使用LDAP/Java启用Active Directory用户

使用LDAP/Java启用Active Directory用户

问题描述:

我试图在Active Directory中使用LDAP和Java(1.4)启用用户。 不过,我不断收到以下错误:使用LDAP/Java启用Active Directory用户

java.lang.NullPointerException at com.sun.jndi.ldap.LdapCtx.c_modifyAttributes(LdapCtx.java:1432) at com.sun.jndi.toolkit.ctx.ComponentDirContext.p_modifyAttributes(ComponentDir Context.java:255) at com.sun.jndi.toolkit.ctx.PartialCompositeDirContext.modifyAttributes(Partial CompositeDirContext.java:172) at com.sun.jndi.toolkit.ctx.PartialCompositeDirContext.modifyAttributes(Partial CompositeDirContext.java:161) at javax.naming.directory.InitialDirContext.modifyAttributes(InitialDirContext. java:146) at be.ideal.LDAP.newuser.main(newuser.java:61) Exception in thread "main"

我已经证实了我的用户有一个密码,我似乎无法对他的状态变为有效

我的代码:

public static void main(String[] args) { 
     String userName = "cn=Albert Einstein,ou=Accounts,DC=PORTAL,DC=COMPANY,DC=BE"; 
     String groupName = "cn=Administrators,cn=Roles,DC=PORTAL,DC=COMPANY,DC=BE"; 
     boolean isDisabled = false; 

     try { 

      System.out.println("Creating initial directory context..."); 
      LdapContext ctx = new InitialLdapContext(X_Ldap.getEnvironment(), 
        null); 

      Attributes attrs = new BasicAttributes(true); 

      attrs.put("objectClass", "user"); 
      attrs.put("cn", "Albert Einstein"); 

String newQuotedPassword = "\"Pass123\""; 
      byte[] newUnicodePassword = newQuotedPassword.getBytes("UTF-16LE"); 
      attrs.put(new BasicAttribute("unicodePwd", newUnicodePassword)); 

      attrs.put(new BasicAttribute("msDS-UserAccountDisabled", "FALSE")); 

      System.out.println("Creating context..."); 
      Context result = ctx.createSubcontext(userName, attrs); 
      System.out.println("Created account for: " + userName); 

      System.out.println("Creating context..."); 
      Context result = ctx.createSubcontext(userName, attrs); 
      System.out.println("Created account for: " + userName); 

      try { 
       ModificationItem member[] = new ModificationItem[1]; 
       member[0] = new ModificationItem(DirContext.ADD_ATTRIBUTE, 
         new BasicAttribute("member", userName)); 

       ctx.modifyAttributes(groupName, member); 
       System.out.println("Added user to group: " + groupName); 

      } catch (NamingException e) { 
       System.err.println("Problem adding user to group: " + e); 
      } 

      ctx.close(); 

      System.out.println("Successfully created User: " + userName); 

     } catch (NamingException e) { 
      System.err.println("Problem creating object: " + e); 
     } 

     catch (IOException e) { 
      System.err.println("Problem creating object: " + e); 
     } 
    } 

PS:我使用AD LDS我的活动目录

发现: 需要使用DirContext.ADD_ATTRIBUTE代替DirConte xt.REPLACE_ATTRIBUTE

+0

有关更多信息,请参阅[替换多值属性值]的进一步讨论(http://ff1959.wordpress.com/2011/07/28/replace-a-value-of -a-多值属性/)。 – 2012-03-22 16:00:16

+0

在AD LDS/Active目录中多值是一个布尔值? – Andreas 2012-03-22 16:14:21

+1

您还需要定义'enableUser []'的第二个成员,或将其维度减少到1.但我不明白为什么在创建子上下文前没有设置所需的所有属性,而不是创建它然后修改它。 – EJP 2012-03-22 21:25:14