在jsp中读取Active Directory用户名

时间:2012-02-20 08:34:27

标签: java active-directory

我尝试读取Active Directory中的用户名,但是我收到了错误消息。错误是: 线程“main”中的异常javax.naming.AuthenticationException:[LDAP:错误代码49 - 80090308:LdapErr:DSID-0C0903AA,注释:AcceptSecurityContext错误,数据525,v1772]

但是,我的代码是:

package client;
    import javax.naming.Context;
    import javax.naming.InitialContext;
    import javax.naming.directory.*;
    import javax.naming.ldap.*;
    import javax.naming.*;
    import java.util.Hashtable;
    import java.util.Enumeration;
public class AD {
    public AD() {
        super();
    }


            public static void main(String[] args) throws NamingException {
                    Hashtable envVars = new Hashtable();
                    envVars.put(Context.INITIAL_CONTEXT_FACTORY, "com.sun.jndi.ldap.LdapCtxFactory");
                    envVars.put(Context.PROVIDER_URL, "ldap://" + "IP:Port");
                    envVars.put(Context.SECURITY_AUTHENTICATION, "simple");
                    envVars.put(Context.SECURITY_PRINCIPAL, "username");
                    envVars.put(Context.SECURITY_CREDENTIALS, "password");


                    DirContext myContext = new InitialDirContext(envVars);
                    try{

                    SearchControls searchCtrls = new SearchControls();
                    searchCtrls.setSearchScope(SearchControls.SUBTREE_SCOPE);
                    String[] attributes = { "cn", "telephoneNumber", "sn", "userPrincipalName","memberOf","name" };
                    searchCtrls.setReturningAttributes(attributes);


                    String filter = "(objectClass=organizationalPerson)";
                    NamingEnumeration values = myContext.search("CN=Users,DC=bma.gov.bh,DC=gov,DC=bh",filter, searchCtrls);
                    while (values.hasMoreElements())
                    {
                           SearchResult result = (SearchResult) values.next();
                            Attributes attribs = result.getAttributes();


                            if (null != attribs)
                            {
                                    for (NamingEnumeration ae = attribs.getAll(); ae.hasMoreElements();)
                                    {
                                            Attribute atr = (Attribute) ae.next();
                                            String attributeID = atr.getID();
                                            for (
                                                    Enumeration vals = atr.getAll(); 
                                                    vals.hasMoreElements(); 
                                                    System.out.println(attributeID +": " +vals.nextElement()) );
                                    }
                            }
                    }


                    myContext.close();


                    }

                    catch(Exception e)
                    {
                            //e
                    }
            }



}

问题出在这一行:

DirContext myContext = new InitialDirContext(envVars);

你能帮忙吗

2 个答案:

答案 0 :(得分:1)

请注意,代码80090308并未完全识别此问题。因为数据代码提供了有关该问题的一些详细信息:

  • 525用户未找到
  • 52e无效凭据
  • 530此时不允许登录
  • 531不允许在此工作站登录
  • 532密码已过期
  • 533帐户已停用
  • 701帐号已过期
  • 773用户必须重置密码
  • 775用户帐户已锁定

有关详情,请参阅此页:http://www-01.ibm.com/support/docview.wss?uid=swg21290631

非常感谢IBM支持!

答案 1 :(得分:0)

您可以在winerror.h中找到80090308的错误代码 - 它说

  

提供给该函数的令牌无效

很可能这是因为Active Directory希望密码是UTF-8编码的字节数组,而Java字符串不是。

尝试更改您的代码:

envVars.put(Context.SECURITY_CREDENTIALS, "password".getBytes("UTF8"));