LDAP搜索 - 错误过滤器

时间:2012-03-22 20:50:40

标签: perl search filter base netldap

所以我正在尝试搜索LDAP以填充CSV文件。通过解析文本文件获得用户ID。我想在LDAP中搜索用户ID(mailNickname),FName(givenName),LName(sn),“OU”,pwdLastSet。如何使用搜索的过滤方面,因为我不断收到“错误的过滤器”错误。

感谢您的帮助。

    #!/usr/bin/perl
use xSV;
use Net::LDAP;
use Term::ReadKey;
# use strict;

$debug_on = 1;  # This will enable some debugging messages.

if (defined($ARGV[0])) {
    $input = $ARGV[0];
} else {
    print "No input file specified!  Assuming MKSGroupsoutput.txt...\n";
    $input = "MKSGroupsoutput.txt";
}

if (defined($ARGV[1])) { 
    $output = $ARGV[1];
} else {
    $output = $input . ".csv";
}

open GROUPS, "< $input" or die "ERROR: Can't open input file: '$input'\n";

print "INPUT: $input\nOUTPUT: $output\n";

sub debug {
    if ($debug_on == 1) {
        print "@_";
    }
}

my $csv = Text::xSV->new(
    filename => $output,
    header   => [
    "AccountName", 
    "LastName", 
    "FirstName", 
    "EEID", 
    "SYSGenericAcct", 
    "Notes", 
    "AccessLevel", 
    "AccessCapability", 
    "Owner/Manager",
    "Description", 
    "Created", 
    "Status", 
    "LastStatusChange", 
    "LastPwdChange", 
    "DataSource"
    ],
  );
$csv->print_header();

my ($inputname, $fname, $lname, @name, $uname, $pwordinput, $pword, $domain, $line, $ldap, $bindstring, $root, $pword, $base_dn);
#User driven input to connect to LDAP.  ReadMode 2 keeps password hidden, the reset back to 0.
print "Please enter your Full Name: ";
$inputname = <STDIN>;
print "Please enter your password: ";
ReadMode 2;
$pwordinput = <STDIN>;
ReadMode 0;

#Builds the LDAP CN value from user input. Trims \n off user input values
$inputname = substr($inputname,0,-1);
@name = split(' ', $inputname);
$fname = ucfirst(@name[0]);
$lname = ucfirst(@name[1]);
$pword = substr($pwordinput,0,-1);
$uname = $lname ."\\, " . $fname;
$bindstring = "CN=" . $uname . ",OU=User,DC=hq,DC=name,DC=com";

#LDAP Connection parameters
$base_dn = "OU=User,DC=hq,DC=name,DC=com";
$ldap = Net::LDAP->new('ldap://local', onerror =>'die');
$ldap->bind($bindstring, password => $pword); #Sometimes the BIND fails (1 out of 10 times)
$root = $ldap->root_dse;

#Parses text file
while ($line = <GROUPS>) {
    chomp($line);
    if ($line =~ m/^  user  .*/) {
        $line =~ s/^  user.\s//;
        my ($searchoutput, $user, @entries, $entry, $href, $strDomain, $strUsername, $strDN, $arrSplitResponse, $strLName, $strFName, $strUserType);
        $user = $line;
        $user = "mailNickname: " . $user;
        $searchoutput = $ldap->search(filter=>$user,base=>$base_dn); # ERROR HERE
        @entries = $searchoutput->entries;
        foreach $entry ( @entries ) {
            print "DN: ", $entry->dn, "\n"; #NEVER ENTERS THIS LOOP
        }

1 个答案:

答案 0 :(得分:1)

为什么要删除use strict;?它总是应该在那里。与use warnings;相同。这可能有助于指出您的一些问题。

我看到你设置onerror一旦你解决了问题就可以了,但我建议你在解决所有问题之前不要这样做。而是捕获LDAP方法的输出:

my $ldap_message = $ldap->bind($bindstring, password => $pword);
die qq(LDAP Error Code: ) . $ldap_message->code if $ldap_message->code;

这可以帮助您调试。


好的,有足够的责备你。让我们来看看你的错误:

如果我记得我的Net::LDAP,则搜索结果为:

my $search_obj = ldap->search(base => $base, filter => $filter);

其中$base是有效的LDAP基础,$filter是LDAP语法中的有效查询。

查看您的代码:

my $user = "mailNickname: " . $user;
my $searchoutput = $ldap->search(filter=>$user, base=>$base_dn); # ERROR HERE

如果mailNickName: david$user,您的搜索查询似乎为david。这不是有效的LDAP搜索。它应该是

my $user = "(mailNickname=$user)"; #Equal sign. Parentheses might be unnecessary
my $searchoutput = $ldap->search(filter=>$user, base=>$base_dn);

注意我可以将变量名放在引号内。这是我在Perl中喜欢的东西之一。使代码更易于阅读。这可能会成功。再次,捕获所有LDAP方法的输出,并使用代码方法找出导致错误的原因。