5

使用 VB.NET,如何使用 Active Directory 将 sid 转换为组名?

示例:我需要获取“group_test”而不是“S-1-5-32-544”

我正在使用的代码是:

Public ReadOnly Property Groups As IdentityReferenceCollection
    Get

        Dim irc As IdentityReferenceCollection
        Dim ir As IdentityReference
        irc = WindowsIdentity.GetCurrent().Groups
        Dim strGroupName As String

        For Each ir In irc
            Dim mktGroup As IdentityReference = ir.Translate(GetType(NTAccount))
            MsgBox(mktGroup.Value)
            Debug.WriteLine(mktGroup.Value)
            strGroupName = mktGroup.Value.ToString

        Next

        Return irc

    End Get
End Property

或类似的东西?

        currentUser = WindowsIdentity.GetCurrent()

        For Each refGroup As IdentityReference In currentUser.Groups

            Dim acc As NTAccount = TryCast(refGroup.Translate(GetType(NTAccount)), NTAccount)
            If AdminGroupName = acc.Value Then
                ret = "999"
            End If
            If UsersGroupName = acc.Value Then
                ret = "1"
            End If

您将如何使其适应此代码?(如果用户在 xx 组中,则在下拉列表中显示 xx 组)

        For Each UserGroup In WindowsIdentity.GetCurrent().Groups
            If mktGroup.Value = "BIG" Then
                Dim Company = ac1.Cast(Of MarketingCompany).Where(Function(ac) ac.MarketingCompanyShort = "BIG").FirstOrDefault
                If Company IsNot Nothing Then
                    marketingCo.Items.Add(String.Format("{0} | {1}", Company.MarketingCompanyShort, Company.MarketingCompanyName))
                End If
            End If
        Next
4

3 回答 3

9

C# 中的代码:

    public static string GetGroupNameBySid(string sid)
    {
        using(var ctx = 
            new PrincipalContext(ContextType.Domain))
        {
            using(var group = 
                GroupPrincipal.FindByIdentity(
                    ctx, 
                    IdentityType.Sid, 
                    sid))
            {
                return group.SamAccountName;
            }
        }
    }

您必须添加程序集 System.DirectoryServices.AccountManagement.dll。如果您在连接 AD 时遇到任何问题,可以尝试在 PrincipalContext 构造函数中添加 AD 服务器名称。

于 2011-05-05T06:31:49.003 回答
4

以下是如何将 SID 转换为名称的链接:http: //vbdotnet.canbal.com/view.php ?sessionid=JEf85K%2B%2BeBj9Pz%2BWz9hJJicW%2FYEPtADXfcpYCovZ7js%3D

基本上,您会得到一个 DirectoryEntry 对象,然后您可以使用它来获取名称。但是,如果您正在寻找我认为更简单的方法来执行此操作,只需获取当前用户并在 AD 中查找他们的组成员身份。这是一个如何做到这一点的示例(您将需要更大的文章来实际完成您的任务,但此代码是您问题的具体答案): http: //www.codeproject.com/KB/system/everythingInAD.aspx #39

很抱歉代码是用 C# 编写的。但是,您应该能够只使用转换器将其转换为 VB.NET 而不会出现问题。

在 C# 中从 ASP.NET 获取登录用户的用户组成员身份

public ArrayList Groups()
{
    ArrayList groups = new ArrayList();

    foreach (System.Security.Principal.IdentityReference group in
            System.Web.HttpContext.Current.Request.LogonUserIdentity.Groups)
    {
        groups.Add(group.Translate(typeof
        (System.Security.Principal.NTAccount)).ToString());
    }

    return groups;
 }

使用Developer Fusion 的转换器工具在 VB.NET 中从 ASP.NET 获取登录用户的用户组成员资格:

    Public Function Groups() As ArrayList
        Dim groups__1 As New ArrayList()

        For Each group As System.Security.Principal.IdentityReference In                 System.Web.HttpContext.Current.Request.LogonUserIdentity.Groups

               groups__1.Add(group.Translate(GetType(System.Security.Principal.NTAccount)).ToString())
        Next

    Return groups__1
    End Function
于 2011-05-02T16:32:23.817 回答
2

这是用 C# 编写的一种简单方法,我认为它不难适应:

  /* Retreiving object from SID
  */
  string SidLDAPURLForm = "LDAP://WM2008R2ENT:389/<SID={0}>";
  System.Security.Principal.SecurityIdentifier sidToFind = new System.Security.Principal.SecurityIdentifier("S-1-5-21-3115856885-816991240-3296679909-1106");

  DirectoryEntry userEntry = new DirectoryEntry(string.Format(SidLDAPURLForm, sidToFind.Value));

  string name = userEntry.Properties["cn"].Value.ToString();

感谢REFLECTOR ,它在VB .NET中

Dim SidLDAPURLForm As String = "LDAP://WM2008R2ENT:389/<SID={0}>"
Dim sidToFind As New SecurityIdentifier("S-1-5-21-3115856885-816991240-3296679909-1106")
Dim userEntry As New DirectoryEntry(String.Format(SidLDAPURLForm, sidToFind.Value))
Dim name As String = userEntry.Properties.Item("cn").Value.ToString

---- EDITED ----- 所以这就是你想要的,但它与@BiggsTRC 之前给出的相同

Private Shared Sub Main(args As String())
    Dim currentUser As WindowsIdentity = WindowsIdentity.GetCurrent()

For Each iRef As IdentityReference In currentUser.Groups
        Console.WriteLine(iRef.Translate(GetType(NTAccount)))
    Next
End Sub
于 2011-05-02T19:15:15.207 回答