麻烦PHP LDAP代码检查某个组的成员

时间:2010-09-15 19:24:50

标签: php active-directory ldap

我遇到以下代码时出现问题,该代码应检查$ user是否在AD中的AlumniDBusers或AlumniDBmanagers组中

条目[0]数组始终返回空白

任何人都可以看到可能出错的地方吗?

由于

// Active Directory server
define('LDAP_HOST','dc1.college.school.edu');

// Active Directory DN
define('LDAP_DN','OU=Alumni Relations,OU=Departments,DC=college,DC=school,DC=edu');

// Active Directory user group
define('LDAP_USER_GROUP','AlumniDBusers');

// Active Directory manager group
define('LDAP_MANAGER_GROUP','AlumniDBmanagers');

 $ldap = ldap_connect(LDAP_HOST);

 echo "LDAP CONNECTED<br />";

 if($bind = ldap_bind($ldap, $user, $password)) {
  echo "PASS BIND<br />";

  $filter = "(samAccountName=" . $user . ")";
  $attrs = array("memberOf");
  $result = ldap_search($ldap, LDAP_DN, $filter, $attrs);

  $entries = ldap_get_entries($ldap, $result);

  echo "ENTRY RESULTS: ";
  print_r($entries[0]['memberOf']);
  echo "<br />";

  // see if member is in user or manager group
  if (in_array(LDAP_USER_GROUP,$entries[0]['memberOf']) || in_array(LDAP_MANAGER_GROUP,$entries[0]['memberOf']))
  { 
   echo "IN GROUP";
   ldap_unbind($ldap);
  } else {
   echo "NOT IN GROUP";
   ldap_unbind($ldap);
  }

 } else {
  echo "FAIL BIND";
  ldap_unbind($ldap);
 } 

2 个答案:

答案 0 :(得分:1)

搞定了,我的DN错了 代码是对的

答案 1 :(得分:0)

link text PHP手册

“在为用户添加/编辑属性时,请记住'memberof'属性是一种特殊情况.memberOf属性不是用户模式的可访问属性。”