0

所以我正在尝试搜索 LDAP 以填充 CSV 文件。用户 ID 是通过解析文本文件获得的。我想在 LDAP 中搜索用户 ID (mailNickname)、FName (givenName)、LName (sn)、“OU”、pwdLastSet。我如何使用搜索的过滤器方面,因为我不断收到“错误过滤器”错误。

谢谢你的帮助。

    #!/usr/bin/perl
use xSV;
use Net::LDAP;
use Term::ReadKey;
# use strict;

$debug_on = 1;  # This will enable some debugging messages.

if (defined($ARGV[0])) {
    $input = $ARGV[0];
} else {
    print "No input file specified!  Assuming MKSGroupsoutput.txt...\n";
    $input = "MKSGroupsoutput.txt";
}

if (defined($ARGV[1])) { 
    $output = $ARGV[1];
} else {
    $output = $input . ".csv";
}

open GROUPS, "< $input" or die "ERROR: Can't open input file: '$input'\n";

print "INPUT: $input\nOUTPUT: $output\n";

sub debug {
    if ($debug_on == 1) {
        print "@_";
    }
}

my $csv = Text::xSV->new(
    filename => $output,
    header   => [
    "AccountName", 
    "LastName", 
    "FirstName", 
    "EEID", 
    "SYSGenericAcct", 
    "Notes", 
    "AccessLevel", 
    "AccessCapability", 
    "Owner/Manager",
    "Description", 
    "Created", 
    "Status", 
    "LastStatusChange", 
    "LastPwdChange", 
    "DataSource"
    ],
  );
$csv->print_header();

my ($inputname, $fname, $lname, @name, $uname, $pwordinput, $pword, $domain, $line, $ldap, $bindstring, $root, $pword, $base_dn);
#User driven input to connect to LDAP.  ReadMode 2 keeps password hidden, the reset back to 0.
print "Please enter your Full Name: ";
$inputname = <STDIN>;
print "Please enter your password: ";
ReadMode 2;
$pwordinput = <STDIN>;
ReadMode 0;

#Builds the LDAP CN value from user input. Trims \n off user input values
$inputname = substr($inputname,0,-1);
@name = split(' ', $inputname);
$fname = ucfirst(@name[0]);
$lname = ucfirst(@name[1]);
$pword = substr($pwordinput,0,-1);
$uname = $lname ."\\, " . $fname;
$bindstring = "CN=" . $uname . ",OU=User,DC=hq,DC=name,DC=com";

#LDAP Connection parameters
$base_dn = "OU=User,DC=hq,DC=name,DC=com";
$ldap = Net::LDAP->new('ldap://local', onerror =>'die');
$ldap->bind($bindstring, password => $pword); #Sometimes the BIND fails (1 out of 10 times)
$root = $ldap->root_dse;

#Parses text file
while ($line = <GROUPS>) {
    chomp($line);
    if ($line =~ m/^  user  .*/) {
        $line =~ s/^  user.\s//;
        my ($searchoutput, $user, @entries, $entry, $href, $strDomain, $strUsername, $strDN, $arrSplitResponse, $strLName, $strFName, $strUserType);
        $user = $line;
        $user = "mailNickname: " . $user;
        $searchoutput = $ldap->search(filter=>$user,base=>$base_dn); # ERROR HERE
        @entries = $searchoutput->entries;
        foreach $entry ( @entries ) {
            print "DN: ", $entry->dn, "\n"; #NEVER ENTERS THIS LOOP
        }
4

1 回答 1

1

你为什么删除use strict;?它应该总是在那里。与 相同use warnings;。这可能有助于指出您的一些问题。

我看到你已经设置onerror了一旦你解决了你的问题就可以了,但我建议你在解决所有问题之前不要这样做。相反,捕获 LDAP 方法的输出:

my $ldap_message = $ldap->bind($bindstring, password => $pword);
die qq(LDAP Error Code: ) . $ldap_message->code if $ldap_message->code;

这可能会帮助您调试。


好了,骂你够了。让我们开始解决您的错误:

如果我记得我Net::LDAP的,搜索是:

my $search_obj = ldap->search(base => $base, filter => $filter);

where$base是有效的 LDAP 基础,并且$filter是 LDAP 语法中的有效查询。

查看您的代码:

my $user = "mailNickname: " . $user;
my $searchoutput = $ldap->search(filter=>$user, base=>$base_dn); # ERROR HERE

看起来您的搜索查询是mailNickName: davidif $useris david。这不是有效的 LDAP 搜索。它应该是

my $user = "(mailNickname=$user)"; #Equal sign. Parentheses might be unnecessary
my $searchoutput = $ldap->search(filter=>$user, base=>$base_dn);

请注意,我可以将变量名放在引号内。这是我在 Perl 中喜欢的事情之一。使代码更易于阅读。这可能会奏效。同样,捕获所有 LDAP 方法的输出,并使用代码方法找出导致错误的原因。

于 2012-03-23T03:59:33.113 回答