0x80005000 未知错误 UserPrincipal.GetGroups 在 OU 中具有特殊字符

jal*_*ert 5 .net c# directoryservices active-directory

我正在尝试使用 UserPrincipal 的 GetGroups 方法。如果用户帐户位于包含正斜杠的 OU 中,则对 GetGroups 的调用将失败,并显示 COM 未知错误 0x80005000。找到用户帐户只需查找,我就可以访问其他属性。如果我删除 OU 名称中的斜杠,则一切正常。我找到了对名称中斜杠转义的引用,但它包含在 GetGroups 方法下。我还发现确保使用我已经完成的 PrincipalContext(ContextType, String) 构造函数。我还尝试使用带有转义斜杠的 FQDN 并获得相同的结果。我在 C# 下面有一些示例代码:

我使用的是 Visual Studio 2012。代码在 Windows 10 Enterprise x64 上运行。.net 目标版本是 4.5

using System;
using System.Linq;
using System.DirectoryServices.AccountManagement;

string SamAccountName = "user1";
//The OUs the user is in:
//Broken OU:  "OU=Test / Test,DC=contoso,DC=com"
//Working OU: "OU=Test & Test,DC=contoso,DC=com"

PrincipalContext domainContext = new PrincipalContext(ContextType.Domain, Environment.UserDomainName);
UserPrincipal user = UserPrincipal.FindByIdentity(domainContext, IdentityType.SamAccountName, SamAccountName);

//The user was found so this works
Console.WriteLine("User Found: {0}", user.DistinguishedName);

//This causes COM Exception: Unknown Error 0x80005000                
string output = string.Join(Environment.NewLine, user.GetGroups().Select(x => x.Name).ToArray());
Console.WriteLine(output);
Run Code Online (Sandbox Code Playgroud)

最终,我只是替换了 OU 名称中的任何这些类型的特殊字符,因为这是迄今为止最简单的解决方案。我主要只是想确保我正在编写的代码不会在将来爆炸。

Gab*_*uci 4

我相信这是一个错误。

命名空间的 .NET Core 实现的源代码AccountManagement现已在线提供。我想 .NET Framework 版本大致相同。

我相信问题出在ADStoreCtx.cs 的第 1218 行:

roots.Add(new DirectoryEntry("GC://" + gc.Name + "/" + p.DistinguishedName, this.credentials != null ? this.credentials.UserName : null, this.credentials != null ? this.credentials.Password : null, this.AuthTypes));
Run Code Online (Sandbox Code Playgroud)

即将用户的专有名称放入 LDAP 路径中,该路径使用斜杠作为分隔符,而不转义 DN 中的任何斜杠。

我知道可以在 GitHub 中报告 .NET Core 的错误,但我不确定在哪里报告 .NET Framework 的错误。

  • 我能够重现这一点,因此我报告了 .NET Core 的错误:https://github.com/dotnet/corefx/issues/29090 我还询问在哪里报告完整 .NET Framework 的错误。 (2认同)
  • @CSharpConner据我所知没有。由于这个问题,我最终写了一篇关于查找用户组的不同方法的文章:[查找所有用户组](https://www.gabescode.com/active-directory/2018/06/08 /finding-all-of-a-users-groups.html)。里面有代码示例。无论如何,“DirectoryEntry”[几乎总是更快](https://www.gabescode.com/active-directory/2018/12/15/better-performance-activedirectory.html),尽管使用起来有点复杂。 (2认同)