LDAP:ldap.SIZELIMIT_EXCEEDED

8 python ldap

我运行此代码时收到ldap.SIZELIMIT_EXCEEDED错误:

import ldap

url = 'ldap://<domain>:389'
binddn = 'cn=<username> readonly,cn=users,dc=tnc,dc=org'
password = '<password>'

conn = ldap.initialize(url)
conn.simple_bind_s(binddn,password)

base_dn = "ou=People,dc=tnc,dc=org"
filter = '(objectClass=*)'
attrs = ['sn']

conn.search_s( base_dn, ldap.SCOPE_SUBTREE, filter, attrs )
Run Code Online (Sandbox Code Playgroud)

我的实际用户名,实际密码和实际域名在哪里.

我不明白为什么会这样.有人可以解释一下吗?

谢谢!:)埃里克

Jos*_*eia 6

您遇到该异常很可能是因为与您通信的服务器的结果多于单个请求所能返回的结果。为了解决这个问题,您需要使用分页结果,这可以通过使用SimplePagedResultsControl来完成。

这是我在对此处和官方文档中找到的内容进行大量编辑后提出的 Python3 实现。在撰写本文时,它适用于 pip3 包python-ldap版本 3.2.0。

def get_list_of_ldap_users():
    hostname = "<domain>:389"
    username = "username_here"
    password = "password_here"
    base = "ou=People,dc=tnc,dc=org"

    print(f"Connecting to the LDAP server at '{hostname}'...")
    connect = ldap.initialize(f"ldap://{hostname}")
    connect.set_option(ldap.OPT_REFERRALS, 0)
    connect.simple_bind_s(username, password)
    search_flt = "(objectClass=*)"
    page_size = 500 # how many users to search for in each page, this depends on the server maximum setting (default highest value is 1000)
    searchreq_attrlist=["sn"] # change these to the attributes you care about
    req_ctrl = SimplePagedResultsControl(criticality=True, size=page_size, cookie='')
    msgid = connect.search_ext(base=base, scope=ldap.SCOPE_SUBTREE, filterstr=search_flt, attrlist=searchreq_attrlist, serverctrls=[req_ctrl])

    total_results = []
    pages = 0
    while True: # loop over all of the pages using the same cookie, otherwise the search will fail
        pages += 1
        rtype, rdata, rmsgid, serverctrls = connect.result3(msgid)
        for user in rdata:
            total_results.append(user)

        pctrls = [c for c in serverctrls if c.controlType == SimplePagedResultsControl.controlType]
        if pctrls:
            if pctrls[0].cookie: # Copy cookie from response control to request control
                req_ctrl.cookie = pctrls[0].cookie
                msgid = connect.search_ext(base=base, scope=ldap.SCOPE_SUBTREE, filterstr=search_flt, attrlist=searchreq_attrlist, serverctrls=[req_ctrl])
            else:
                break
        else:
            break
    return total_results
Run Code Online (Sandbox Code Playgroud)

这将返回所有用户的列表,但您可以根据需要对其进行编辑以返回您想要的内容,而不会遇到问题SIZELIMIT_EXCEEDED:)


Nul*_*ion 5

手册:http://www.python-ldap.org/doc/html/ldap.html

例外 ldap。 超过了LDAP大小限制。这可能是由于 LDAP服务器上的配置。SIZELIMIT_EXCEEDED
sizelimit

我认为您最好的选择是限制sizelimit从服务器收到的消息。您可以通过设置属性LDAPObject.sizelimit(不建议使用)或在使用时使用sizelimit参数来实现search_ext()

您还应该确保绑定实际上是成功的。