我正在使用python-ldap3
编写一个小脚本来生成虚拟用户和组。
我在将用户与组关联时遇到问题。运行此代码片段后,我的活动目录服务器中没有任何更改:
conn.modify('cn=dancing,ou=test-groups,dc=stand,dc=lsd', {'memberuid': [(MODIFY_REPLACE, ['cn=User1, ou=users,dc=stand,dc=lsd'])]})
怎么了?
使用ldap3.extend.microsoft.addMembersToGroups
from ldap3.extend.microsoft.addMembersToGroups import ad_add_members_to_groups as addUsersInGroups
...
addUsersInGroups(conn, user_dn, group_dn)
完整脚本:
from ldap3 import Server, Connection, ALL, NTLM
from elizabeth import Personal, Address,Text
from ldap3.extend.microsoft.addMembersToGroups import ad_add_members_to_groups as addUsersInGroups
import random
serverName='dc1.stand.local'
connUser="stand.lsd\Admin"
connUserPwd=""
usersOU = 'ou=test-ou,dc=stand,dc=local'
groupsOU = 'ou=test-groups,dc=stand,dc=local'
usersDnList = []
groupsDnList = []
server = Server(serverName, get_info=ALL)
conn = Connection(server, user=connUser, password=connUserPwd, authentication=NTLM)
conn.bind() #must be TRUE
conn.add(usersOU, 'organizationalUnit') # add test-ou for users
conn.add(groupsOU, 'organizationalUnit') # add test-ou for groups
data = Text('en')
for _ in range(0,10):
currentGroup = 'cn='+data.word()+',ou=test-groups,dc=stand,dc=local'
groupsDnList.append(currentGroup)
conn.add(currentGroup, 'group')
address = Address('en')
person = Personal('en')
for _ in range(0,10):
address_country = address.country()
conn.add('ou='+address_country+',ou=test-ou,dc=stand,dc=local', 'organizationalUnit')
for _ in range (0,10):
name = person.name(gender='male')
surname = person.surname(gender='male')
currentUser = 'cn='+name+'.'+surname+','+'ou='+address_country+',ou=test-ou,dc=stand,dc=local'
usersDnList.append(currentUser)
conn.add(currentUser, 'User',
{'givenName': name,
'sn': surname,
'departmentNumber': 'DEV',
'telephoneNumber': 1111})
for _ in range(0,300):
rndUser = random.choice(usersDnList)
rndGroup = random.choice(groupsDnList)
addUsersInGroups(conn, rndUser, rndGroup)
我解决它做...
def insert_ldif (firstname, last_name, UserName, password):
host = 'YourldapIP'
user = 'root'
password = 'YourldapPassword'
a=''
b=a+1
uidNumber = str(b)
sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
sock.connect((host, 22))
session = Session()
session.handshake(sock)
session.userauth_password(user, password)
channel = session.open_session()
channel.shell()
channel.write('cat > /home/reemplaceusername/gen.ldif <<EOFn')
channel.write('dn: uid= %s'',ou=MeLi,dc=lnxnet,dc=ldapn' %UserName)
channel.write('objectClass: inetOrgPersonn')
channel.write('objectClass: posixAccountn')
channel.write('objectClass: shadowAccountn')
channel.write('shadowLastChange: 0n')
channel.write('uid: %sn' %firstname)
channel.write('sn: %sn' %last_name)
channel.write('givenName: %sn'%firstname)
channel.write('cn: %s'%firstname)
channel.write(' %sn'%last_name)
channel.write('displayName: %s ' %firstname)
channel.write('%sn' %last_name)
channel.write('uidNumber: %sn' %uidNumber)
channel.write('gidNumber: 5000n')
channel.write('userPassword: %sn'%password)
channel.write('gecos: %s ' %firstname)
channel.write('%sn'%last_name)
channel.write('loginShell:/bin/bashn')
channel.write('homeDirectory: /home/users/%sn'%UserName)
channel.write('EOFn')
channel.write('ldapadd -x -D cn=admin,dc=lnxnet,dc=ldap -W -f /home/reemplaceusername/gen.ldifn')
channel.write('ldappasswordn')
channel.close()
size, data = channel.read()
while size > 0:
print(data.decode())
size, data = channel.read()
channel.close()
print("Exit status: {0}".format(channel.get_exit_status()))