我们正在使用 System.DirectoryServices.DirectorySearcher 进行 sAMAccountName 查找。这很好用,只是在查询某个我们怀疑很大的广告时,搜索经常会超时。在做了一些研究之后,我发现使用 System.DirectoryServices.Protocols 的搜索在查询大型 AD 时会更快。我正在尝试使用协议重新创建我们所拥有的内容,看看这是否会对超时产生任何影响。这是目前存在的:
Dim Entry As New DirectoryEntry(anLDAPURL, aDomainUserName, aPassword)
Dim obj As Object = Entry.NativeObject 'Force Authentication on Active Directory Server
Dim Filter As String = String.Format("(sAMAccountName={0})", aDomainUserName)
Dim Search As New DirectorySearcher(Entry, Filter)
Search.PropertiesToLoad.Add(SID)
Search.PropertiesToLoad.Add(ACCOUNTISLOCKEDOUT)
Search.PropertiesToLoad.Add(ACCOUNTISDISABLED)
Dim Results As SearchResult = Search.FindOne()
这工作正常并且非常快(除了上面提到的超时情况)。这就是我试图改变它以便我可以测试它:
Dim credentials As New System.Net.NetworkCredential(aDomainUserName, aPassword)
Dim directoryIdentifier As New System.DirectoryServices.Protocols.LdapDirectoryIdentifier("ldap-ad.example.org")
Using connection As New System.DirectoryServices.Protocols.LdapConnection(directoryIdentifier, credentials, Protocols.AuthType.Basic)
Dim attributes() As String = {SID, ACCOUNTISLOCKEDOUT, ACCOUNTISDISABLED}
Dim search As New System.DirectoryServices.Protocols.SearchRequest(
"dc=example,dc=org",
String.Format("(sAMAccountName={0})", aDomainUserName),
Protocols.SearchScope.Subtree,
attributes)
Dim response As System.DirectoryServices.Protocols.SearchResponse = DirectCast(connection.SendRequest(search), System.DirectoryServices.Protocols.SearchResponse)
End Using
上面的代码有效,因为它返回一个结果,但比原来的要慢得多。我怀疑我尝试查询的方式效率低下,但我不太确定应该如何设置它以使其更快。