
return false;
}
}
答案 0 :(得分:2)
实际上"userAccountControl"
属性无法设置为512
或66048
,因为上面的代码会在AD服务器中创建没有密码的AD帐户。我使用命令行AD帐户创建方法dsadd user "cn=User name,ou=org unit,ou=org unit,dc=domain,dc=domain" -upn "userName@dat.com" -email "userName@dat.com" -fn firstName -ln lastName -display "Display user name" -mustchpwd no -pwd password -disabled no